Avatar of Josh Hind
Josh Hind
Flag for United States of America asked on

DNS cannot be installed on this domain controller

We have a new Server 2012R2 machine.  Getting an error after trying to promote to domain controller.  I've added the roles of Active Directory Sites and Services, AD users and computers, AD domains and trusts and DNS.  But I get the error, "DNS cannot be installed on this domain controller because this domain does not host DNS."  We absolutely use DNS on our domain.  But this halts the install and I can't go any further in the server promotion.  I've researched this and I haven't found a situation that matches ours exactly.  Some say to run dcpromo from a cmd prompt but that has gone away in 2012R2.  We only have one other DC it is a Windows Server 2008 Standard machine.  I have verified that it has the DNS role.
Microsoft Server OSDNSActive Directory

Avatar of undefined
Last Comment
Josh Hind

8/22/2022 - Mon
it_saige

Have you looked at this Microsoft TID?

http://support.microsoft.com/en-us/kb/2002584

-saige-
Josh Hind

ASKER
Yes I have.  I tried the commands listed.  They didn't help.
ASKER CERTIFIED SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Paul MacDonald

I would check to make sure you can reach the extant DCs from this new machine.  It may be there's a networking/firewall issue that's preventing this new DC from contacting DNS.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Josh Hind

ASKER
Performing initial setup:
   Trying to find home server...
   ***Error: *servername* is not a Directory Server.  Must specify /s:<Directory
   Server> or  /n:<Naming Context> or nothing to use the local machine.
   ERROR: Could not find home server.
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Paul MacDonald

You can also check the functional level of the domain.  Have you run ADPREP?

I still suspect a networking issue though.
Josh Hind

ASKER
I ran it. It revealed a bunch of problems.  It's attached.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
Trying to attach again.
DCDIAG-Output.txt
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
The server that held the PDCe FSMO role died due to multiple hard drive failure.  The output of the nslookup command is attached.  Two of the three machines are no longer on the domain.
DNS-Info.txt
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
They were on one of the servers that died.   Can I promote the current DC to those roles?
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
SOLUTION
David Johnson, CD

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
it_saige

Have you ran the script provided by David yet?  Once you have done this, then you will want to do a metadata cleanup of all orphaned DC's.  Orphaned DC's are domain controllers that have been removed from the domain but still have entries in AD because of a failed or improper removal.

https://gallery.technet.microsoft.com/scriptcenter/d31f091f-2642-4ede-9f97-0e1cc4d577f3/view/Discussions

-saige-
Josh Hind

ASKER
I finally got the script to run but now it is reporting an error.  I am attaching it.
error.txt
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
It is not R2 it's  Windows Server 2008 Standard.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
Ok *Server1* now has roles: Schema, Naming Master, PDC, RID and Infrastructure.   Working on the metadata cleanup now.
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
I am still working on the tasks outlined in 40699444.  I will update with new DCDIAG summary when completed.
Josh Hind

ASKER
Here is the updated dcdiag output.
dcdiag2.txt
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
Ok both commands yielded "sufficient".
Testing.txt
it_saige

Let's add it to your domain then.

-saige-
Josh Hind

ASKER
It is added to the domain.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
it_saige

Let's run a DCDIAG on the newly added server.

-saige-
Josh Hind

ASKER
It has not been promoted to DC yet.
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
I've tried doing that but it brings up a message referring me to a technet article.
dc-promo-message.jpg
dc-promo-message.jpg
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
it_saige

Which message?

-saige-
Josh Hind

ASKER
I attached it to ID: 40701655
it_saige

⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
Ok so it completed but gave the attached message.
Final-Message.jpg
it_saige

Ok.  Let's look at the DNS and NIC configuration on SERVER1.

-saige-
Josh Hind

ASKER
Ok *Server1* has three DNS entries:

192.*.*.14 (itself because it was the only DNS server on the domain)
8.8.8.8 (Google DNS)
8.8.4.4 (Google DNS)
Your help has saved me hundreds of hours of internet surfing.
fblack61
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
Ok, a few things.  I've finished tweaking the DNS settings.  I obtained DNS info from my service provider and entered it on *SERVER1*.  I ran the commands listed in #1, it did not like 'netlogon'.  It told me "'netdiag' is not recognized as an internal
operable program or batch file."  Upon researching I found it was an older command not available on 2008 anymore so I moved on.  In #2 I already had a.root-servers.net entered.  Only, b through m.root-servers.net are listed as well.  Should I delete them?  Finally, in DNS manager I don't see the newly promoted DC.  It is listed in "name servers" for our domain though.
SOLUTION
it_saige

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Josh Hind

ASKER
Thanks, it_saige!