Avatar of valmatic
valmatic
Flag for United States of America asked on

DNS Error LDAP?

Hi
I am getting this error in my best practive anazlyzer. I was checking here since i was having a sysvol replication issue. What record is this looking for dns? My 2 DCs each have their local ip in the forward zones?

Issue:
The "LdapIpAddress" DNS (A/AAAA) resource records that advertise this domain controller as an available LDAP server in the domain and point to its IPv4 or IPv6 addresses are not registered. All writeable domain controllers in the domain (but not read-only domain controllers (RODCs)) must register these records.
DNSWindows Server 2008Windows Server 2012

Avatar of undefined
Last Comment
Dan McFadden

8/22/2022 - Mon
Dan McFadden

This initially appears to be an Active Directory issue.  I would run the following command:

with an account that has Admin privileges = dcdiag /test:DNS /e /v > dcdiag.txt

and attach the output so it can be looked over.

Dan
James

Check that replication is functioning. Run the following commands from the command prompt > repadmin /syncall /AdeP and also > repadmin /showreps

Check to see can you access the sysvol share from each domain controller and vice a versa.

Regards,

JBond2010
valmatic

ASKER
Mostly i am seeing it is missing my AAAA records but i dont use IP V6. Ill have it posted in a few.
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
valmatic

ASKER
My sys vol share is not replicating to my second DC. I usually edit Group policy on my main server and it is not replicating over is the reason i started looking around.  

I got nothing from that command about repadmin...
James

You did not get any errors from repadmin? The command is - repadmin /AdeP

Please be aware the AP in /AdeP are capitals.


Regards,

JBond2010
valmatic

ASKER
No errors at all with that command
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
Dan McFadden

There should be a file called dcdiag.txt in the location that you ran the command prompt from.

If you just opened a command prompt and ran the command, the text file is probably in your user directory.
valmatic

ASKER
Dan i ran your command and the only errors on all 9 pages were the server not listed it V6 AAAA record, other than that it came out clean. Im not sure what this ldapipaddress setting is supposed to be the best practice thing is complaining about?
Dan McFadden

Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
valmatic

ASKER
it is talking about ldap in the error but is it simply stating it is mad i disabled ip v6 on my nic and once i turn it on and that record hits dns it will be happy?
Dan McFadden

You should not disable IPv6 on domain controllers.  It is not recommended by Microsoft.  IPv6 should be enabled and for all options configured as automatic.

Dan
ASKER CERTIFIED SOLUTION
Dan McFadden

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
valmatic

ASKER
is this ok to do during the day since i am not messing with my ip v4 address?
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
Dan McFadden

This can be done without disrupting operations.
valmatic

ASKER
i added ip v6 back in but the analyzer is still not happy.
Is this supposed to be in DNS somewhere i do not see it?
LdapIpAddress ??
Dan McFadden

The "LdapIpAddress" item is described in my post from yesterday at 16:38.  Please read thru the article from Microsoft as it describes what you need to do to address the issue,

Dan
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck