For no apparant reason today, cannot log into domain console & users cannot access domain

I have a primary and secondary DC on Windows Server 2008. Users called this morning could not access domain resources. After I arrived I could not log in as Administrator even to the console of either controller. Had to hard power off BOTH machines! I am seeing a lot of messages in event viewer pertaining to GP (Event ID 1006) and KDC (Event ID 29) but that is all. Could this have anything to do with the leap second?
Kirk MillerInformation Technology DirectorAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Emmanuel AdebayoGlobal Windows Infrastructure Engineer - ConsultantCommented:
Are these errors on the client workstation?.

After hard power off both DCs were you able to log on.?

Not sure if this is related to leap second.

Check the local host files on both servers to see if you will see any entries apart from the normal ones that were commented out.

regards
0
Kirk MillerInformation Technology DirectorAuthor Commented:
After I hard powered both servers I was able to get logged in as well as workstations. You are referring to the host file located at C:\Windows\System32\drivers\etc, correct? If so, there are no entries entered, just the normal commented out examples...no entries. The primary DC runs DNS server service though. What other even id entries may indicate problem this morning?
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
Can you run the command dcdiag please and post the output.
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
run this command on both dc lets pay particular attention to the primary though for now have both DC powered on when running these commands too please
1
Kirk MillerInformation Technology DirectorAuthor Commented:
Thanks Mark! Here are the DC Diagnostics Results:

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = dcod1
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests
   
   Testing server: Default-First-Site-Name\DCOD1
      Starting test: Connectivity
         ......................... DCOD1 passed test Connectivity

Doing primary tests
   
   Testing server: Default-First-Site-Name\DCOD1
      Starting test: Advertising
         ......................... DCOD1 passed test Advertising
      Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... DCOD1 passed test FrsEvent
      Starting test: DFSREvent
         ......................... DCOD1 passed test DFSREvent
      Starting test: SysVolCheck
         ......................... DCOD1 passed test SysVolCheck
      Starting test: KccEvent
         ......................... DCOD1 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... DCOD1 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... DCOD1 passed test MachineAccount
      Starting test: NCSecDesc
         ......................... DCOD1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... DCOD1 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... DCOD1 passed test ObjectsReplicated
      Starting test: Replications
         ......................... DCOD1 passed test Replications
      Starting test: RidManager
         ......................... DCOD1 passed test RidManager
      Starting test: Services
         ......................... DCOD1 passed test Services
      Starting test: SystemLog
         ......................... DCOD1 passed test SystemLog
      Starting test: VerifyReferences
         ......................... DCOD1 passed test VerifyReferences
   
   
   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation
   
   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation
   
   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
   
   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
   
   Running partition tests on : ciscoeq
      Starting test: CheckSDRefDom
         ......................... ciscoeq passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ciscoeq passed test CrossRefValidation
   
   Running enterprise tests on : ciscoeq.com
      Starting test: LocatorCheck
         ......................... ciscoeq.com passed test LocatorCheck
      Starting test: Intersite
         ......................... ciscoeq.com passed test Intersite
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
can you run netdiag command and post this please?
1
Kirk MillerInformation Technology DirectorAuthor Commented:
This is the DC Diag for the secondary:


Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = dcod2

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\DCOD2

      Starting test: Connectivity

         ......................... DCOD2 passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\DCOD2

      Starting test: Advertising

         Warning: DCOD2 is not advertising as a time server.

         ......................... DCOD2 failed test Advertising

      Starting test: FrsEvent

         There are warning or error events within the last 24 hours after the

         SYSVOL has been shared.  Failing SYSVOL replication problems may cause

         Group Policy problems.
         ......................... DCOD2 passed test FrsEvent

      Starting test: DFSREvent

         ......................... DCOD2 passed test DFSREvent

      Starting test: SysVolCheck

         ......................... DCOD2 passed test SysVolCheck

      Starting test: KccEvent

         ......................... DCOD2 passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... DCOD2 passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... DCOD2 passed test MachineAccount

      Starting test: NCSecDesc

         ......................... DCOD2 passed test NCSecDesc

      Starting test: NetLogons

         ......................... DCOD2 passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... DCOD2 passed test ObjectsReplicated

      Starting test: Replications

         ......................... DCOD2 passed test Replications

      Starting test: RidManager

         ......................... DCOD2 passed test RidManager

      Starting test: Services

         ......................... DCOD2 passed test Services

      Starting test: SystemLog

         ......................... DCOD2 passed test SystemLog

      Starting test: VerifyReferences

         ......................... DCOD2 passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : ciscoeq

      Starting test: CheckSDRefDom

         ......................... ciscoeq passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ciscoeq passed test CrossRefValidation

   
   Running enterprise tests on : ciscoeq.com

      Starting test: LocatorCheck

         ......................... ciscoeq.com passed test LocatorCheck

      Starting test: Intersite

         ......................... ciscoeq.com passed test Intersite
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
Is the time set correctly on both servers and the time service started on both servers?

what do you see in the event logs errors, warnings and criticals?
1
Kirk MillerInformation Technology DirectorAuthor Commented:
Mark, The two controllers were off by about 2 minutes. I need a better understanding of the time service and advised configuration. I suppose them being off could be the cuplrit, correct? If so, do you recommend using the time service installed or a third party utility and how about for the workstations?
0
Kirk MillerInformation Technology DirectorAuthor Commented:
Mark, I also just discovered that on the secondary machine the Time Service is set up as "manual" vs. "Automatic" on the primary machine!
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
no we can set the time manually for now and then set the time service to use an external source once weve pinpointed the issue.

try this.

on DC1 set the time to the correct time. verify this in whatever locale your in.
on DC2 set the time to the correct time.
Restart the time service on DC1
Restart the time service on DC2

run dcdiag again
run netdiag command also

see where we are at, at this point.
1
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
bingo, time service not started right? set it to automatic and start it.
1
Emmanuel AdebayoGlobal Windows Infrastructure Engineer - ConsultantCommented:
AD automatically sets each DC to sync time with the master DC

I would suggest that you set your master DC to get the time source from time.windows.com
The workstation will by default use the DC as the time server.
0
Emmanuel AdebayoGlobal Windows Infrastructure Engineer - ConsultantCommented:
Sorry, I'll leave Mark to go through this with you.

All the best
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
hey op!

we can set the time service once we verify we are in better situation ;)

M
0
Kirk MillerInformation Technology DirectorAuthor Commented:
Ok Mark. Thank You. I will follow your steps. One question though. Do I run netdiag from elevated command prompt with any parameters. When I attempt to simply type in netdiag I get a return that it is not a recognized command.
0
Kirk MillerInformation Technology DirectorAuthor Commented:
C:\>netdiag
'netdiag' is not recognized as an internal or external command,
operable program or batch file.

C:\>
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
hi we need to install the support tools for this operating system if it is returning this when you run netdiag

we can ignore this for now

is the dcdiag clean now on both servers?

are the workstations able to log on?
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
can we also run this command on the dc01 w32tm /query /source

this will tell us where the time is being set from then we can see what if any changes we want to make here.
1
Kirk MillerInformation Technology DirectorAuthor Commented:
New DIAG Results:

DC1 -

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = dcod1
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests
   
   Testing server: Default-First-Site-Name\DCOD1
      Starting test: Connectivity
         ......................... DCOD1 passed test Connectivity

Doing primary tests
   
   Testing server: Default-First-Site-Name\DCOD1
      Starting test: Advertising
         ......................... DCOD1 passed test Advertising
      Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... DCOD1 passed test FrsEvent
      Starting test: DFSREvent
         ......................... DCOD1 passed test DFSREvent
      Starting test: SysVolCheck
         ......................... DCOD1 passed test SysVolCheck
      Starting test: KccEvent
         ......................... DCOD1 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... DCOD1 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... DCOD1 passed test MachineAccount
      Starting test: NCSecDesc
         ......................... DCOD1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... DCOD1 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... DCOD1 passed test ObjectsReplicated
      Starting test: Replications
         ......................... DCOD1 passed test Replications
      Starting test: RidManager
         ......................... DCOD1 passed test RidManager
      Starting test: Services
         ......................... DCOD1 passed test Services
      Starting test: SystemLog
         A warning event occurred.  EventID: 0x0000000C
            Time Generated: 07/01/2015   10:34:31
            Event String:
            Time Provider NtpClient: This machine is configured to use the domain hierarchy to determine its time source, but it is the AD PDC emulator for the domain at the root of the forest, so there is no machine above it in the domain hierarchy to use as a time source. It is recommended that you either configure a reliable time service in the root domain, or manually configure the AD PDC to synchronize with an external time source. Otherwise, this machine will function as the authoritative time source in the domain hierarchy. If an external time source is not configured or used for this computer, you may choose to disable the NtpClient.
         A warning event occurred.  EventID: 0x0000000C
            Time Generated: 07/01/2015   10:44:25
            Event String:
            Time Provider NtpClient: This machine is configured to use the domain hierarchy to determine its time source, but it is the AD PDC emulator for the domain at the root of the forest, so there is no machine above it in the domain hierarchy to use as a time source. It is recommended that you either configure a reliable time service in the root domain, or manually configure the AD PDC to synchronize with an external time source. Otherwise, this machine will function as the authoritative time source in the domain hierarchy. If an external time source is not configured or used for this computer, you may choose to disable the NtpClient.
         A warning event occurred.  EventID: 0x0000000C
            Time Generated: 07/01/2015   10:45:29
            Event String:
            Time Provider NtpClient: This machine is configured to use the domain hierarchy to determine its time source, but it is the AD PDC emulator for the domain at the root of the forest, so there is no machine above it in the domain hierarchy to use as a time source. It is recommended that you either configure a reliable time service in the root domain, or manually configure the AD PDC to synchronize with an external time source. Otherwise, this machine will function as the authoritative time source in the domain hierarchy. If an external time source is not configured or used for this computer, you may choose to disable the NtpClient.
         ......................... DCOD1 passed test SystemLog
      Starting test: VerifyReferences
         ......................... DCOD1 passed test VerifyReferences
   
   
   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation
   
   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation
   
   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
   
   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
   
   Running partition tests on : ciscoeq
      Starting test: CheckSDRefDom
         ......................... ciscoeq passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ciscoeq passed test CrossRefValidation
   
   Running enterprise tests on : ciscoeq.com
      Starting test: LocatorCheck
         ......................... ciscoeq.com passed test LocatorCheck
      Starting test: Intersite
         ......................... ciscoeq.com passed test Intersite
0
Kirk MillerInformation Technology DirectorAuthor Commented:
DC2 -

Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = dcod2

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\DCOD2

      Starting test: Connectivity

         ......................... DCOD2 passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\DCOD2

      Starting test: Advertising

         Warning: DCOD2 is not advertising as a time server.

         ......................... DCOD2 failed test Advertising

      Starting test: FrsEvent

         There are warning or error events within the last 24 hours after the

         SYSVOL has been shared.  Failing SYSVOL replication problems may cause

         Group Policy problems.
         ......................... DCOD2 passed test FrsEvent

      Starting test: DFSREvent

         ......................... DCOD2 passed test DFSREvent

      Starting test: SysVolCheck

         ......................... DCOD2 passed test SysVolCheck

      Starting test: KccEvent

         ......................... DCOD2 passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... DCOD2 passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... DCOD2 passed test MachineAccount

      Starting test: NCSecDesc

         ......................... DCOD2 passed test NCSecDesc

      Starting test: NetLogons

         ......................... DCOD2 passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... DCOD2 passed test ObjectsReplicated

      Starting test: Replications

         ......................... DCOD2 passed test Replications

      Starting test: RidManager

         ......................... DCOD2 passed test RidManager

      Starting test: Services

         ......................... DCOD2 passed test Services

      Starting test: SystemLog

         A warning event occurred.  EventID: 0x0000008E

            Time Generated: 07/01/2015   10:23:16

            Event String:

            The time service has stopped advertising as a time source because the local clock is not synchronized.

         A warning event occurred.  EventID: 0x0000008E

            Time Generated: 07/01/2015   10:26:16

            Event String:

            The time service has stopped advertising as a time source because the local clock is not synchronized.

         ......................... DCOD2 passed test SystemLog

      Starting test: VerifyReferences

         ......................... DCOD2 passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : ciscoeq

      Starting test: CheckSDRefDom

         ......................... ciscoeq passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ciscoeq passed test CrossRefValidation

   
   Running enterprise tests on : ciscoeq.com

      Starting test: LocatorCheck

         ......................... ciscoeq.com passed test LocatorCheck

      Starting test: Intersite

         ......................... ciscoeq.com passed test Intersite
0
Kirk MillerInformation Technology DirectorAuthor Commented:
Ok, so above are the new dcdiag results from both servers. Yes, my clients have been logged on for several hours now. Just trying to get this correct so doesn't happen again. That being said I did a GPUPDATE /F from my workstation and it changed the time which is off by a minute or two from the DC1.
What should I do next?
0
Kirk MillerInformation Technology DirectorAuthor Commented:
From the command you suggested above "w32tm /query /source" on DC1 it shows the source is the Local CMOS Clock
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
ok so we are in a better state now.

all we need to do is set the dc01 to a good external source.

what is the output of the following command from dc01

w32tm /query /source
1
Kirk MillerInformation Technology DirectorAuthor Commented:
The output for DC1 & DC2:

Local CMOS Clock
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
w32tm /config /manualpeerlist:PEERS /syncfromflags:manual /reliable:yes /update

we need to run this command on PDC lets forget DC2 until we get this right.

in the above command where it says peers we need to set our ntp server

i am in the uk, i do not know where you are, you need to find a suitable set of ntp servers(time servers)

lets try the command like this on dc1 w32tm /config /manualpeerlist:0.pool.ntp.org, 1.pool.ntp.org, 2.pool.ntp.org /syncfromflags:manual /reliable:yes /update
1
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
once this is done please verify by checking

1) time is correct on dc1
2) running w32tm query source command again pls.
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
sorry the second post above, i am pretty busy here got lost in that post, i specify the command to run in the end at the bottom of the post.
0
Kirk MillerInformation Technology DirectorAuthor Commented:
Sorry Mark. I am a little lost with the posts. I appreciate your help. I am in the United States in the Central Time Zone, so it it 11:24AM here on 7/1/15. What should be the command I type in?
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
w32tm /config /manualpeerlist:0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org /syncfromflags:manual /reliable:yes /update

run this on dc1

sorry i made a couple of confusing posts.

then
1) verify time on dc1 is correct
2) then run w32tm /query /source on dc1 and tell me the output please

There are no spaces in the above time set command you may want to run it again
1
Kirk MillerInformation Technology DirectorAuthor Commented:
Thank You sir!
Did exactly as you specified and it states the command completed successfully, then the output is not as expected:

C:\Windows\system32>w32tm /config /manualpeerlist:0.pool.ntp.org,1.pool.ntp.org,
2.pool.ntp.org /syncfromflags:manual /reliable:yes /update
The command completed successfully.

C:\Windows\system32>w32tm /query /source
Local CMOS Clock
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
1. First, locate your PDC Server. Open the command prompt and type: C:>netdom /query fsmo
2. Log in to your PDC Server and open the command prompt.
3. Stop the W32Time service: C:>net stop w32time
4. Configure the external time sources, type: C:> w32tm /config /syncfromflags:manual /manualpeerlist:”0.pool.ntp.org, 1.pool.ntp.org, 2.pool.ntp.org”
5. Make your PDC a reliable time source for the clients. Type: C:>w32tm /config /reliable:yes
Start the w32time service: C:>net start w32time

Lets try again with this one this time, im on the road here going to be gone for a short period of time.

We just need to set the time source here on PDC, we know what the issue is, if the time is wrong pc will not log in, SQL server will not work, Exchange server will not work all under the correct circumstances.

We will get this right, we can change these settings by registry too if we need too once im back.
1

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Kirk MillerInformation Technology DirectorAuthor Commented:
Thank You Mark. Here is everything you told me to do, which I did:


C:\>netdom /query fsmo
Schema master               dcod1.ciscoeq.com
Domain naming master        dcod1.ciscoeq.com
PDC                         dcod1.ciscoeq.com
RID pool manager            dcod1.ciscoeq.com
Infrastructure master       dcod1.ciscoeq.com
The command completed successfully.


C:\>net stop w32time
The Windows Time service is stopping.
The Windows Time service was stopped successfully.

C:\>w32tm /config /syncfromflags:manual /manualpeerlist:"0.pool.ntp.org 1.pool.n
tp.org 2.pool.ntp.org"
The command completed successfully.

C:\>w32tm /config /reliable:yes
The command completed successfully.

C:\>net start w32time
The Windows Time service is starting.
The Windows Time service was started successfully.

C:\>w32tm /query /source
1.pool.ntp.org
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
no problems, sorry things are bit hectic for me with work right now.

What happens if you run the w32tm /query /source on dc02?
1
Kirk MillerInformation Technology DirectorAuthor Commented:
Mark, No problem at all. I completely understand. I normally can figure these things out but this has been a bugger getting time syncing properly across the domain and workstations.

DC2:
Local CMOS Clock

P.S.
By the way, where in UK are you? I am traveling to UK for the first time next month. I should treat you to a pint for all that you have done helping me today!
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
not at all mate, thanks though im here to help people, the site and improve my skills. I have been helped plenty of times in sticky spots and given advice so its all good :). These things can be tricky.
Unfortunately im not in the UK, im in Ireland, you can contact me on my details here no problems. :)

can you run this command on DC2 ?

 w32tm /config /syncfromflags:domhier /update

and then check the source again on DC2.
0
Kirk MillerInformation Technology DirectorAuthor Commented:
Same result after running the above commands:

Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Users\systems>w32tm /config /syncfromflags:domhier /update
The command completed successfully.

C:\Users\systems>w32tm /query /source
Local CMOS Clock

C:\Users\systems>
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
im expecting the same result but pls try

on dc2
stop time service
w32tm /config /syncfromflags:domhier /update
start time service

and let me know. we cant be looking at cmos clocks because if the battery dies were in trouble.
the main problem here is sorted anyway the PDC.

add in another step here if we still have the problem on dc2
run this on dc2
w32tm /resync
0
Kirk MillerInformation Technology DirectorAuthor Commented:
Understood. I ran the commands above and the problem is that it will not allow me to do the update with the time service stopped, only with it started. Should I try and configure the same way as dc1?


C:\>net stop w32time
The Windows Time service is stopping.
The Windows Time service was stopped successfully.

C:\>w32tm /config /syncfromflags:domhier /update
The following error occurred: The service has not been started. (0x80070426)

C:\>net start w32time
The Windows Time service is starting.
The Windows Time service was started successfully.

C:\>w32tm /config /syncfromflags:domhier /update
The command completed successfully.
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
and what does it look like now when we check the source?
0
Kirk MillerInformation Technology DirectorAuthor Commented:
Sorry, forgot to post that. Same result:

C:\>w32tm /query /source
Local CMOS Clock
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
Try these steps on DC2

1. Run command below on your DC3:
w32tm /config /syncfromflags:domhier /update
W32tm /resync /rediscover
Net stop w32time && net start w32time
2. If it does not work, reset the time service to default settings on your DC3:
net stop w32time
w32tm /unregister
w32tm /register
net start w32time
1
Kirk MillerInformation Technology DirectorAuthor Commented:
Well my friend. I am calling it a night and a bad day of frustration. :) It tried the commands from above and get various errors with the same result, "Local CMOS clock". I am almost considering demoting this server as a dc2 and making another one but I am open to any other suggestions. I have also tried various other things. Here are the sad reults:


C:\Users\systems>w32tm /config /syncfromflags:domhier /update
The command completed successfully.

C:\Users\systems>W32tm /resync /rediscover
Sending resync command to local computer
The computer did not resync because no time data was available.


C:\Users\systems>Net stop w32time && net start w32time
The Windows Time service is stopping.
The Windows Time service was stopped successfully.

The Windows Time service is starting.
The Windows Time service was started successfully.


C:\Users\systems>w32tm /query /source
Local CMOS Clock

C:\Users\systems>net stop w32time
The Windows Time service is stopping.
The Windows Time service was stopped successfully.


C:\Users\systems>w32tm /unregister
The following error occurred: Access is denied. (0x80070005)
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
unregistering may well fix it, can we log on as the administrator account and try it again ?

the account im talking about is part of enterprise admins group in active directory.
0
Kirk MillerInformation Technology DirectorAuthor Commented:
Good morning Mark! I just tried again with success on dc2!

C:\Users\systems>w32tm /query /source
dcod1.ciscoeq.com
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
nice one, now clear down the event logs, right click and save them somewhere, then run dcdiag on both of the dc with clear logs.

once it passes were all good here once your not experiencing any issues.
0
Kirk MillerInformation Technology DirectorAuthor Commented:
Hello Mate! Sorry I have been out for our holiday. I am going to do as suggested and will let you know but I think all is working well now.
Also, I am a first time user to this forum so what do "Accept Multiple Solution" and "Accept as Solutions" used for/How do I mark your solution as fixed or rate you?
0
Kirk MillerInformation Technology DirectorAuthor Commented:
Ok, after saving the event logs and clearing them here is dcdiag result for DC1 and no events recorded after running:


Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = dcod1
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests
   
   Testing server: Default-First-Site-Name\DCOD1
      Starting test: Connectivity
         ......................... DCOD1 passed test Connectivity

Doing primary tests
   
   Testing server: Default-First-Site-Name\DCOD1
      Starting test: Advertising
         ......................... DCOD1 passed test Advertising
      Starting test: FrsEvent
         ......................... DCOD1 passed test FrsEvent
      Starting test: DFSREvent
         ......................... DCOD1 passed test DFSREvent
      Starting test: SysVolCheck
         ......................... DCOD1 passed test SysVolCheck
      Starting test: KccEvent
         ......................... DCOD1 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... DCOD1 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... DCOD1 passed test MachineAccount
      Starting test: NCSecDesc
         ......................... DCOD1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... DCOD1 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... DCOD1 passed test ObjectsReplicated
      Starting test: Replications
         ......................... DCOD1 passed test Replications
      Starting test: RidManager
         ......................... DCOD1 passed test RidManager
      Starting test: Services
         ......................... DCOD1 passed test Services
      Starting test: SystemLog
         ......................... DCOD1 failed test SystemLog
      Starting test: VerifyReferences
         ......................... DCOD1 passed test VerifyReferences
   
   
   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation
   
   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation
   
   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
   
   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
   
   Running partition tests on : ciscoeq
      Starting test: CheckSDRefDom
         ......................... ciscoeq passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ciscoeq passed test CrossRefValidation
   
   Running enterprise tests on : ciscoeq.com
      Starting test: LocatorCheck
         ......................... ciscoeq.com passed test LocatorCheck
      Starting test: Intersite
         ......................... ciscoeq.com passed test Intersite
0
Kirk MillerInformation Technology DirectorAuthor Commented:
And here is the result for DC2, also no errors in the event log:


Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = dcod2

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\DCOD2

      Starting test: Connectivity

         ......................... DCOD2 passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\DCOD2

      Starting test: Advertising

         ......................... DCOD2 passed test Advertising

      Starting test: FrsEvent

         ......................... DCOD2 passed test FrsEvent

      Starting test: DFSREvent

         ......................... DCOD2 passed test DFSREvent

      Starting test: SysVolCheck

         ......................... DCOD2 passed test SysVolCheck

      Starting test: KccEvent

         ......................... DCOD2 passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... DCOD2 passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... DCOD2 passed test MachineAccount

      Starting test: NCSecDesc

         ......................... DCOD2 passed test NCSecDesc

      Starting test: NetLogons

         ......................... DCOD2 passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... DCOD2 passed test ObjectsReplicated

      Starting test: Replications

         ......................... DCOD2 passed test Replications

      Starting test: RidManager

         ......................... DCOD2 passed test RidManager

      Starting test: Services

         ......................... DCOD2 passed test Services

      Starting test: SystemLog

         ......................... DCOD2 passed test SystemLog

      Starting test: VerifyReferences

         ......................... DCOD2 passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : ciscoeq

      Starting test: CheckSDRefDom

         ......................... ciscoeq passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ciscoeq passed test CrossRefValidation

   
   Running enterprise tests on : ciscoeq.com

      Starting test: LocatorCheck

         ......................... ciscoeq.com passed test LocatorCheck

      Starting test: Intersite

         ......................... ciscoeq.com passed test Intersite
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.