Windows Server - AD / DNS problems whilst adding Server 2008 to existing 2003 Domain

Asked By Andy Woodier on 14-Jul-10 10:05 AM

Hi all,

 

Having major problems here.

 

 

Currently have 2 Windows 2003 DC’s and I need to replace one of these with a new Win 2008 R2 machine.

 

What’s bugging me the most is this is the 4th time I’ve started from scratch with this new server – the first time the DCPROMO seemed to run ok and it was only when I was configuring IIS that this screwed it all up and I had to start again.  It screwed it so bad infact that I’d already transferred the FSMO roles across to it (http://support.microsoft.com/kb/324801) and was unable to run DCPROMO again to remove the server from the AD Config.

 

 

So I transferred the FSMO roles back on the primary server.  I then ran these procedures to remove all old traces of the server: http://support.microsoft.com/?id=216498.

 

 

I can confirm that 10.61.15.5, Server1, has control of all 5 roles, and both it and the other DC (10.16.15.6) are running fine, as they always have done.

 

 

Then started all over again with the new server, from a clean format.  I’ve installed

DHCP, and copied across the config from one of the other two machines, as per here:

http://support.microsoft.com/kb/962355

 

 

Then installed the ADDS role, and then ran DCPROMO again.  For the longest time I was continually getting an error stating that I had DHCP configured on the Network Adapter, but I’ve now (I think) disable IPv6 completely and disabled all other network adapters (server has 4).  The last time I ran DCPROMO I didn’t get the error.

 

DCPROMO runs and the machine gets a restart.  The IP properties are set up so the new server has an ip of 10.61.15.4 (the others are 10.61.15.5 and .6 respectively).  Subnet is set to 255.255.555.0 and default gateway 10.61.15.1.

 

The DNS was set, before running DCPROMO, to look at 10.61.15.5 as otherwise I was unable to run DCPROMO as it told me it couldn’t find a domain controller.

 

I then restart and get  Event ID 4013 errors on boot up, and dcdiag gives me the following:

 

 

4013 ERROR:

Source DNS

EVENT ID 4013

The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed. The DNS server service cannot start until the initial synchronization is complete because critical DNS data might not yet be replicated onto this domain controller. If events in the AD DS event log indicate that there is a problem with DNS name resolution, consider adding the IP address of another DNS server for this domain to the DNS server list in the Internet Protocol properties of this computer. This event will be logged every two minutes until AD DS has signaled that the initial synchronization has successfully completed.

DCDIAG RESULTS:

Directory Server Diagnosis

Performing initial setup:

   Trying to find home server...

   Home Server = slgc-lri-svr-01

   * Identified AD Forest.

   Done gathering initial info.

Doing initial required tests

  

   Testing server: Default-First-Site-Name\SLGC-LRI-SVR-01

    Starting test: Connectivity

     ......................... SLGC-LRI-SVR-01 passed test Connectivity

Doing primary tests

  

   Testing server: Default-First-Site-Name\SLGC-LRI-SVR-01

    Starting test: Advertising

     ......................... SLGC-LRI-SVR-01 passed test Advertising

    Starting test: FrsEvent

     There are warning or error events within the last 24 hours after the

     SYSVOL has been shared.  Failing SYSVOL replication problems may cause

     Group Policy problems.

     ......................... SLGC-LRI-SVR-01 passed test FrsEvent

    Starting test: DFSREvent

     ......................... SLGC-LRI-SVR-01 passed test DFSREvent

    Starting test: SysVolCheck

     ......................... SLGC-LRI-SVR-01 passed test SysVolCheck

    Starting test: KccEvent

     A warning event occurred.  EventID: 0x80000B46

        Time Generated: 07/14/2010   13:21:37

        Event String:

        The security of this directory server can be significantly enhanced by configuring the server to reject SASL (Negotiate,  Kerberos, NTLM, or Digest) LDAP binds that do not request signing (integrity verification) and LDAP simple binds that  are performed on a cleartext (non-SSL/TLS-encrypted) connection.  Even if no clients are using such binds, configuring the server to reject them will improve the security of this server.

     ......................... SLGC-LRI-SVR-01 passed test KccEvent

    Starting test: KnowsOfRoleHolders

     ......................... SLGC-LRI-SVR-01 passed test

     KnowsOfRoleHolders

    Starting test: MachineAccount

     ......................... SLGC-LRI-SVR-01 passed test MachineAccount

    Starting test: NCSecDesc

     Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

        Replicating Directory Changes In Filtered Set

     access rights for the naming context:

     DC=ForestDnsZones,DC=leicester,DC=serco,DC=com

     Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

        Replicating Directory Changes In Filtered Set

     access rights for the naming context:

     DC=DomainDnsZones,DC=leicester,DC=serco,DC=com

     ......................... SLGC-LRI-SVR-01 failed test NCSecDesc

    Starting test: NetLogons

     ......................... SLGC-LRI-SVR-01 passed test NetLogons

    Starting test: ObjectsReplicated

     ......................... SLGC-LRI-SVR-01 passed test

     ObjectsReplicated

    Starting test: Replications

     REPLICATION LATENCY WARNING

     ERROR: Expected notification link is missing.

     Source SERVER1

     Replication of new changes along this path will be delayed.

     This problem should self-correct on the next periodic sync.

     REPLICATION LATENCY WARNING

     ERROR: Expected notification link is missing.

     Source SERVER1

     Replication of new changes along this path will be delayed.

     This problem should self-correct on the next periodic sync.

     REPLICATION LATENCY WARNING

     ERROR: Expected notification link is missing.

     Source SERVER1

     Replication of new changes along this path will be delayed.

     This problem should self-correct on the next periodic sync.

     REPLICATION LATENCY WARNING

     ERROR: Expected notification link is missing.

     Source SERVER1

     Replication of new changes along this path will be delayed.

     This problem should self-correct on the next periodic sync.

     ......................... SLGC-LRI-SVR-01 passed test Replications

    Starting test: RidManager

     ......................... SLGC-LRI-SVR-01 passed test RidManager

    Starting test: Services

     ......................... SLGC-LRI-SVR-01 passed test Services

    Starting test: SystemLog

     An error event occurred.  EventID: 0x0000040B

        Time Generated: 07/14/2010   12:29:20

        Event String:

        The DHCP service was unable to create or lookup the DHCP Users local group on this computer.  The error code is in the data.

     An error event occurred.  EventID: 0x0000040C

        Time Generated: 07/14/2010   12:29:20

        Event String:

        The DHCP server was unable to create or lookup the DHCP Administrators local group on this computer.  The error code is in the data.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   12:29:25

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

       A warning event occurred.  EventID: 0x00000081

        Time Generated: 07/14/2010   12:39:54

        Event String:

        NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)

     A warning event occurred.  EventID: 0x00000081

        Time Generated: 07/14/2010   12:39:55

        Event String:

        NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)

       A warning event occurred.  EventID: 0x00000081

        Time Generated: 07/14/2010   12:40:11

        Event String:

        NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)

     A warning event occurred.  EventID: 0x000003F6

        Time Generated: 07/14/2010   12:40:32

        Event String:

        Name resolution for the name slgc-lri-svr-01.leicester.serco.com timed out after none of the configured DNS servers responded.

     A warning event occurred.  EventID: 0x00000081

        Time Generated: 07/14/2010   12:51:00

        Event String:

        NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)

     A warning event occurred.  EventID: 0x00000081

        Time Generated: 07/14/2010   12:51:01

        Event String:

        NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)

     A warning event occurred.  EventID: 0x00000081

        Time Generated: 07/14/2010   12:51:19

        Event String:

        NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)

     An error event occurred.  EventID: 0x00000456

        Time Generated: 07/14/2010   13:05:40

        Event String:

        The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest. Ensure the user domain name matches the name of a trusted domain that resides in the same forest as the computer account.

     A warning event occurred.  EventID: 0x8000001D

        Time Generated: 07/14/2010   13:08:39

        Event String:

        The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.

     A warning event occurred.  EventID: 0x000003F6

        Time Generated: 07/14/2010   13:08:50

        Event String:

        Name resolution for the name _ldap._tcp.dc._msdcs.leicester.serco.com timed out after none of the configured DNS servers responded.

     A warning event occurred.  EventID: 0x00000420

        Time Generated: 07/14/2010   13:16:01

        Event String:

        The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service.   This is not a recommended security configuration.  Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:16:05

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     A warning event occurred.  EventID: 0x00000420

        Time Generated: 07/14/2010   13:16:47

        Event String:

        The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service.   This is not a recommended security configuration.  Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:16:51

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     A warning event occurred.  EventID: 0x00000420

        Time Generated: 07/14/2010   13:17:31

        Event String:

        The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service.   This is not a recommended security configuration.  Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:17:35

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     A warning event occurred.  EventID: 0x00000420

        Time Generated: 07/14/2010   13:18:01

        Event String:

        The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service.   This is not a recommended security configuration.  Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:18:05

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     A warning event occurred.  EventID: 0x80000431

        Time Generated: 07/14/2010   13:18:32

        Event String:

        The attempt by user LEICESTER\administrator to restart/shutdown computer SLGC-LRI-SVR-01 failed

     A warning event occurred.  EventID: 0x8000001D

        Time Generated: 07/14/2010   13:21:30

        Event String:

        The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.

     A warning event occurred.  EventID: 0x000003F6

        Time Generated: 07/14/2010   13:21:41

        Event String:

        Name resolution for the name _ldap._tcp.dc._msdcs.leicester.serco.com timed out after none of the configured DNS servers responded.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:22:03

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     A warning event occurred.  EventID: 0x000727AA

        Time Generated: 07/14/2010   13:24:09

        Event String:

        The WinRM service failed to create the following SPNs: WSMAN/slgc-lri-svr-01.leicester.serco.com; WSMAN/slgc-lri-svr-01.

     ......................... SLGC-LRI-SVR-01 failed test SystemLog

    Starting test: VerifyReferences

       ......................... SLGC-LRI-SVR-01 passed test VerifyReferences

  

  

   Running partition tests on : ForestDnsZones

    Starting test: CheckSDRefDom

     ......................... ForestDnsZones passed test CheckSDRefDom

    Starting test: CrossRefValidation

     ......................... ForestDnsZones passed test

     CrossRefValidation

  

   Running partition tests on : DomainDnsZones

    Starting test: CheckSDRefDom

     ......................... DomainDnsZones passed test CheckSDRefDom

    Starting test: CrossRefValidation

     ......................... DomainDnsZones passed test

     CrossRefValidation

  

   Running partition tests on : Schema

    Starting test: CheckSDRefDom

     ......................... Schema passed test CheckSDRefDom

    Starting test: CrossRefValidation

     ......................... Schema passed test CrossRefValidation

  

   Running partition tests on : Configuration

    Starting test: CheckSDRefDom

     ......................... Configuration passed test CheckSDRefDom

    Starting test: CrossRefValidation

     ......................... Configuration passed test CrossRefValidation

  

   Running partition tests on : leicester

    Starting test: CheckSDRefDom

     ......................... leicester passed test CheckSDRefDom

    Starting test: CrossRefValidation

     ......................... leicester passed test CrossRefValidation

  

   Running enterprise tests on : leicester.serco.com

    Starting test: LocatorCheck

     ......................... leicester.serco.com passed test LocatorCheck

    Starting test: Intersite

     ......................... leicester.serco.com passed test Intersite

 

I can see the AD has replicated across as I can browse users and computers etc, but I don’t want the DNS setup this way as it’s not set like this on the other servers.  So I go into IP properties and see that the system has auto added the alternate DNS of 127.0.0.1.  The preferred is still set to 10.61.15.5, which now needs changing to that of this new server, and the 127.0.0.0 removed.

 

 

It takes 20 minutes to get past the Apply computer setting dialog too even when set to look at 10.61.15.5.

 

Once I change these settings it cannot replicate, connect to the internet, and the problem then is the network adapter reports it cannot connect to a network (unidentified network) and the server has no access to the DC to replicate at all then.

 

Running dcdia

g now gives following:

 

Directory Server Diagnosis

Performing initial setup:

   Trying to find home server...

   Home Server = slgc-lri-svr-01

   * Identified AD Forest.

   Done gathering initial info.

Doing initial required tests

  

   Testing server: Default-First-Site-Name\SLGC-LRI-SVR-01

    Starting test: Connectivity

     ......................... SLGC-LRI-SVR-01 passed test Connectivity

Doing primary tests

  

   Testing server: Default-First-Site-Name\SLGC-LRI-SVR-01

    Starting test: Advertising

     Warning: SLGC-LRI-SVR-01 is not advertising as a time server.

     ......................... SLGC-LRI-SVR-01 failed test Advertising

    Starting test: FrsEvent

     There are warning or error events within the last 24 hours after the

     SYSVOL has been shared.  Failing SYSVOL replication problems may cause

     Group Policy problems.

     ......................... SLGC-LRI-SVR-01 passed test FrsEvent

    Starting test: DFSREvent

     ......................... SLGC-LRI-SVR-01 passed test DFSREvent

    Starting test: SysVolCheck

     ......................... SLGC-LRI-SVR-01 passed test SysVolCheck

    Starting test: KccEvent

     A warning event occurred.  EventID: 0x80000828

        Time Generated: 07/14/2010   13:43:03

        Event String:

        Active Directory Domain Services could not use DNS to resolve the IP address of the source domain controller listed below. To maintain the consistency of Security groups, group policy, users and computers and their passwords, Active Directory Domain Services successfully replicated using the NetBIOS or fully qualified computer name of the source domain controller.

     A warning event occurred.  EventID: 0x80000828

        Time Generated: 07/14/2010   13:44:04

        Event String:

        Active Directory Domain Services could not use DNS to resolve the IP address of the source domain controller listed below. To maintain the consistency of Security groups, group policy, users and computers and their passwords, Active Directory Domain Services successfully replicated using the NetBIOS or fully qualified computer name of the source domain controller.

     ......................... SLGC-LRI-SVR-01 passed test KccEvent

    Starting test: KnowsOfRoleHolders

     ......................... SLGC-LRI-SVR-01 passed test

     KnowsOfRoleHolders

    Starting test: MachineAccount

     ......................... SLGC-LRI-SVR-01 passed test MachineAccount

    Starting test: NCSecDesc

     Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

        Replicating Directory Changes In Filtered Set

     access rights for the naming context:

     DC=ForestDnsZones,DC=leicester,DC=serco,DC=com

     Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

        Replicating Directory Changes In Filtered Set

     access rights for the naming context:

     DC=DomainDnsZones,DC=leicester,DC=serco,DC=com

     ......................... SLGC-LRI-SVR-01 failed test NCSecDesc

    Starting test: NetLogons

     ......................... SLGC-LRI-SVR-01 passed test NetLogons

    Starting test: ObjectsReplicated

     ......................... SLGC-LRI-SVR-01 passed test

     ObjectsReplicated

    Starting test: Replications

     ......................... SLGC-LRI-SVR-01 passed test Replications

    Starting test: RidManager

     ......................... SLGC-LRI-SVR-01 passed test RidManager

    Starting test: Services

     ......................... SLGC-LRI-SVR-01 passed test Services

    Starting test: SystemLog

     An error event occurred.  EventID: 0x00000456

        Time Generated: 07/14/2010   13:05:40

        Event String:

        The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest. Ensure the user domain name matches the name of a trusted domain that resides in the same forest as the computer account.

     A warning event occurred.  EventID: 0x8000001D

        Time Generated: 07/14/2010   13:08:39

        Event String:

        The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.

     A warning event occurred.  EventID: 0x000003F6

        Time Generated: 07/14/2010   13:08:50

        Event String:

        Name resolution for the name _ldap._tcp.dc._msdcs.leicester.serco.com timed out after none of the configured DNS servers responded.

     A warning event occurred.  EventID: 0x00000420

        Time Generated: 07/14/2010   13:16:01

        Event String:

        The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service.   This is not a recommended security configuration.  Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:16:05

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     A warning event occurred.  EventID: 0x00000420

        Time Generated: 07/14/2010   13:16:47

        Event String:

        The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service.   This is not a recommended security configuration.  Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:16:51

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     A warning event occurred.  EventID: 0x00000420

        Time Generated: 07/14/2010   13:17:31

        Event String:

        The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service.   This is not a recommended security configuration.  Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:17:35

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     A warning event occurred.  EventID: 0x00000420

        Time Generated: 07/14/2010   13:18:01

        Event String:

        The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service.   This is not a recommended security configuration.  Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:18:05

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     A warning event occurred.  EventID: 0x80000431

        Time Generated: 07/14/2010   13:18:32

        Event String:

        The attempt by user LEICESTER\administrator to restart/shutdown computer SLGC-LRI-SVR-01 failed

     A warning event occurred.  EventID: 0x8000001D

        Time Generated: 07/14/2010   13:21:30

        Event String:

        The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.

     A warning event occurred.  EventID: 0x000003F6

        Time Generated: 07/14/2010   13:21:41

        Event String:

        Name resolution for the name _ldap._tcp.dc._msdcs.leicester.serco.com timed out after none of the configured DNS servers responded.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:22:03

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     A warning event occurred.  EventID: 0x000727AA

        Time Generated: 07/14/2010   13:24:09

        Event String:

        The WinRM service failed to create the following SPNs: WSMAN/slgc-lri-svr-01.leicester.serco.com; WSMAN/slgc-lri-svr-01.

     A warning event occurred.  EventID: 0x8000001D

        Time Generated: 07/14/2010   13:41:27

        Event String:

        The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.

     A warning event occurred.  EventID: 0x00000C18

        Time Generated: 07/14/2010   13:41:36

        Event String:

        The primary Domain Controller for this domain could not be located.

     A warning event occurred.  EventID: 0x000003F6

        Time Generated: 07/14/2010   13:41:44

        Event String:

        Name resolution for the name slgc-lri-svr-01.leicester.serco.com timed out after none of the configured DNS servers responded.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:41:55

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     A warning event occurred.  EventID: 0x000003F6

        Time Generated: 07/14/2010   13:42:15

        Event String:

        Name resolution for the name leicester.serco.com timed out after none of the configured DNS servers responded.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:42:22

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:42:49

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:43:16

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:43:43

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:44:10

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:44:37

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:45:04

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     A warning event occurred.  EventID: 0x00002724

        Time Generated: 07/14/2010   13:45:15

        Event String:

        This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:45:31

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     A warning event occurred.  EventID: 0x00000081

        Time Generated: 07/14/2010   13:45:34

        Event String:

        NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)

     A warning event occurred.  EventID: 0x00000081

        Time Generated: 07/14/2010   13:45:35

        Event String:

        NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)

     An error event occurred.  EventID: 0x00000423

        Time Generated: 07/14/2010   13:45:39

        Event String:

        The DHCP service failed to see a directory server for authorization.

     An error event occurred.  EventID: 0x00000423

        Time Generated: 07/14/2010   13:45:52

        Event String:

        The DHCP service failed to see a directory server for authorization.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:45:58

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     An error event occurred.  EventID: 0xC00038D6

        Time Generated: 07/14/2010   13:46:25

        Event String:

        The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

     A warning event occurred.  EventID: 0x00001695

        Time Generated: 07/14/2010   13:47:29

        Event String:

        Dynamic registration or deletion of one or more DNS records associated with DNS domain 'leicester.serco.com.' failed.  These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition). 

     A warning event occurred.  EventID: 0x000727AA

        Time Generated: 07/14/2010   13:47:36

        Event String:

        The WinRM service failed to create the following SPNs: WSMAN/slgc-lri-svr-01.leicester.serco.com; WSMAN/slgc-lri-svr-01.

     An error event occurred.  EventID: 0x0000168E

        Time Generated: 07/14/2010   13:56:15

        Event String:

        The dynamic registration of the DNS record '_kerberos._tcp.dc._msdcs.leicester.serco.com. 600 IN SRV 0 100 88 slgc-lri-svr-01.leicester.serco.com.' failed on the following DNS server: 

     A warning event occurred.  EventID: 0x00001695

        Time Generated: 07/14/2010   13:56:15

        Event String:

        Dynamic registration or deletion of one or more DNS records associated with DNS domain 'leicester.serco.com.' failed.  These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition). 

     A warning event occurred.  EventID: 0x00001695

        Time Generated: 07/14/2010   13:56:15

        Event String:

        Dynamic registration or deletion of one or more DNS records associated with DNS domain 'ForestDnsZones.leicester.serco.com.' failed.  These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition). 

     A warning event occurred.  EventID: 0x00001695

        Time Generated: 07/14/2010   13:56:15

        Event String:

        Dynamic registration or deletion of one or more DNS records associated with DNS domain 'DomainDnsZones.leicester.serco.com.' failed.  These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition). 

     ......................... SLGC-LRI-SVR-01 failed test SystemLog

    Starting test: VerifyReferences

     ......................... SLGC-LRI-SVR-01 passed test VerifyReferences

  

  

   Running partition tests on : ForestDnsZones

    Starting test: CheckSDRefDom

     ......................... ForestDnsZones passed test CheckSDRefDom

    Starting test: CrossRefValidation

       ......................... ForestDnsZones passed test

     CrossRefValidation

  

   Running partition tests on : DomainDnsZones

    Starting test: CheckSDRefDom

     ......................... DomainDnsZones passed test CheckSDRefDom

    Starting test: CrossRefValidation

     ......................... DomainDnsZones passed test

     CrossRefValidation

  

   Running partition tests on : Schema

    Starting test: CheckSDRefDom

     ......................... Schema passed test CheckSDRefDom

    Starting test: CrossRefValidation

     ......................... Schema passed test CrossRefValidation

  

   Running partition tests on : Configuration

    Starting test: CheckSDRefDom

     ......................... Configuration passed test CheckSDRefDom

    Starting test: CrossRefValidation

     ......................... Configuration passed test CrossRefValidation

  

   Running partition tests on : leicester

    Starting test: CheckSDRefDom

     ......................... leicester passed test CheckSDRefDom

    Starting test: CrossRefValidation

     ......................... leicester passed test CrossRefValidation

  

   Running enterprise tests on : leicester.serco.com

    Starting test: LocatorCheck

     ......................... leicester.serco.com passed test LocatorCheck

    Starting test: Intersite

     ......................... leicester.serco.com passed test Intersite

 

 

 

I feel like I’m missing something here, I’ve spent 4 days trying to get this working and I’ve tried all sorts of stuff – too much to list.  I’m open to any suggestions and will try anything.  I’m not sure if the problem lies with the DNS settings somewhere, the AD config or the IP settings on the new server.

 

I’m sort of assuming the problem may lie somewhere with AD as like I say at the very beginning I believe I got it all working in the first place.  The new server was most certainly pointing to itself for DNS at the very least, however I can’t confirm whether I got the 4013 errors or dcdiag errors as being totally honest this my first server migration and I wasn’t aware of the tools available – it’s only since I’ve had problems that I’m truly learning all about AD/DNS.

 

I’m really stuck – help me?!

 

 

 

Further information - Andy Woodier replied to Andy Woodier on 14-Jul-10 10:25 AM

Further to the above after a reboot (and a subsequent 20 minute log on) i get this:


Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = slgc-lri-svr-01

   The directory service on slgc-lri-svr-01 has not finished initializing.

    In order for the directory service to consider itself synchronized, it must

   attempt an initial synchronization with at least one replica of this

   server's writeable domain.  It must also obtain Rid information from the Rid

   FSMO holder.

    The directory service has not signalled the event which lets other services

   know that it is ready to accept requests. Services such as the Key

   Distribution Center, Intersite Messaging Service, and NetLogon will not

   consider this system as an eligible domain controller.
   * Identified AD Forest.
   The directory service on SLGC-LRI-SVR-01 has not finished initializing.

    In order for the directory service to consider itself synchronized, it must

   attempt an initial synchronization with at least one replica of this

   server's writeable domain.  It must also obtain Rid information from the Rid

   FSMO holder.

    The directory service has not signalled the event which lets other services

   know that it is ready to accept requests. Services such as the Key

   Distribution Center, Intersite Messaging Service, and NetLogon will not

   consider this system as an eligible domain controller.
   Ldap search capabality attribute search failed on server SERVER1, return

   value = 81
   Got error while checking if the DC is using FRS or DFSR. Error:

   Win32 Error 81The VerifyReferences, FrsEvent and DfsrEvent tests might fail

   because of this error.

   Ldap search capabality attribute search failed on server SERVER1-BACKUP,

   return value = 81
   Got error while checking if the DC is using FRS or DFSR. Error:

   Win32 Error 81The VerifyReferences, FrsEvent and DfsrEvent tests might fail

   because of this error.

   Done gathering initial info.


Doing initial required tests

  
   Testing server: Default-First-Site-Name\SLGC-LRI-SVR-01

      Starting test: Connectivity

         The host

         9bb52952-6d7b-43eb-88fc-a7cf540788d6._msdcs.leicester.serco.com could

         not be resolved to an IP address. Check the DNS server, DHCP, server

         name, etc.

         Got error while checking LDAP and RPC connectivity. Please check your

         firewall settings.

         ......................... SLGC-LRI-SVR-01 failed test Connectivity



Doing primary tests

  
   Testing server: Default-First-Site-Name\SLGC-LRI-SVR-01

      Skipping all tests, because server SLGC-LRI-SVR-01 is not responding to

      directory service requests.

  
  
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

  
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

  
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

  
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

  
   Running partition tests on : leicester

      Starting test: CheckSDRefDom

         ......................... leicester passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... leicester passed test CrossRefValidation

  
   Running enterprise tests on : leicester.serco.com

      Starting test: LocatorCheck

         Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355

         A Global Catalog Server could not be located - All GC's are down.

         Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355

         A Primary Domain Controller could not be located.

         The server holding the PDC role is down.

         ......................... leicester.serco.com failed test LocatorCheck

      Starting test: Intersite

         ......................... leicester.serco.com passed test Intersite


Dr. Techie replied to Andy Woodier on 29-Jan-12 09:37 AM
end of post

Hi, did you check if you have configured global catalog settings? - Dr. Techie replied to Andy Woodier on 29-Jan-12 09:39 AM

end of post
Dr. Techie replied to Dr. Techie on 29-Jan-12 09:49 AM
end of post
Dr. Techie replied to Dr. Techie on 29-Jan-12 09:49 AM
end of post
Dr. Techie replied to Dr. Techie on 29-Jan-12 09:49 AM
end of post
Dr. Techie replied to Dr. Techie on 29-Jan-12 09:50 AM
end of post
Dr. Techie replied to Dr. Techie on 29-Jan-12 09:50 AM
end of post