Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Windows 2012 second DC in AD. DNS issue

Posted on 2016-09-23
9
Medium Priority
?
77 Views
Last Modified: 2016-10-14
So this issue shows up at our remote office (connected via site to site VPN).
This is the DC for that office and after having some odd "hiccups"  (NOTE DC1 is in Chicago and shows no issue).
Running BPA I have four errors now.
NIC1 should include loopback address but not as first entry (it's list last).
NIC1 DNS should be configured to register its IP address in DNS ( I checked the box on the NIC properties).
DNS Zone Trusted Anchors secondary server must respond to queries for the zone.
Zone _msdcs.domain.local is an ad integrated zone and must be available.

Any help would be appreciated.
0
Comment
Question by:mark hale
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
9 Comments
 
LVL 83

Accepted Solution

by:
David Johnson, CD, MVP earned 2000 total points
ID: 41812874
you obviously are having replication problems from office and DC1
Repadmin /showrepl will give you some information on your replication
https://technet.microsoft.com/library/cc742066(v=ws.10).aspx
0
 

Author Comment

by:mark hale
ID: 41813108
Thanks for your reply David!  I ran the command but don't see any errors.

PS C:\repadmin /showrepl * /errorsonly

Repadmin: running command /showrepl against full DC SSDC2.Domain name
Default-First-Site-Name\SSDC2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
DSA invocationID: 2a7f5d31-4b8d-4700-9cbd-5a5b039a60a2

==== INBOUND NEIGHBORS ======================================

Repadmin: running command /showrepl against full DC SSDFW2.domain name
Default-First-Site-Name\SSDFW2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: caeec2f0-75d5-47c1-b3f8-ffafa9572366
DSA invocationID: fdcd30a4-702c-432f-9588-4d402fe89307

==== INBOUND NEIGHBORS ======================================
0
 
LVL 83

Expert Comment

by:David Johnson, CD, MVP
ID: 41813260
what about the results from dcdiag run on both dc's"
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:mark hale
ID: 41813289
The only note is DCDiag, There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems.  It is on both servers, but I did just add the remote 2012 (Dallas)  server (the "old" 2008 is in Chicago). When I run a show repl it all looks ok???

PS C:\> repadmin /showrepl *

Repadmin: running command /showrepl against full DC SSDC2.Domain
Default-First-Site-Name\SSDC2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
DSA invocationID: ad94f432-17b5-45fd-810b-45387e9284da

==== INBOUND NEIGHBORS ======================================

DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:19:09 was successful.

CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

CN=Schema,CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

DC=DomainDnsZones,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

DC=ForestDnsZones,DC=sDomain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

Repadmin: running command /showrepl against full DC SSDFW2.Domain
Default-First-Site-Name\SSDFW2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
DSA invocationID: 875b825d-dd7c-4f17-acb3-8934b42f4e58

==== INBOUND NEIGHBORS ======================================

DC=DOMAIN.
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:53 was successful.

CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

CN=Schema,CN=Configuration,DOMAIN
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

DC=DomainDnsZones,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

DC=ForestDnsZones,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.


Also I created a test user in Chicago and it did replicate to Dallas across the site to site vpn.....

kind of stumped....
0
 

Author Comment

by:mark hale
ID: 41813316
Unless this has something to do with all the server (DC) upgrades over the years... I do know it all started as an old SBS domain and then NT, win 2k , win 2003 , 2008 and now a new 2012 server added on.... (just thinking various domain function level "upgrades" may have an effect).
0
 

Author Comment

by:mark hale
ID: 41813822
Remoted dns in Dallas
Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SSDFW2
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SSDFW2
      Starting test: Connectivity
         ......................... SSDFW2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SSDFW2

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SSDFW2 passed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : schulershook

   Running enterprise tests on : schulershook.net
      Starting test: DNS
         ......................... Domain passed test DNS

This is curious, if I just ping server name I get this (IPV6 is disabled).

Pinging SSDFW2.domain [::1] with 32 bytes of data:
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms

Ping statistics for ::1:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
0
 
LVL 83

Expert Comment

by:David Johnson, CD, MVP
ID: 41813916
now from the other domain controller
0
 

Author Comment

by:mark hale
ID: 41814100
Sorry Thought I posted it.

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SSDC2
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SSDC2
      Starting test: Connectivity
         ......................... SSDC2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SSDC2

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SSDC2 passed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : schulershook

   Running enterprise tests on : sdomain
      Starting test: DNS
         ......................... domain passed test DNS
0
 

Author Closing Comment

by:mark hale
ID: 41844271
I did end up deleting the old _msdc folder as it became greyed out and was causing errors but David certainly put me on the correct path!
0

Featured Post

Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
In this Micro Tutorial viewers will learn how they can get their files copied out from their unbootable system without need to use recovery services. As an example non-bootable Windows 2012R2 installation is used which has boot problems.
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…

598 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question