Solved

Changed IP address on DC and now I cannot join clients to domain.

Posted on 2016-08-16
9
107 Views
Last Modified: 2016-08-16
So I have a domain controller (windows 2012 server) that has been moved to a new location. It had to have the IP address changed to match the new network. SO now that this has all happened it appears to have fouled up all my dns setting because I cannot join computers to the domain. The client computers that are trying to join are using the IP address of the DC as the primary DNS. I know its something with the dns settings (lookup zones) on the server im just not sure what I dont have configured right. the new dc controller IP is 10.0.0.90 and I have removed all the old entries in DNS and added new zones pointing to the new address. Is there a simple way to rebuild this?
0
Comment
Question by:mikesmithccs
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
  • +1
9 Comments
 
LVL 41

Expert Comment

by:Adam Brown
ID: 41758223
Make sure the NIC on the DC is configured to register itself in DNS (Adapter properties > IPv4 properties > Advanced > DNS tab > Check mark in register this connection). Run ipconfig /flushdns, then run ipconfig /registerdns on the DC. Then stop and restart the netlogon service. There are probably more DNS entries that need to be updated. Doing these things will cause the DC to register itself in DNS again.

If that doesn't fix the issue, clear and rebuild your _msdcs zone. Go into DNS, find a zone and/or folder called _msdcs. Delete it (delete both if there is a zone *and* folder with that name), run ipconfig/flushdns on the DC, then ipconfig /registerdns. Once that's done, stop and restart the netlogon service on the DC. that will force the DC to re-register everything and rebuild the _msdcs zone, which defines all the
0
 
LVL 1

Author Comment

by:mikesmithccs
ID: 41758289
I am still getting "an active directory domain controller for the domain could not be contacted" error.

Also, and nslookup doesnt not resolve the server name.

When I try to ping the server name from the client, I get "Pinging (server name) 222.222.222.155" which is the old IP address.
0
 
LVL 5

Expert Comment

by:foochar
ID: 41758321
How are your clients getting DNS server information, is it statically configured or are they getting DNS settings via DHCP?

Was the server that was relocated also acting as the DNS server for the clients?  If so have the settings for the clients been updated to point to the new DNS server?  Or if they weren't using directly using it as a DNS server was it configured as a forward lookup on the DNS server they do use, in which case the information for the forwarder may need updated...
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 
LVL 41

Expert Comment

by:Adam Brown
ID: 41758322
run ipconfig /flushdns on the client.
0
 
LVL 1

Author Comment

by:mikesmithccs
ID: 41758336
Foochar - They are getting DNS manually. I have entered the domain controller as the primary dns address(10.0.0.90). The server that was relocated is the acting DNS server. After the move I uninstalled the dns server role and reinstalled. However, it appears some of the old entries were still residing in the DNS. I had to manually delete some entries that showed my DC A record still using the old 222.222.222.155 IP address.

Adam - did that and it didnt help.

Also, still getting this from client.......
Pinging NHP-RDS01 [222.222.222.155] with 32 bytes of data:
Request timed out.
Request timed out.
Request timed out.
Request timed out.

222.222.222.155 is the old address of the DC.
0
 
LVL 5

Expert Comment

by:foochar
ID: 41758351
You mentioned earlier that nslookup isn't resolving the request.  Have you verified that the clients are able to ping the server at its new 10.0.0.90 IP address?  Since its not resolving at all (as opposed to just resolving to the old address) when you do an nslookup I'd be looking first at basic network and DNS connectivity, for example the possibility that traffic on port 53 isn't allowed between the two networks, or that there is a routing issue between the two networks...
0
 
LVL 1

Author Comment

by:mikesmithccs
ID: 41758361
If I ping the Dc via the server name it comes back with above. If I ping using the Ip address the it comes back fine.

The computer that I am trying to connect to the domain is on the same network with the DC. They are local to each other.

Pinging 10.0.0.90 with 32 bytes of data:
Reply from 10.0.0.90: bytes=32 time<1ms TTL=128
Reply from 10.0.0.90: bytes=32 time<1ms TTL=128
Reply from 10.0.0.90: bytes=32 time<1ms TTL=128
Reply from 10.0.0.90: bytes=32 time<1ms TTL=128
0
 
LVL 96

Accepted Solution

by:
Lee W, MVP earned 500 total points
ID: 41758447
I would say stop.

Now, check the workstation:
1. Check the HOSTS file
2. Check the LMHOSTS file
3. Check the DNS settings on the workstation.  They should ONLY point to the server's CURRENT private IP.  There should not be any other DNS servers listed (no ISP DNS servers, no google servers, nothing... JUST the DC).
4. IDEALLY, post screen shots of all of the above.

Now check the server:
1. Does the server's TCP/IP properties DNS listing ONLY point to itself (I prefer by server IP and NOT the loopback address, though that should theoretically be fine)?
2. Restart the netlogon service on the server.  That should re-register all AD records in DNS.

Are things working now?

No?  Try joining the fully qualified domain name instead of the netbios name.

No? Try adding the dns suffix to the system properties of the domain name.

No?  Post screen shots of the server.
0
 
LVL 1

Author Closing Comment

by:mikesmithccs
ID: 41758455
Lee you are a genius. There was a manual entry in the hosts file pointing to the old IP address.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

What to do when Windows Update is not working correctly? What tools can I use to detect the cause of the malfunction problem? What does this numeric error code mean? These and other questions that you have been asking in the past are answered here (…
An article on effective troubleshooting
In this Micro Tutorial viewers will learn how to use Windows Server Backup to create full image of their system. Tutorial shows how to install Windows Server Backup Feature on Windows 2012R2 and how to configure scheduled Bare Metal Recovery backup.…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question