mark hale
asked on
Windows 2012 second DC in AD. DNS issue
So this issue shows up at our remote office (connected via site to site VPN).
This is the DC for that office and after having some odd "hiccups" (NOTE DC1 is in Chicago and shows no issue).
Running BPA I have four errors now.
NIC1 should include loopback address but not as first entry (it's list last).
NIC1 DNS should be configured to register its IP address in DNS ( I checked the box on the NIC properties).
DNS Zone Trusted Anchors secondary server must respond to queries for the zone.
Zone _msdcs.domain.local is an ad integrated zone and must be available.
Any help would be appreciated.
This is the DC for that office and after having some odd "hiccups" (NOTE DC1 is in Chicago and shows no issue).
Running BPA I have four errors now.
NIC1 should include loopback address but not as first entry (it's list last).
NIC1 DNS should be configured to register its IP address in DNS ( I checked the box on the NIC properties).
DNS Zone Trusted Anchors secondary server must respond to queries for the zone.
Zone _msdcs.domain.local is an ad integrated zone and must be available.
Any help would be appreciated.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
what about the results from dcdiag run on both dc's"
ASKER
The only note is DCDiag, There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems. It is on both servers, but I did just add the remote 2012 (Dallas) server (the "old" 2008 is in Chicago). When I run a show repl it all looks ok???
PS C:\> repadmin /showrepl *
Repadmin: running command /showrepl against full DC SSDC2.Domain
Default-First-Site-Name\SS DC2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7 ba0d4c1057
DSA invocationID: ad94f432-17b5-45fd-810b-45 387e9284da
==== INBOUND NEIGHBORS ========================== ========== ==
DC=Domain
Default-First-Site-Name\SS DFW2 via RPC
DSA object GUID: 47a44102-0cee-4c95-8983-67 f42b7985b5
Last attempt @ 2016-09-23 20:19:09 was successful.
CN=Configuration,DC=Domain
Default-First-Site-Name\SS DFW2 via RPC
DSA object GUID: 47a44102-0cee-4c95-8983-67 f42b7985b5
Last attempt @ 2016-09-23 20:17:57 was successful.
CN=Schema,CN=Configuration ,DC=Domain
Default-First-Site-Name\SS DFW2 via RPC
DSA object GUID: 47a44102-0cee-4c95-8983-67 f42b7985b5
Last attempt @ 2016-09-23 20:17:57 was successful.
DC=DomainDnsZones,DC=Domai n
Default-First-Site-Name\SS DFW2 via RPC
DSA object GUID: 47a44102-0cee-4c95-8983-67 f42b7985b5
Last attempt @ 2016-09-23 20:17:57 was successful.
DC=ForestDnsZones,DC=sDoma in
Default-First-Site-Name\SS DFW2 via RPC
DSA object GUID: 47a44102-0cee-4c95-8983-67 f42b7985b5
Last attempt @ 2016-09-23 20:17:57 was successful.
Repadmin: running command /showrepl against full DC SSDFW2.Domain
Default-First-Site-Name\SS DFW2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 47a44102-0cee-4c95-8983-67 f42b7985b5
DSA invocationID: 875b825d-dd7c-4f17-acb3-89 34b42f4e58
==== INBOUND NEIGHBORS ========================== ========== ==
DC=DOMAIN.
Default-First-Site-Name\SS DC2 via RPC
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7 ba0d4c1057
Last attempt @ 2016-09-23 20:18:53 was successful.
CN=Configuration,DC=Domain
Default-First-Site-Name\SS DC2 via RPC
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7 ba0d4c1057
Last attempt @ 2016-09-23 20:18:03 was successful.
CN=Schema,CN=Configuration ,DOMAIN
Default-First-Site-Name\SS DC2 via RPC
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7 ba0d4c1057
Last attempt @ 2016-09-23 20:18:03 was successful.
DC=DomainDnsZones,DC=Domai n
Default-First-Site-Name\SS DC2 via RPC
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7 ba0d4c1057
Last attempt @ 2016-09-23 20:18:03 was successful.
DC=ForestDnsZones,DC=Domai n
Default-First-Site-Name\SS DC2 via RPC
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7 ba0d4c1057
Last attempt @ 2016-09-23 20:18:03 was successful.
Also I created a test user in Chicago and it did replicate to Dallas across the site to site vpn.....
kind of stumped....
PS C:\> repadmin /showrepl *
Repadmin: running command /showrepl against full DC SSDC2.Domain
Default-First-Site-Name\SS
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7
DSA invocationID: ad94f432-17b5-45fd-810b-45
==== INBOUND NEIGHBORS ==========================
DC=Domain
Default-First-Site-Name\SS
DSA object GUID: 47a44102-0cee-4c95-8983-67
Last attempt @ 2016-09-23 20:19:09 was successful.
CN=Configuration,DC=Domain
Default-First-Site-Name\SS
DSA object GUID: 47a44102-0cee-4c95-8983-67
Last attempt @ 2016-09-23 20:17:57 was successful.
CN=Schema,CN=Configuration
Default-First-Site-Name\SS
DSA object GUID: 47a44102-0cee-4c95-8983-67
Last attempt @ 2016-09-23 20:17:57 was successful.
DC=DomainDnsZones,DC=Domai
Default-First-Site-Name\SS
DSA object GUID: 47a44102-0cee-4c95-8983-67
Last attempt @ 2016-09-23 20:17:57 was successful.
DC=ForestDnsZones,DC=sDoma
Default-First-Site-Name\SS
DSA object GUID: 47a44102-0cee-4c95-8983-67
Last attempt @ 2016-09-23 20:17:57 was successful.
Repadmin: running command /showrepl against full DC SSDFW2.Domain
Default-First-Site-Name\SS
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 47a44102-0cee-4c95-8983-67
DSA invocationID: 875b825d-dd7c-4f17-acb3-89
==== INBOUND NEIGHBORS ==========================
DC=DOMAIN.
Default-First-Site-Name\SS
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7
Last attempt @ 2016-09-23 20:18:53 was successful.
CN=Configuration,DC=Domain
Default-First-Site-Name\SS
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7
Last attempt @ 2016-09-23 20:18:03 was successful.
CN=Schema,CN=Configuration
Default-First-Site-Name\SS
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7
Last attempt @ 2016-09-23 20:18:03 was successful.
DC=DomainDnsZones,DC=Domai
Default-First-Site-Name\SS
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7
Last attempt @ 2016-09-23 20:18:03 was successful.
DC=ForestDnsZones,DC=Domai
Default-First-Site-Name\SS
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7
Last attempt @ 2016-09-23 20:18:03 was successful.
Also I created a test user in Chicago and it did replicate to Dallas across the site to site vpn.....
kind of stumped....
ASKER
Unless this has something to do with all the server (DC) upgrades over the years... I do know it all started as an old SBS domain and then NT, win 2k , win 2003 , 2008 and now a new 2012 server added on.... (just thinking various domain function level "upgrades" may have an effect).
ASKER
Remoted dns in Dallas
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = SSDFW2
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\SS DFW2
Starting test: Connectivity
......................... SSDFW2 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\SS DFW2
Starting test: DNS
DNS Tests are running and not hung. Please wait a few minutes...
......................... SSDFW2 passed test DNS
Running partition tests on : ForestDnsZones
Running partition tests on : DomainDnsZones
Running partition tests on : Schema
Running partition tests on : Configuration
Running partition tests on : schulershook
Running enterprise tests on : schulershook.net
Starting test: DNS
......................... Domain passed test DNS
This is curious, if I just ping server name I get this (IPV6 is disabled).
Pinging SSDFW2.domain [::1] with 32 bytes of data:
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Ping statistics for ::1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = SSDFW2
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\SS
Starting test: Connectivity
......................... SSDFW2 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\SS
Starting test: DNS
DNS Tests are running and not hung. Please wait a few minutes...
......................... SSDFW2 passed test DNS
Running partition tests on : ForestDnsZones
Running partition tests on : DomainDnsZones
Running partition tests on : Schema
Running partition tests on : Configuration
Running partition tests on : schulershook
Running enterprise tests on : schulershook.net
Starting test: DNS
......................... Domain passed test DNS
This is curious, if I just ping server name I get this (IPV6 is disabled).
Pinging SSDFW2.domain [::1] with 32 bytes of data:
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Ping statistics for ::1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
now from the other domain controller
ASKER
Sorry Thought I posted it.
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = SSDC2
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\SS DC2
Starting test: Connectivity
......................... SSDC2 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\SS DC2
Starting test: DNS
DNS Tests are running and not hung. Please wait a few minutes...
......................... SSDC2 passed test DNS
Running partition tests on : ForestDnsZones
Running partition tests on : DomainDnsZones
Running partition tests on : Schema
Running partition tests on : Configuration
Running partition tests on : schulershook
Running enterprise tests on : sdomain
Starting test: DNS
......................... domain passed test DNS
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = SSDC2
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\SS
Starting test: Connectivity
......................... SSDC2 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\SS
Starting test: DNS
DNS Tests are running and not hung. Please wait a few minutes...
......................... SSDC2 passed test DNS
Running partition tests on : ForestDnsZones
Running partition tests on : DomainDnsZones
Running partition tests on : Schema
Running partition tests on : Configuration
Running partition tests on : schulershook
Running enterprise tests on : sdomain
Starting test: DNS
......................... domain passed test DNS
ASKER
I did end up deleting the old _msdc folder as it became greyed out and was causing errors but David certainly put me on the correct path!
ASKER
PS C:\repadmin /showrepl * /errorsonly
Repadmin: running command /showrepl against full DC SSDC2.Domain name
Default-First-Site-Name\SS
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 72fe5fdb-4e8e-441e-88f4-e7
DSA invocationID: 2a7f5d31-4b8d-4700-9cbd-5a
==== INBOUND NEIGHBORS ==========================
Repadmin: running command /showrepl against full DC SSDFW2.domain name
Default-First-Site-Name\SS
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: caeec2f0-75d5-47c1-b3f8-ff
DSA invocationID: fdcd30a4-702c-432f-9588-4d
==== INBOUND NEIGHBORS ==========================