Solved

Windows 2012 second DC in AD. DNS issue

Posted on 2016-09-23
9
67 Views
Last Modified: 2016-10-14
So this issue shows up at our remote office (connected via site to site VPN).
This is the DC for that office and after having some odd "hiccups"  (NOTE DC1 is in Chicago and shows no issue).
Running BPA I have four errors now.
NIC1 should include loopback address but not as first entry (it's list last).
NIC1 DNS should be configured to register its IP address in DNS ( I checked the box on the NIC properties).
DNS Zone Trusted Anchors secondary server must respond to queries for the zone.
Zone _msdcs.domain.local is an ad integrated zone and must be available.

Any help would be appreciated.
0
Comment
Question by:mark hale
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
9 Comments
 
LVL 81

Accepted Solution

by:
David Johnson, CD, MVP earned 500 total points
ID: 41812874
you obviously are having replication problems from office and DC1
Repadmin /showrepl will give you some information on your replication
https://technet.microsoft.com/library/cc742066(v=ws.10).aspx
0
 

Author Comment

by:mark hale
ID: 41813108
Thanks for your reply David!  I ran the command but don't see any errors.

PS C:\repadmin /showrepl * /errorsonly

Repadmin: running command /showrepl against full DC SSDC2.Domain name
Default-First-Site-Name\SSDC2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
DSA invocationID: 2a7f5d31-4b8d-4700-9cbd-5a5b039a60a2

==== INBOUND NEIGHBORS ======================================

Repadmin: running command /showrepl against full DC SSDFW2.domain name
Default-First-Site-Name\SSDFW2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: caeec2f0-75d5-47c1-b3f8-ffafa9572366
DSA invocationID: fdcd30a4-702c-432f-9588-4d402fe89307

==== INBOUND NEIGHBORS ======================================
0
 
LVL 81

Expert Comment

by:David Johnson, CD, MVP
ID: 41813260
what about the results from dcdiag run on both dc's"
0
Edgartown IT Case Study

Learn about Edgartown's quest to ensure the safety and security of the entire town's employee and citizen data. Read the case study!

 

Author Comment

by:mark hale
ID: 41813289
The only note is DCDiag, There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems.  It is on both servers, but I did just add the remote 2012 (Dallas)  server (the "old" 2008 is in Chicago). When I run a show repl it all looks ok???

PS C:\> repadmin /showrepl *

Repadmin: running command /showrepl against full DC SSDC2.Domain
Default-First-Site-Name\SSDC2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
DSA invocationID: ad94f432-17b5-45fd-810b-45387e9284da

==== INBOUND NEIGHBORS ======================================

DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:19:09 was successful.

CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

CN=Schema,CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

DC=DomainDnsZones,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

DC=ForestDnsZones,DC=sDomain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

Repadmin: running command /showrepl against full DC SSDFW2.Domain
Default-First-Site-Name\SSDFW2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
DSA invocationID: 875b825d-dd7c-4f17-acb3-8934b42f4e58

==== INBOUND NEIGHBORS ======================================

DC=DOMAIN.
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:53 was successful.

CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

CN=Schema,CN=Configuration,DOMAIN
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

DC=DomainDnsZones,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

DC=ForestDnsZones,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.


Also I created a test user in Chicago and it did replicate to Dallas across the site to site vpn.....

kind of stumped....
0
 

Author Comment

by:mark hale
ID: 41813316
Unless this has something to do with all the server (DC) upgrades over the years... I do know it all started as an old SBS domain and then NT, win 2k , win 2003 , 2008 and now a new 2012 server added on.... (just thinking various domain function level "upgrades" may have an effect).
0
 

Author Comment

by:mark hale
ID: 41813822
Remoted dns in Dallas
Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SSDFW2
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SSDFW2
      Starting test: Connectivity
         ......................... SSDFW2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SSDFW2

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SSDFW2 passed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : schulershook

   Running enterprise tests on : schulershook.net
      Starting test: DNS
         ......................... Domain passed test DNS

This is curious, if I just ping server name I get this (IPV6 is disabled).

Pinging SSDFW2.domain [::1] with 32 bytes of data:
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms

Ping statistics for ::1:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
0
 
LVL 81

Expert Comment

by:David Johnson, CD, MVP
ID: 41813916
now from the other domain controller
0
 

Author Comment

by:mark hale
ID: 41814100
Sorry Thought I posted it.

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SSDC2
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SSDC2
      Starting test: Connectivity
         ......................... SSDC2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SSDC2

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SSDC2 passed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : schulershook

   Running enterprise tests on : sdomain
      Starting test: DNS
         ......................... domain passed test DNS
0
 

Author Closing Comment

by:mark hale
ID: 41844271
I did end up deleting the old _msdc folder as it became greyed out and was causing errors but David certainly put me on the correct path!
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
In this Micro Tutorial viewers will learn how to restore their server from Bare Metal Backup image created with Windows Server Backup feature. As an example Windows 2012R2 is used.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question