ccwait
asked on
DNS Broken Delegations
How would you troubleshoot DNS broken delegations?
ASKER
ccwa.us is our domain name and we were using dcdiag /test:dns to see the broken delegation issue. How would I go about getting the zonefile?
No need to provide the zonefile for what appears to be an AD domain.
Most likely what you're seeing is in relation to the _msdcs.yourdomain.com zone. In the yourdomain.com zone there should be a delegation (appears as kind of a grayed out icon) for _msdcs. Open the delegation, then right click on it and go to properties. On the name servers tab, remove any invalid entries. I generally will recommend to include all your DC/DNS servers.
Most likely what you're seeing is in relation to the _msdcs.yourdomain.com zone. In the yourdomain.com zone there should be a delegation (appears as kind of a grayed out icon) for _msdcs. Open the delegation, then right click on it and go to properties. On the name servers tab, remove any invalid entries. I generally will recommend to include all your DC/DNS servers.
ASKER
I did that however it is still saying that delegation failed when I run the tests. I went through DNS Manager and removed all references to old DC's that we had before
Can you run dcdiag /v /test:dns and provide what it says about delegations?
ASKER
So I ran the test and these are the errors that I am getting for all four of our domain controllers:
DC1: [Error details: 9501 (Type: Win32 - Description: No records found for given DNS query.)]
DC2: [Error details: 9501 (Type: Win32 - Description: No records found for given DNS query.)]
DC3: [Error details: 9501 (Type: Win32 - Description: No records found for given DNS query.)]
DC4: [Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
The fourth domain is our main Domain Controller with all the FSMO roles.
All four DC's also state this: DNS delegation for the domain domain.com.domain.com. is broken on IP (DC's IP)
DC1: [Error details: 9501 (Type: Win32 - Description: No records found for given DNS query.)]
DC2: [Error details: 9501 (Type: Win32 - Description: No records found for given DNS query.)]
DC3: [Error details: 9501 (Type: Win32 - Description: No records found for given DNS query.)]
DC4: [Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
The fourth domain is our main Domain Controller with all the FSMO roles.
All four DC's also state this: DNS delegation for the domain domain.com.domain.com. is broken on IP (DC's IP)
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
We deleted the records that were in the subdomain. That seemed to work. Thanks. !!
What is solution
Solutions will likely require some simple modification of your domain zone file.
If you have access to your zonefile, post it + this will speed up answering you too.