Solved

DNS seems incorrect after promoting 2008 R2 Server and demoted 2003 server as domain controllers

Posted on 2014-12-10
9
43 Views
Last Modified: 2015-02-07
After transferring the FSMO roles to our 2008 R2 server and making it the new PDC. I was unable to get the 2003 server to graciously demote as DC, I then used the dcpromo /forceremoval, since then we are unable to reconnect the 2003 server to the domain, All the workstations can no longer connect to Exchange (also hosted on the PDC at this point), when running a nltest /dclist:domain command the domain cannot be found.  I have attached a copy of the dcdiag, any help would be appreciated.
dcdiag.txt
nltest.txt
0
Comment
Question by:Danbman
  • 5
  • 4
9 Comments
 
LVL 10

Expert Comment

by:Walter Padrón
ID: 40492527
You must setup the DNS role on your DC, seems is not working
"Name resolution for the name isatap timed out after none of the configured DNS servers responded."
0
 

Author Comment

by:Danbman
ID: 40492606
DNS role is installed on DC, Best practices analyzer comes back with no errors or warnings.
0
 
LVL 10

Expert Comment

by:Walter Padrón
ID: 40492618
Check firewall rules, open DNS console and check you see your dns zones. dcdiag doesn't found any DNS servers.
0
 

Author Comment

by:Danbman
ID: 40492624
Not sure if this will help, but here is the BPA log for AD DS
DirectoryServices-EngineReport1.txt
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 10

Expert Comment

by:Walter Padrón
ID: 40492643
The BPS logs are in xml format, is difficult to red but some messages can be extracted.
"<Message>Could not find a forest identified by: 'crossroads.local'.</Message>"
this points to a DNS issue also.
0
 

Author Comment

by:Danbman
ID: 40492688
Disabled local firewall as well as created a rule in external firewall to allow all internal traffic (just in case). Opened DNS console and am able to see the forest for the domain just fine. When trying to connect the 2003 server to the domain it states

DNS was successfully queried for the service location (SRV) resource record used to locate a domain controller for domain crossroads.local:

The query was for the SRV record for _ldap._tcp.dc._msdcs.crossroads.local

The following domain controllers were identified by the query:

crm-dc.crossroads.local
hp-crmdc.crossroads.local

Common causes of this error include:

- Host (A) records that map the name of the domain controller to its IP addresses are missing or contain incorrect addresses.

- Domain controllers registered in DNS are not connected to the network or are not running.

For information about correcting this problem, click Help.
0
 
LVL 10

Expert Comment

by:Walter Padrón
ID: 40493850
How many domain controllers do you have now?

You must check the DNS zone _msdcs.yourdomain.com for staled or wrong records pointing to non-existing DCs, do the same in your domainname.com zone for NS records.
0
 

Accepted Solution

by:
Danbman earned 0 total points
ID: 40494675
It looks like I have cleared the largest hurdle.  Turns out the issue had something to do with netlogon and sysvol shares not replicating correctly. I was able to rebuild them and now computers are able to join the networks again as well as exchange seems to be functioning again.  I would like to thank you for your help regardless Walter.
0
 

Author Closing Comment

by:Danbman
ID: 40595418
Working
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
Synchronize a new Active Directory domain with an existing Office 365 tenant
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now