tryssenaar
MIS
I am having a wierd problem with DNS on my network. I have an AD integrated DNS setup on 2 Windows 2003 DCs. All clients are pointing to those DNS servers which use forwarders and the root servers to resolve internet addresses. No clients have troubles joining the domain and otherwise DNS works properly.
I have a global catalog server setup which isn't on the same server as the Infrastructure Master Role for the domain. Whenever I try to add a user or group to the domain on any other server/computer than the GC, I get a message that the global catalog cannot be contacted.
Following is the error I get when netdiag is run:
DNS test . . . . . . . . . . . . . : Failed
[WARNING] Cannot find a primary authoritative DNS server for the name
'SERVER.DOMAIN.'. [RCODE_SERVER_FAILURE]
The name 'SERVER.DOMAIN.' may not be registered in DNS.
[WARNING] The DNS entries for this DC are not registered correctly on DNS server '192.168.100.9'. Please wait for 30 minutes for DNS server replication.
[WARNING] The DNS entries for this DC are not registered correctly on DNS server '192.168.100.6'. Please wait for 30 minutes for DNS server replication.
[FATAL] No DNS servers have the DNS records for this DC registered.
As far as I can tell, all the records for the DCs (according to %systemroot%\systems32\config\netlogon.dns file) are in DNS. If I run "netdiag /fix" on either DC they can't update said records to the server.
I'm thinking there must be a security setting in DNS which is the problem. Domain Admins, Administrators (group), etc. all have write access, but there is also one orphaned SID (account unknown) with write access as well. Could that account gotten deleted from my domain which my servers use to update DNS, or am I way off??
Thanks in advance for any help,
Ryan
I have a global catalog server setup which isn't on the same server as the Infrastructure Master Role for the domain. Whenever I try to add a user or group to the domain on any other server/computer than the GC, I get a message that the global catalog cannot be contacted.
Following is the error I get when netdiag is run:
DNS test . . . . . . . . . . . . . : Failed
[WARNING] Cannot find a primary authoritative DNS server for the name
'SERVER.DOMAIN.'. [RCODE_SERVER_FAILURE]
The name 'SERVER.DOMAIN.' may not be registered in DNS.
[WARNING] The DNS entries for this DC are not registered correctly on DNS server '192.168.100.9'. Please wait for 30 minutes for DNS server replication.
[WARNING] The DNS entries for this DC are not registered correctly on DNS server '192.168.100.6'. Please wait for 30 minutes for DNS server replication.
[FATAL] No DNS servers have the DNS records for this DC registered.
As far as I can tell, all the records for the DCs (according to %systemroot%\systems32\config\netlogon.dns file) are in DNS. If I run "netdiag /fix" on either DC they can't update said records to the server.
I'm thinking there must be a security setting in DNS which is the problem. Domain Admins, Administrators (group), etc. all have write access, but there is also one orphaned SID (account unknown) with write access as well. Could that account gotten deleted from my domain which my servers use to update DNS, or am I way off??
Thanks in advance for any help,
Ryan