Solved

Windows 2012 second DC in AD. DNS issue

Posted on 2016-09-23
9
41 Views
Last Modified: 2016-10-14
So this issue shows up at our remote office (connected via site to site VPN).
This is the DC for that office and after having some odd "hiccups"  (NOTE DC1 is in Chicago and shows no issue).
Running BPA I have four errors now.
NIC1 should include loopback address but not as first entry (it's list last).
NIC1 DNS should be configured to register its IP address in DNS ( I checked the box on the NIC properties).
DNS Zone Trusted Anchors secondary server must respond to queries for the zone.
Zone _msdcs.domain.local is an ad integrated zone and must be available.

Any help would be appreciated.
0
Comment
Question by:mark hale
  • 6
  • 3
9 Comments
 
LVL 78

Accepted Solution

by:
David Johnson, CD, MVP earned 500 total points
ID: 41812874
you obviously are having replication problems from office and DC1
Repadmin /showrepl will give you some information on your replication
https://technet.microsoft.com/library/cc742066(v=ws.10).aspx
0
 

Author Comment

by:mark hale
ID: 41813108
Thanks for your reply David!  I ran the command but don't see any errors.

PS C:\repadmin /showrepl * /errorsonly

Repadmin: running command /showrepl against full DC SSDC2.Domain name
Default-First-Site-Name\SSDC2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
DSA invocationID: 2a7f5d31-4b8d-4700-9cbd-5a5b039a60a2

==== INBOUND NEIGHBORS ======================================

Repadmin: running command /showrepl against full DC SSDFW2.domain name
Default-First-Site-Name\SSDFW2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: caeec2f0-75d5-47c1-b3f8-ffafa9572366
DSA invocationID: fdcd30a4-702c-432f-9588-4d402fe89307

==== INBOUND NEIGHBORS ======================================
0
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 41813260
what about the results from dcdiag run on both dc's"
0
 

Author Comment

by:mark hale
ID: 41813289
The only note is DCDiag, There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems.  It is on both servers, but I did just add the remote 2012 (Dallas)  server (the "old" 2008 is in Chicago). When I run a show repl it all looks ok???

PS C:\> repadmin /showrepl *

Repadmin: running command /showrepl against full DC SSDC2.Domain
Default-First-Site-Name\SSDC2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
DSA invocationID: ad94f432-17b5-45fd-810b-45387e9284da

==== INBOUND NEIGHBORS ======================================

DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:19:09 was successful.

CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

CN=Schema,CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

DC=DomainDnsZones,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

DC=ForestDnsZones,DC=sDomain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

Repadmin: running command /showrepl against full DC SSDFW2.Domain
Default-First-Site-Name\SSDFW2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
DSA invocationID: 875b825d-dd7c-4f17-acb3-8934b42f4e58

==== INBOUND NEIGHBORS ======================================

DC=DOMAIN.
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:53 was successful.

CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

CN=Schema,CN=Configuration,DOMAIN
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

DC=DomainDnsZones,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

DC=ForestDnsZones,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.


Also I created a test user in Chicago and it did replicate to Dallas across the site to site vpn.....

kind of stumped....
0
 

Author Comment

by:mark hale
ID: 41813316
Unless this has something to do with all the server (DC) upgrades over the years... I do know it all started as an old SBS domain and then NT, win 2k , win 2003 , 2008 and now a new 2012 server added on.... (just thinking various domain function level "upgrades" may have an effect).
0
 

Author Comment

by:mark hale
ID: 41813822
Remoted dns in Dallas
Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SSDFW2
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SSDFW2
      Starting test: Connectivity
         ......................... SSDFW2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SSDFW2

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SSDFW2 passed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : schulershook

   Running enterprise tests on : schulershook.net
      Starting test: DNS
         ......................... Domain passed test DNS

This is curious, if I just ping server name I get this (IPV6 is disabled).

Pinging SSDFW2.domain [::1] with 32 bytes of data:
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms

Ping statistics for ::1:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
0
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 41813916
now from the other domain controller
0
 

Author Comment

by:mark hale
ID: 41814100
Sorry Thought I posted it.

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SSDC2
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SSDC2
      Starting test: Connectivity
         ......................... SSDC2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SSDC2

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SSDC2 passed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : schulershook

   Running enterprise tests on : sdomain
      Starting test: DNS
         ......................... domain passed test DNS
0
 

Author Closing Comment

by:mark hale
ID: 41844271
I did end up deleting the old _msdc folder as it became greyed out and was causing errors but David certainly put me on the correct path!
0

Join & Write a Comment

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…
In this Micro Tutorial viewers will learn how to restore single file or folder from Bare Metal backup image of their system. Tutorial shows how to restore files and folders from system backup. Often it is not needed to restore entire system when onl…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now