Link to home
Start Free TrialLog in
Avatar of mark hale
mark hale

asked on

Windows 2012 second DC in AD. DNS issue

So this issue shows up at our remote office (connected via site to site VPN).
This is the DC for that office and after having some odd "hiccups"  (NOTE DC1 is in Chicago and shows no issue).
Running BPA I have four errors now.
NIC1 should include loopback address but not as first entry (it's list last).
NIC1 DNS should be configured to register its IP address in DNS ( I checked the box on the NIC properties).
DNS Zone Trusted Anchors secondary server must respond to queries for the zone.
Zone _msdcs.domain.local is an ad integrated zone and must be available.

Any help would be appreciated.
ASKER CERTIFIED SOLUTION
Avatar of David Johnson, CD
David Johnson, CD
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of mark hale
mark hale

ASKER

Thanks for your reply David!  I ran the command but don't see any errors.

PS C:\repadmin /showrepl * /errorsonly

Repadmin: running command /showrepl against full DC SSDC2.Domain name
Default-First-Site-Name\SSDC2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
DSA invocationID: 2a7f5d31-4b8d-4700-9cbd-5a5b039a60a2

==== INBOUND NEIGHBORS ======================================

Repadmin: running command /showrepl against full DC SSDFW2.domain name
Default-First-Site-Name\SSDFW2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: caeec2f0-75d5-47c1-b3f8-ffafa9572366
DSA invocationID: fdcd30a4-702c-432f-9588-4d402fe89307

==== INBOUND NEIGHBORS ======================================
what about the results from dcdiag run on both dc's"
The only note is DCDiag, There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems.  It is on both servers, but I did just add the remote 2012 (Dallas)  server (the "old" 2008 is in Chicago). When I run a show repl it all looks ok???

PS C:\> repadmin /showrepl *

Repadmin: running command /showrepl against full DC SSDC2.Domain
Default-First-Site-Name\SSDC2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
DSA invocationID: ad94f432-17b5-45fd-810b-45387e9284da

==== INBOUND NEIGHBORS ======================================

DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:19:09 was successful.

CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

CN=Schema,CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

DC=DomainDnsZones,DC=Domain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

DC=ForestDnsZones,DC=sDomain
    Default-First-Site-Name\SSDFW2 via RPC
        DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
        Last attempt @ 2016-09-23 20:17:57 was successful.

Repadmin: running command /showrepl against full DC SSDFW2.Domain
Default-First-Site-Name\SSDFW2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 47a44102-0cee-4c95-8983-67f42b7985b5
DSA invocationID: 875b825d-dd7c-4f17-acb3-8934b42f4e58

==== INBOUND NEIGHBORS ======================================

DC=DOMAIN.
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:53 was successful.

CN=Configuration,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

CN=Schema,CN=Configuration,DOMAIN
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

DC=DomainDnsZones,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.

DC=ForestDnsZones,DC=Domain
    Default-First-Site-Name\SSDC2 via RPC
        DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7ba0d4c1057
        Last attempt @ 2016-09-23 20:18:03 was successful.


Also I created a test user in Chicago and it did replicate to Dallas across the site to site vpn.....

kind of stumped....
Unless this has something to do with all the server (DC) upgrades over the years... I do know it all started as an old SBS domain and then NT, win 2k , win 2003 , 2008 and now a new 2012 server added on.... (just thinking various domain function level "upgrades" may have an effect).
Remoted dns in Dallas
Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SSDFW2
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SSDFW2
      Starting test: Connectivity
         ......................... SSDFW2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SSDFW2

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SSDFW2 passed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : schulershook

   Running enterprise tests on : schulershook.net
      Starting test: DNS
         ......................... Domain passed test DNS

This is curious, if I just ping server name I get this (IPV6 is disabled).

Pinging SSDFW2.domain [::1] with 32 bytes of data:
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms

Ping statistics for ::1:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
now from the other domain controller
Sorry Thought I posted it.

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SSDC2
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SSDC2
      Starting test: Connectivity
         ......................... SSDC2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SSDC2

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SSDC2 passed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : schulershook

   Running enterprise tests on : sdomain
      Starting test: DNS
         ......................... domain passed test DNS
I did end up deleting the old _msdc folder as it became greyed out and was causing errors but David certainly put me on the correct path!