Quantcast
Channel: Network Infrastructure Servers forum
Viewing all articles
Browse latest Browse all 5877

dcdiag failing dns tests

$
0
0

w2k8 domain with two DCs - this error is present.
initially we had issues with initial synchronization of the directory by we logged a call with MS and they address a registry entry that bypassed the initial syncronization, but I can still see the errors below and a client not registering in DNS sue to no permissions.

canyou advise what can I do to get rid of this error:

Log Name:      Directory Service
Source:        Microsoft-Windows-ActiveDirectory_DomainService
Date:          28/10/2009 18:54:04
Event ID:      2088
Task Category: DS RPC Client
Level:         Warning
Keywords:      Classic
User:          ANONYMOUS LOGON
Computer:      olivia.domain.com
Description:
Active Directory Domain Services could not use DNS to resolve the IP address of the source domain controller listed below. To maintain the consistency of Security groups, group policy, users and computers and their passwords, Active Directory Domain Services successfully replicated using the NetBIOS or fully qualified computer name of the source domain controller.
 
Invalid DNS configuration may be affecting other essential operations on member computers, domain controllers or application servers in this Active Directory Domain Services forest, including logon authentication or access to network resources.
 
You should immediately resolve this DNS configuration error so that this domain controller can resolve the IP address of the source domain controller using DNS.
 
Alternate server name:
 katie
Failing DNS host name:
 60c35a20-978b-4e86-9751-e65d9e584e76._msdcs.domain.com
 
NOTE: By default, only up to 10 DNS failures are shown for any given 12 hour period, even if more than 10 failures occur.  To log all individual failure events, set the following diagnostics registry value to 1:
 
Registry Path:
HKLM\System\CurrentControlSet\Services\NTDS\Diagnostics\22 DS RPC Client
 
User Action:
 
 1) If the source domain controller is no longer functioning or its operating system has been reinstalled with a different computer name or NTDSDSA object GUID, remove the source domain controller's metadata with ntdsutil.exe, using the steps outlined in MSKB article 216498.
 
 2) Confirm that the source domain controller is running Active Directory Domain Services and is accessible on the network by typing "net view \\<source DC name>" or "ping <source DC name>".
 
 3) Verify that the source domain controller is using a valid DNS server for DNS services, and that the source domain controller's host record and CNAME record are correctly registered, using the DNS Enhanced version of DCDIAG.EXE available on http://www.microsoft.com/dns
 
  dcdiag /test:dns
 
 4) Verify that this destination domain controller is using a valid DNS server for DNS services, by running the DNS Enhanced version of DCDIAG.EXE command on the console of the destination domain controller, as follows:
 
  dcdiag /test:dns
 
 5) For further analysis of DNS error failures see KB 824449:
   http://support.microsoft.com/?kbid=824449
 
Additional Data
Error value:
 11001 No such host is known.

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-ActiveDirectory_DomainService" Guid="{0e8478c5-3605-4e8c-8497-1e730c959516}" EventSourceName="NTDS General" />
    <EventID Qualifiers="32768">2088</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>22</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2009-10-28T18:54:04.390Z" />
    <EventRecordID>179247</EventRecordID>
    <Correlation />
    <Execution ProcessID="700" ThreadID="920" />
    <Channel>Directory Service</Channel>
    <Computer>olivia.domain.com</Computer>
    <Security UserID="S-1-5-7" />
  </System>
  <EventData>
    <Data>katie</Data>
    <Data>60c35a20-978b-4e86-9751-e65d9e584e76._msdcs.domain.com</Data>
    <Data>11001</Data>
    <Data>No such host is known.</Data>
    <Data>System\CurrentControlSet\Services\NTDS\Diagnostics</Data>
    <Data>22 DS RPC Client</Data>
  </EventData>
</Event>

**************************************

C:\Users\secadmin>net view \\katie
Shared resources at \\katie

Share name  Type  Used as  Comment
---------------------------------------------
dfs         Disk
NETLOGON    Disk           Logon server share
SYSVOL      Disk           Logon server share
The command completed successfully.

**************************************

Directory Server Diagnosis

Performing initial setup:

   Trying to find home server...

   Home Server = olivia

   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: NorthwayHouse\OLIVIA

      Starting test: Connectivity

         ......................... OLIVIA passed test Connectivity

Doing primary tests

  
   Testing server: NorthwayHouse\OLIVIA

  
      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...

         ......................... OLIVIA passed test DNS

  
   Running partition tests on : ForestDnsZones

  
   Running partition tests on : DomainDnsZones

  
   Running partition tests on : Schema

  
   Running partition tests on : Configuration

  
   Running partition tests on : domain

  
   Running enterprise tests on : domain.com

      Starting test: DNS

         Test results for domain controllers:

           
            DC: olivia.domain.com

            Domain: domain.com

               TEST: Basic (Basc)
                  Warning: The AAAA record for this DC was not found
                 
               TEST: Delegations (Del)
                  Error: DNS server: katie.domain.com. IP:10.30.0.2

                  [Broken delegated domain domain.com.domain.com.]

                  Error: DNS server: olivia.domain.com. IP:10.30.0.1

                  [Broken delegated domain domain.com.domain.com.]

               TEST: Dynamic update (Dyn)
                  Warning: Failed to delete the test record _dcdiag_test_record in zone domain.com
                 
               TEST: Records registration (RReg)
                  Network Adapter

                  [00000006] Intel(R) PRO/1000 CT Network Connection:

                     Warning:
                     Missing AAAA record at DNS server 10.30.0.1:
                     olivia.domain.com
                    
                     Warning:
                     Missing AAAA record at DNS server 10.30.0.1:
                     gc._msdcs.domain.com
                    
               Warning: Record Registrations not found in some network adapters

        
         Summary of test results for DNS servers used by the above domain

         controllers:

        

            DNS server: 10.30.0.1 (olivia.domain.com.)

               1 test failure on this DNS server

              
            DNS server: 10.30.0.2 (katie.domain.com.)

               1 test failure on this DNS server

              
         Summary of DNS test results:

        
                                            Auth Basc Forw Del  Dyn  RReg Ext
            _________________________________________________________________
            Domain: domain.com

               olivia                       PASS WARN PASS FAIL WARN WARN n/a 
        
         ......................... domain.com failed test DNS


Viewing all articles
Browse latest Browse all 5877

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>