Link to home
Start Free TrialLog in
Avatar of Snowy Canada
Snowy CanadaFlag for Canada

asked on

The whole host record is missing under Forward Lookup Zone

We have three Active Directory DC, DC1, DC2 and DC3. All the DC has DNS role.
On DC1 all host record is missing, as below image shows.
 User generated imageOn DC2 and DC3, record is still exist.
I had tried replicate from DC2 and DC3 on Active Directory Sites and Services.
The message shows Active Directory Domain Services has replicated the connections.
Back to DNS server, still no any of host record.

Question: How to replicate DNS record successfully from other DC?

Tried dcdiag /fix

Here is the output

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = DC1
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Connectivity
         ......................... DC1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Advertising
         ......................... DC1 passed test Advertising
      Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... DC1 passed test FrsEvent
      Starting test: DFSREvent
         ......................... DC1 passed test DFSREvent
      Starting test: SysVolCheck
         ......................... DC1 passed test SysVolCheck
      Starting test: KccEvent
         A warning event occurred.  EventID: 0x8000051C
            Time Generated: 07/07/2020   13:01:25
            Event String:
            The Knowledge Consistency Checker (KCC) has detected that successive
 attempts to replicate with the following directory service has consistently fai
led.
         A warning event occurred.  EventID: 0x8000051C
            Time Generated: 07/07/2020   13:01:25
            Event String:
            The Knowledge Consistency Checker (KCC) has detected that successive
 attempts to replicate with the following directory service has consistently fai
led.
         ......................... DC1 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... DC1 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... DC1 passed test MachineAccount
      Starting test: NCSecDesc
         ......................... DC1 passed test NCSecDesc
      Starting test: NetLogons
         [DC1] User credentials does not have permission to perform this
         operation.
         The account used for this test must have network logon privileges
         for this machine's domain.
         ......................... DC1 failed test NetLogons
      Starting test: ObjectsReplicated
         ......................... DC1 passed test ObjectsReplicated
      Starting test: Replications
         [Replications Check,DC1] A recent replication attempt failed:
            From DC2 to DC1
            Naming Context: DC=ForestDnsZones,DC=Getcha,DC=ca
            The replication generated an error (1256):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.

            The failure occurred at 2020-07-07 12:57:07.
            The last success occurred at 2020-07-07 10:56:55.
            2 failures have occurred since the last success.
         [Replications Check,DC1] A recent replication attempt failed:
            From DC3 to DC1
            Naming Context: DC=ForestDnsZones,DC=Getcha,DC=ca
            The replication generated an error (1256):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.

            The failure occurred at 2020-07-07 12:57:50.
            The last success occurred at 2020-07-07 10:56:55.
            2 failures have occurred since the last success.
         [Replications Check,DC1] A recent replication attempt failed:
            From DC2 to DC1
            Naming Context: DC=DomainDnsZones,DC=Getcha,DC=ca
            The replication generated an error (1256):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.

            The failure occurred at 2020-07-07 12:57:07.
            The last success occurred at 2020-07-07 10:56:55.
            2 failures have occurred since the last success.
         [Replications Check,DC1] A recent replication attempt failed:
            From DC3 to DC1
            Naming Context: DC=DomainDnsZones,DC=Getcha,DC=ca
            The replication generated an error (1256):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.

            The failure occurred at 2020-07-07 12:57:50.
            The last success occurred at 2020-07-07 10:56:55.
            2 failures have occurred since the last success.
         ......................... DC1 failed test Replications
      Starting test: RidManager
         ......................... DC1 passed test RidManager
      Starting test: Services
            Could not open NTDS Service on DC1, error 0x5
            "Access is denied."
         ......................... DC1 failed test Services
      Starting test: SystemLog
         A warning event occurred.  EventID: 0xA004001B
            Time Generated: 07/07/2020   12:14:16
            EvtFormatMessage failed, error 15027 the message resource is present
 but the message is not found in the string/message table.
            (Event String (event log = System) could not be retrieved, error
            0x3ab3)
         An error event occurred.  EventID: 0x0000165B
            Time Generated: 07/07/2020   12:14:35
            Event String:
            The session setup from computer 'SHARE03' failed because the securit
y database does not contain a trust account 'SHARE03$' referenced by the specifi
ed computer.
         A warning event occurred.  EventID: 0xA004001B
            Time Generated: 07/07/2020   12:14:52
            EvtFormatMessage failed, error 15027 the message resource is present
 but the message is not found in the string/message table.
            (Event String (event log = System) could not be retrieved, error
            0x3ab3)
         An error event occurred.  EventID: 0x000016AD
            Time Generated: 07/07/2020   12:20:59
            Event String:
            The session setup from the computer SHARE03 failed to authenticate.
The following error occurred:
         A warning event occurred.  EventID: 0xA004001B
            Time Generated: 07/07/2020   12:58:39
            EvtFormatMessage failed, error 15027 the message resource is present
 but the message is not found in the string/message table.
            (Event String (event log = System) could not be retrieved, error
            0x3ab3)
         A warning event occurred.  EventID: 0xA004001B
            Time Generated: 07/07/2020   12:59:52
            EvtFormatMessage failed, error 15027 the message resource is present
 but the message is not found in the string/message table.
            (Event String (event log = System) could not be retrieved, error
            0x3ab3)
         A warning event occurred.  EventID: 0xA004001B
            Time Generated: 07/07/2020   13:02:00
            EvtFormatMessage failed, error 15027 the message resource is present
 but the message is not found in the string/message table.
            (Event String (event log = System) could not be retrieved, error
            0x3ab3)
         A warning event occurred.  EventID: 0xA004001B
            Time Generated: 07/07/2020   13:02:23
            EvtFormatMessage failed, error 15027 the message resource is present
 but the message is not found in the string/message table.
            (Event String (event log = System) could not be retrieved, error
            0x3ab3)
         A warning event occurred.  EventID: 0xA004001B
            Time Generated: 07/07/2020   13:08:45
            EvtFormatMessage failed, error 15027 the message resource is present
 but the message is not found in the string/message table.
            (Event String (event log = System) could not be retrieved, error
            0x3ab3)
         ......................... DC1 failed test SystemLog
      Starting test: VerifyReferences
         ......................... DC1 passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : Getcha
      Starting test: CheckSDRefDom
         ......................... Getcha passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Getcha passed test CrossRefValidation

   Running enterprise tests on : Getcha.ca
      Starting test: LocatorCheck
         ......................... Getcha.ca passed test LocatorCheck
      Starting test: Intersite
         ......................... Getcha.ca passed test Intersite
Avatar of David Johnson, CD
David Johnson, CD
Flag of Canada image

quick fix, remove ADDS role from DC1, reboot, dcpromo dc1 again.
Avatar of Snowy Canada

ASKER

The DC is running as a workstation VM, and has daily backup, If I restore DC1 from days ago version, is there any side effect?

Generally, restoring a DC from a backup is one of your last options.  There could definitely be side-effects, depending on how that backup was taken, etc.

The DC is running as a workstation VM ....
That's pretty concerning, and doesn't sound like a good situation at all.

Your dcdiag results show issues with replication (so far I only see DomainDnsZones and ForestDnsZones contexts mentioned, other contexts may be healthy). Have you looked in your event logs to see how far they go back?  What other errors are there?  Are you running your dcdiag commands from within an elevated prompt?  What's the result of running the following?
repadmin /showrepl
Where are your FSMO roles?
I ran DCdiag within elevated prompt.

The DC1 has all five FSMO roles, but last night I moved these roles to DC2. I removed all the roles from DC1 including Active Directory, then rejoin domain (I didn't delete DC1 from ADUC), and add DNS role, but still hasn't any host record.

In event viewer, no special event is recorded while replication running.

Tonight I will disjoin Dc and then delete it on DC2 ADUC, then try join, add roles again. Hope it works.

Here is the output of repadmin command

C:\Windows\system32>repadmin /showrepl

Repadmin: running command /showrepl against full DC localhost
Default-First-Site-Name\DC1
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 30fa2f98-7117-42b1-9d67-083f3d2e3392
DSA invocationID: 7026897c-e836-4d6d-8f1f-3b5ac172453f

==== INBOUND NEIGHBORS ======================================

DC=Getcha,DC=ca
    Default-First-Site-Name\DC3 via RPC
        DSA object GUID: b379e868-cb1b-4939-8c3d-01eff26eeb15
        Last attempt @ 2020-07-08 11:00:51 was successful.
    Default-First-Site-Name\DC2 via RPC
        DSA object GUID: 70da75e4-1511-4493-b200-87193a02c552
        Last attempt @ 2020-07-08 11:00:54 was successful.

CN=Configuration,DC=Getcha,DC=ca
    Default-First-Site-Name\DC3 via RPC
        DSA object GUID: b379e868-cb1b-4939-8c3d-01eff26eeb15
        Last attempt @ 2020-07-08 10:56:52 failed, result 1722 (0x6ba):
            The RPC server is unavailable.
        12 consecutive failure(s).
        Last success @ 2020-07-07 23:45:55.
    Default-First-Site-Name\DC2 via RPC
        DSA object GUID: 70da75e4-1511-4493-b200-87193a02c552
        Last attempt @ 2020-07-08 10:57:37 failed, result 1722 (0x6ba):
            The RPC server is unavailable.
        12 consecutive failure(s).
        Last success @ 2020-07-07 23:46:03.

CN=Schema,CN=Configuration,DC=Getcha,DC=ca
    Default-First-Site-Name\DC2 via RPC
        DSA object GUID: 70da75e4-1511-4493-b200-87193a02c552
        Last attempt @ 2020-07-08 10:58:19 failed, result 1722 (0x6ba):
            The RPC server is unavailable.
        12 consecutive failure(s).
        Last success @ 2020-07-07 23:40:55.
    Default-First-Site-Name\DC3 via RPC
        DSA object GUID: b379e868-cb1b-4939-8c3d-01eff26eeb15
        Last attempt @ 2020-07-08 10:59:01 failed, result 1722 (0x6ba):
            The RPC server is unavailable.
        12 consecutive failure(s).
        Last success @ 2020-07-07 23:45:25.

DC=DomainDnsZones,DC=Getcha,DC=ca
    Default-First-Site-Name\DC3 via RPC
        DSA object GUID: b379e868-cb1b-4939-8c3d-01eff26eeb15
        Last attempt @ 2020-07-08 10:56:10 failed, result 1256 (0x4e8):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.
        12 consecutive failure(s).
        Last success @ 2020-07-07 23:45:25.
    Default-First-Site-Name\DC2 via RPC
        DSA object GUID: 70da75e4-1511-4493-b200-87193a02c552
        Last attempt @ 2020-07-08 10:57:37 failed, result 1256 (0x4e8):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.
        12 consecutive failure(s).
        Last success @ 2020-07-07 23:40:55.

DC=ForestDnsZones,DC=Getcha,DC=ca
    Default-First-Site-Name\DC3 via RPC
        DSA object GUID: b379e868-cb1b-4939-8c3d-01eff26eeb15
        Last attempt @ 2020-07-08 10:56:10 failed, result 1256 (0x4e8):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.
        12 consecutive failure(s).
        Last success @ 2020-07-07 23:45:25.
    Default-First-Site-Name\DC2 via RPC
        DSA object GUID: 70da75e4-1511-4493-b200-87193a02c552
        Last attempt @ 2020-07-08 10:57:37 failed, result 1256 (0x4e8):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.
        12 consecutive failure(s).
        Last success @ 2020-07-07 23:40:55.

Source: Default-First-Site-Name\DC2
******* 12 CONSECUTIVE FAILURES since 2020-07-07 23:49:03
Last error: 1256 (0x4e8):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.

Source: Default-First-Site-Name\DC3
******* 12 CONSECUTIVE FAILURES since 2020-07-07 23:46:42
Last error: 1256 (0x4e8):
            The remote system is not available. For information about network tr
oubleshooting, see Windows Help.





SOLUTION
Avatar of footech
footech
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Solved. Thanks to Hello Three and other experts' solution.