Link to home
Start Free TrialLog in
Avatar of Emeka Ibekweh
Emeka IbekwehFlag for United States of America

asked on

Can't promote Server 2019

Hi.  We were experiencing what seemed to be DNS issues (among other issues) with this domain controller (CBLSDC01) 10.105.1.12.  We demoted and removed the AD roles.  Now, we're unable to promote this server.  I've tried the following:

  • Using the IP address of the PDC (located in another subnet via our ELAN) 10.100.1.14 as the primary DNS server on CBLSDC01
  • Adding host file entries for two other domain controllers (FQDNs and short names) at another site since I can't ping them by hostname, but can ping via IP address

See attachments for error messages.
domain.PNG
promo.PNG
Avatar of DrDave242
DrDave242
Flag of United States of America image

These two things - the error stating that a DC for the domain couldn't be located and an inability to ping existing DCs by name - do indeed suggest that you've got a DNS problem. Can you check DNS on one of the existing DCs to see whether the expected zones and records are present? This article gives an overview of the DNS records you should find.
Avatar of Emeka Ibekweh

ASKER

Yes, DNS is functioning correctly on the other DCs.
If you use nslookup to send DNS queries to the existing DCs from the server that can't be promoted, are you able to get responses?
Yes; that (and pings) works.  BACSDC02 to CBLSDC01.
The domain.png screenshot shows that it was looking for a domain controller in the domain "10.100.1.14" rather than the actual domain name. Do you know what caused that?
I’m thinking the host file entries. Without that, I can’t ping by DNS name.
Can you remove the host file entries, flush the resolver cache (ipconfig /flushdns) and try promoting again? Please post the resulting error, as its description section contains a lot of information that could be useful.
Completed as per your request.
error.txt
It tells you that it cannot find the SRV records. Look in the DNS zone for your domain and make sure you see the SRV records. Should be 4 folders called. _msdcs, _Sites,_UDP, _TCP, and perhaps _DomainDNSZones. Each of these will hold SRV records for your domain. IF they are missing, make sure the Zone will accept updates and then restart the netlogon service of a functioning DC that has that DNS server as its primary.
All of those folders are located there.  See attachment.
Untitled.png
And do they have SRV records for your active DCs?
Yes, that’s correct.
Ah, I think I see the problem in that latest screenshot. Since you've got a separate forward lookup zone for _msdcs.ascendlearning.org, the _msdcs folder inside the ascendlearning.org zone shouldn't contain anything. In fact, it should be a delegation instead of an actual folder/subdomain. A delegation will appear in the console as a gray folder, which is how I can tell it's not one currently.

To properly fix this, you'll need to delete that _msdcs folder, recreate it as a delegation (right-click the ascendlearning.org zone, select New > Delegation, and follow the prompts), and then have your DCs re-register their DNS records (ipconfig /flushdns, ipconfig /registerdns, and restart the Netlogon service for the SRV records). That may sound a little scary, since you're deleting stuff along with that folder, but if everything else is working, the deleted records will reappear in the _msdcs.ascendlearning.org zone where they belong.
Same result.  See attachments.
new-error.txt
DNS-entries.PNG
Expand that _msdcs.ascendlearning.org zone, then expand dc and _tcp. Is there at least one SRV record named _ldap there?
See attachment.
DNS-entries2.PNG
If you were referring to the _msdcs.ascendlearning.org zone above the ascendlearning.org zone, then there are a number of SRV records named _ldap

Any thoughts?
Could part of the issue be that when I do an nslookup of my domain name on this DC (CBLSDC01), it returns the IP addresses of our website, under non-authoritative answer?
Could part of the issue be that when I do an nslookup of my domain name on this DC (CBLSDC01), it returns the IP addresses of our website, under non-authoritative answer?

That shouldn't cause this issue; the modern DC locator process doesn't use those records, which are there for legacy purposes. It's still not really a good thing to mess with them, though. When you do an nslookup for the domain name, you should receive only host records for your DCs.

If you were referring to the _msdcs.ascendlearning.org zone above the ascendlearning.org zone, then there are a number of SRV records named _ldap

Yep, that's the zone I'm referring to. Can you post a screenshot showing those records?
ASKER CERTIFIED SOLUTION
Avatar of Emeka Ibekweh
Emeka Ibekweh
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial