DFS errors
I hope someone out there can help me. I am getting errors when I run DCDIAG. Below is the output from DCDIAG /D /V /C. I believe this has been caused by attempting to move the SYSVOL location. (This is not my server, but a clients server) I attempted to restore the missing FRS information as per but when I attempt to add the fRSMemberReference information I get an error message stating “The name reference is invalid.” I would greatly appreciate any help I can get.
Domain Controller Diagnosis
Performing initial setup:
* Verifying that the local machine godzilla, is a DC.
* Connecting to directory service on server godzilla.
* Collecting site info.
* Identifying all servers.
* Identifying all NC cross-refs.
* Found 1 DC(s). Testing 1 of them.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\GODZILLA
Starting test: Connectivity
* Active Directory LDAP Services Check
* Active Directory RPC Services Check
......................... GODZILLA passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\GODZILLA
Starting test: Replications
* Replications Check
* Replication Latency Check
DC=DomainDnsZones,DC=office,DC=eswcpc,DC=net
Latency information for 23 entries in the vector were ignored.
23 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or
dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=ForestDnsZones,DC=office,DC=eswcpc,DC=net
Latency information for 23 entries in the vector were ignored.
23 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or
dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Schema,CN=Configuration,DC=office,DC=eswcpc,DC=net
Latency information for 29 entries in the vector were ignored.
29 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or
dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Configuration,DC=office,DC=eswcpc,DC=net
Latency information for 29 entries in the vector were ignored.
29 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or
dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=office,DC=eswcpc,DC=net
Latency information for 29 entries in the vector were ignored.
29 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or
dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
......................... GODZILLA passed test Replications
Starting test: Topology
* Configuration Topology Integrity Check
[Topology Integrity Check,GODZILLA] Intra-site topology generation is disabled in this site.
* Analyzing the connection topology for DC=DomainDnsZones,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for DC=ForestDnsZones,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for CN=Schema,CN=Configuration,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for CN=Configuration,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
......................... GODZILLA passed test Topology
Starting test: CutoffServers
* Configuration Topology Aliveness Check
* Analyzing the alive system replication topology for DC=DomainDnsZones,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for DC=ForestDnsZones,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for
CN=Schema,CN=Configuration,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for CN=Configuration,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
......................... GODZILLA passed test CutoffServers
Starting test: NCSecDesc
* Security Permissions check for all NC's on DC GODZILLA.
* Security Permissions Check for
DC=DomainDnsZones,DC=office,DC=eswcpc,DC=net
(NDNC,Version 2)
* Security Permissions Check for
DC=ForestDnsZones,DC=office,DC=eswcpc,DC=net
(NDNC,Version 2)
* Security Permissions Check for
CN=Schema,CN=Configuration,DC=office,DC=eswcpc,DC=net
(Schema,Version 2)
* Security Permissions Check for
CN=Configuration,DC=office,DC=eswcpc,DC=net
(Configuration,Version 2)
* Security Permissions Check for
DC=office,DC=eswcpc,DC=net
(Domain,Version 2)
......................... GODZILLA passed test NCSecDesc
Starting test: NetLogons
* Network Logons Privileges Check
Verified share \\GODZILLA\netlogon
Verified share \\GODZILLA\sysvol
......................... GODZILLA passed test NetLogons
Starting test: Advertising
The DC GODZILLA is advertising itself as a DC and having a DS.
The DC GODZILLA is advertising as an LDAP server
The DC GODZILLA is advertising as having a writeable directory
The DC GODZILLA is advertising as a Key Distribution Center
The DC GODZILLA is advertising as a time server
The DS GODZILLA is advertising as a GC.
......................... GODZILLA passed test Advertising
Starting test: KnowsOfRoleHolders
Role Schema Owner = CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
Role Domain Owner = CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
Role PDC Owner = CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
Role Rid Owner = CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
Role Infrastructure Update Owner = CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
......................... GODZILLA passed test KnowsOfRoleHolders
Starting test: RidManager
* Available RID Pool for the Domain is 16604 to 1073741823
* godzilla.office.eswcpc.net is the RID Master
* DsBind with RID Master was successful
* rIDAllocationPool is 14604 to 15103
* rIDPreviousAllocationPool is 14604 to 15103
* rIDNextRID: 14661
......................... GODZILLA passed test RidManager
Starting test: MachineAccount
Checking machine account for DC GODZILLA on DC GODZILLA.
* SPN found :LDAP/godzilla.office.eswcpc.net/office.eswcpc.net
* SPN found :LDAP/godzilla.office.eswcpc.net
* SPN found :LDAP/GODZILLA
* SPN found :LDAP/godzilla.office.eswcpc.net/OFFICE
* SPN found :LDAP/1529a0f5-2649-4c46-8aa3-77e87fdee157._msdcs.office.eswcpc.net
* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/1529a0f5-2649-4c46-8aa3-77e87fdee157/office.eswcpc.net
* SPN found :HOST/godzilla.office.eswcpc.net/office.eswcpc.net
* SPN found :HOST/godzilla.office.eswcpc.net
* SPN found :HOST/GODZILLA
* SPN found :HOST/godzilla.office.eswcpc.net/OFFICE
* SPN found :GC/godzilla.office.eswcpc.net/office.eswcpc.net
......................... GODZILLA passed test MachineAccount
Starting test: Services
* Checking Service: Dnscache
* Checking Service: NtFrs
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: RpcSs
* Checking Service: w32time
* Checking Service: NETLOGON
......................... GODZILLA passed test Services
Starting test: OutboundSecureChannels
* The Outbound Secure Channels test
** Did not run Outbound Secure Channels test
because /testdomain: was not entered
......................... GODZILLA passed test OutboundSecureChannels
Starting test: ObjectsReplicated
GODZILLA is in domain DC=office,DC=eswcpc,DC=net
Checking for CN=GODZILLA,OU=Domain Controllers,DC=office,DC=eswcpc,DC=net in domain
DC=office,DC=eswcpc,DC=net on 1 servers
Object is up-to-date on all servers.
Checking for CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net in
domain CN=Configuration,DC=office,DC=eswcpc,DC=net on 1 servers
Object is up-to-date on all servers.
......................... GODZILLA passed test ObjectsReplicated
Starting test: frssysvol
* The File Replication Service SYSVOL ready test
File Replication Service's SYSVOL is ready
......................... GODZILLA passed test frssysvol
Starting test: frsevent
* The File Replication Service Event log test
......................... GODZILLA passed test frsevent
Starting test: kccevent
* The KCC Event log test
An Error Event occured. EventID: 0xC00005C9
Time Generated: 06/22/2007 11:50:12
(Event String could not be retrieved)
(NUMEROUS REPEATED ERRORS LIKE ABOVE ARE LOGGED HERE)
......................... GODZILLA failed test kccevent
Starting test: systemlog
* The System Event log test
Found no errors in System Event log in the last 60 minutes.
......................... GODZILLA passed test systemlog
Starting test: VerifyReplicas
......................... GODZILLA passed test VerifyReplicas
Starting test: VerifyReferences
The system object reference (serverReference) CN=GODZILLA,OU=Domain
Controllers,DC=office,DC=eswcpc,DC=net and backlink on
CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net are
correct.
Some objects relating to the DC GODZILLA have problems:
[1] Problem: Missing Expected Value Base Object: CN=GODZILLA,OU=Domain
Controllers,DC=office,DC=eswcpc,DC=net Base Object Description: "DC Account Object" Value
Object Attribute Name: frsComputerReferenceBL Value Object Description: "SYSVOL FRS Member Object"
Recommended Action: See Knowledge Base Article: Q312862
[1] Problem: Missing Expected Value Base Object: CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
Base Object Description: "DSA Object" Value Object Attribute Name: serverReferenceBL
Value Object Description: "SYSVOL FRS Member Object" Recommended Action: See Knowledge Base Article:
Q312862
......................... GODZILLA failed test VerifyReferences
Starting test: VerifyEnterpriseReferences
The following problems were found while verifying various important DN references. Note, that
these problems can be reported because of latency in replication. So follow up to resolve the following
problems, only if the same problem is reported on all DCs for a given domain or if the problem persists
after replication has had reasonable time to replicate changes.
[1] Problem: Missing Expected Value Base Object: CN=GODZILLA,OU=Domain
Controllers,DC=office,DC=eswcpc,DC=net Base Object Description: "DC Account Object" Value
Object Attribute Name: frsComputerReferenceBL Value Object Description: "SYSVOL FRS Member Object"
Recommended Action: See Knowledge Base Article: Q312862
LDAP Error 0x5e (94) - No result present in message.
......................... GODZILLA failed test VerifyEnterpriseReferences
Starting test: CheckSecurityError
* Dr Auth: Beginning security errors check!
Found KDC GODZILLA for domain office.eswcpc.net in site Default-First-Site-Name
Checking machine account for DC GODZILLA on DC GODZILLA.
* SPN found :LDAP/godzilla.office.eswcpc.net/office.eswcpc.net
* SPN found :LDAP/godzilla.office.eswcpc.net
* SPN found :LDAP/GODZILLA
* SPN found :LDAP/godzilla.office.eswcpc.net/OFFICE
* SPN found :LDAP/1529a0f5-2649-4c46-8aa3-77e87fdee157._msdcs.office.eswcpc.net
* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/1529a0f5-2649-4c46-8aa3-77e87fdee157/office.eswcpc.net
* SPN found :HOST/godzilla.office.eswcpc.net/office.eswcpc.net
* SPN found :HOST/godzilla.office.eswcpc.net
* SPN found :HOST/GODZILLA
* SPN found :HOST/godzilla.office.eswcpc.net/OFFICE
* SPN found :GC/godzilla.office.eswcpc.net/office.eswcpc.net
[GODZILLA] No security related replication errors were found on this DC! To target the connection to a
specific source DC use /ReplSource:<DC>.
......................... GODZILLA passed test CheckSecurityError
DNS Tests are running and not hung. Please wait a few minutes...
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : office
Starting test: CrossRefValidation
......................... office passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... office passed test CheckSDRefDom
Running enterprise tests on : office.eswcpc.net
Starting test: Intersite
Skipping site Default-First-Site-Name, this site is outside the scope provided by the command line
arguments provided.
......................... office.eswcpc.net passed test Intersite
Starting test: FsmoCheck
GC Name: \\godzilla.office.eswcpc.net
Locator Flags: 0xe00003fd
PDC Name: \\godzilla.office.eswcpc.net
Locator Flags: 0xe00003fd
Time Server Name: \\godzilla.office.eswcpc.net
Locator Flags: 0xe00003fd
Preferred Time Server Name: \\godzilla.office.eswcpc.net
Locator Flags: 0xe00003fd
KDC Name: \\godzilla.office.eswcpc.net
Locator Flags: 0xe00003fd
......................... office.eswcpc.net passed test FsmoCheck
Starting test: DNS
Test results for domain controllers:
DC: godzilla.office.eswcpc.net
Domain: office.eswcpc.net
TEST: Authentication (Auth)
Authentication test: Successfully completed
TEST: Basic (Basc)
Microsoft(R) Windows(R) Server 2003, Enterprise Edition (Service Pack level: 2.0) is supported
NETLOGON service is running
kdc service is running
DNSCACHE service is running
DNS service is running
DC is a DNS server
Network adapters information:
Adapter [00000012] VMware Accelerated AMD PCNet Adapter:
MAC address is 00:0C:29:3B:71:3F
IP address is static
IP address: 192.168.1.133
DNS servers:
192.168.1.133 (<name unavailable>) [Valid]
Warning: 192.168.1.101 (<name unavailable>) [Invalid (unreachable)]
The A record for this DC was found
The SOA record for the Active Directory zone was found
The Active Directory zone on this DC/DNS server was found (primary)
Root zone on this DC/DNS server was not found
TEST: Forwarders/Root hints (Forw)
Recursion is enabled
Forwarders are not configured on this DNS server
Root hint Information:
Name: a.root-servers.net. IP: 198.41.0.4 [Invalid]
Name: b.root-servers.net. IP: 192.228.79.201 [Invalid]
Name: c.root-servers.net. IP: 192.33.4.12 [Invalid]
Name: d.root-servers.net. IP: 128.8.10.90 [Invalid]
Name: e.root-servers.net. IP: 192.203.230.10 [Invalid]
Name: f.root-servers.net. IP: 192.5.5.241 [Invalid]
Name: g.root-servers.net. IP: 192.112.36.4 [Invalid]
Name: h.root-servers.net. IP: 128.63.2.53 [Invalid]
Name: i.root-servers.net. IP: 192.36.148.17 [Invalid]
Name: j.root-servers.net. IP: 192.58.128.30 [Invalid]
Name: k.root-servers.net. IP: 193.0.14.129 [Invalid]
Name: l.root-servers.net. IP: 198.32.64.12 [Invalid]
Name: m.root-servers.net. IP: 202.12.27.33 [Invalid]
TEST: Delegations (Del)
No delegations were found in this zone on this DNS server
TEST: Dynamic update (Dyn)
Dynamic update is enabled on the zone office.eswcpc.net.
Test record _dcdiag_test_record added successfully in zone office.eswcpc.net.
Test record _dcdiag_test_record deleted successfully in zone office.eswcpc.net.
TEST: Records registration (RReg)
Network Adapter [00000012] VMware Accelerated AMD PCNet Adapter:
Matching A record found at DNS server 192.168.1.133:
godzilla.office.eswcpc.net
Matching CNAME record found at DNS server 192.168.1.133:
1529a0f5-2649-4c46-8aa3-77e87fdee157._msdcs.office.eswcpc.net
Matching DC SRV record found at DNS server 192.168.1.133:
_ldap._tcp.dc._msdcs.office.eswcpc.net
Matching GC SRV record found at DNS server 192.168.1.133:
_ldap._tcp.gc._msdcs.office.eswcpc.net
Matching PDC SRV record found at DNS server 192.168.1.133:
_ldap._tcp.pdc._msdcs.office.eswcpc.net
Summary of test results for DNS servers used by the above domain controllers:
DNS server: 128.63.2.53 (h.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 128.63.2.53
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 128.8.10.90 (d.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 128.8.10.90
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.112.36.4 (g.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.112.36.4
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]
DNS server: 192.168.1.101 (<name unavailable>)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.168.1.101
[Error details: 1460 (Type: Win32 - Description: This operation returned because the timeout period
expired.)]
Name resolution is not functional. _ldap._tcp.office.eswcpc.net. failed on the DNS server
192.168.1.101
[Error details: 1460 (Type: Win32 - Description: This operation returned because the timeout period
expired.)]
DNS server: 192.203.230.10 (e.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.203.230.10
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.228.79.201 (b.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.228.79.201
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.33.4.12 (c.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.33.4.12
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.36.148.17 (i.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.36.148.17
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.5.5.241 (f.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.5.5.241
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.58.128.30 (j.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.58.128.30
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]
DNS server: 193.0.14.129 (k.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 193.0.14.129
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 198.32.64.12 (l.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 198.32.64.12
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 198.41.0.4 (a.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 198.41.0.4
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 202.12.27.33 (m.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 202.12.27.33
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.168.1.133 (<name unavailable>)
All tests passed on this DNS server
This is a valid DNS server.
Name resolution is funtional. _ldap._tcp SRV record for the forest root domain is registered
Summary of DNS test results:
Auth Basc Forw Del Dyn RReg Ext
________________________________________________________________
Domain: office.eswcpc.net
godzilla PASS WARN FAIL PASS PASS PASS n/a
......................... office.eswcpc.net failed test DNS
I hope someone out there can help me. I am getting errors when I run DCDIAG. Below is the output from DCDIAG /D /V /C. I believe this has been caused by attempting to move the SYSVOL location. (This is not my server, but a clients server) I attempted to restore the missing FRS information as per but when I attempt to add the fRSMemberReference information I get an error message stating “The name reference is invalid.” I would greatly appreciate any help I can get.
Domain Controller Diagnosis
Performing initial setup:
* Verifying that the local machine godzilla, is a DC.
* Connecting to directory service on server godzilla.
* Collecting site info.
* Identifying all servers.
* Identifying all NC cross-refs.
* Found 1 DC(s). Testing 1 of them.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\GODZILLA
Starting test: Connectivity
* Active Directory LDAP Services Check
* Active Directory RPC Services Check
......................... GODZILLA passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\GODZILLA
Starting test: Replications
* Replications Check
* Replication Latency Check
DC=DomainDnsZones,DC=office,DC=eswcpc,DC=net
Latency information for 23 entries in the vector were ignored.
23 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or
dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=ForestDnsZones,DC=office,DC=eswcpc,DC=net
Latency information for 23 entries in the vector were ignored.
23 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or
dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Schema,CN=Configuration,DC=office,DC=eswcpc,DC=net
Latency information for 29 entries in the vector were ignored.
29 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or
dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Configuration,DC=office,DC=eswcpc,DC=net
Latency information for 29 entries in the vector were ignored.
29 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or
dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=office,DC=eswcpc,DC=net
Latency information for 29 entries in the vector were ignored.
29 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or
dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
......................... GODZILLA passed test Replications
Starting test: Topology
* Configuration Topology Integrity Check
[Topology Integrity Check,GODZILLA] Intra-site topology generation is disabled in this site.
* Analyzing the connection topology for DC=DomainDnsZones,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for DC=ForestDnsZones,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for CN=Schema,CN=Configuration,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for CN=Configuration,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
......................... GODZILLA passed test Topology
Starting test: CutoffServers
* Configuration Topology Aliveness Check
* Analyzing the alive system replication topology for DC=DomainDnsZones,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for DC=ForestDnsZones,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for
CN=Schema,CN=Configuration,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for CN=Configuration,DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for DC=office,DC=eswcpc,DC=net.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
......................... GODZILLA passed test CutoffServers
Starting test: NCSecDesc
* Security Permissions check for all NC's on DC GODZILLA.
* Security Permissions Check for
DC=DomainDnsZones,DC=office,DC=eswcpc,DC=net
(NDNC,Version 2)
* Security Permissions Check for
DC=ForestDnsZones,DC=office,DC=eswcpc,DC=net
(NDNC,Version 2)
* Security Permissions Check for
CN=Schema,CN=Configuration,DC=office,DC=eswcpc,DC=net
(Schema,Version 2)
* Security Permissions Check for
CN=Configuration,DC=office,DC=eswcpc,DC=net
(Configuration,Version 2)
* Security Permissions Check for
DC=office,DC=eswcpc,DC=net
(Domain,Version 2)
......................... GODZILLA passed test NCSecDesc
Starting test: NetLogons
* Network Logons Privileges Check
Verified share \\GODZILLA\netlogon
Verified share \\GODZILLA\sysvol
......................... GODZILLA passed test NetLogons
Starting test: Advertising
The DC GODZILLA is advertising itself as a DC and having a DS.
The DC GODZILLA is advertising as an LDAP server
The DC GODZILLA is advertising as having a writeable directory
The DC GODZILLA is advertising as a Key Distribution Center
The DC GODZILLA is advertising as a time server
The DS GODZILLA is advertising as a GC.
......................... GODZILLA passed test Advertising
Starting test: KnowsOfRoleHolders
Role Schema Owner = CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
Role Domain Owner = CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
Role PDC Owner = CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
Role Rid Owner = CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
Role Infrastructure Update Owner = CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
......................... GODZILLA passed test KnowsOfRoleHolders
Starting test: RidManager
* Available RID Pool for the Domain is 16604 to 1073741823
* godzilla.office.eswcpc.net is the RID Master
* DsBind with RID Master was successful
* rIDAllocationPool is 14604 to 15103
* rIDPreviousAllocationPool is 14604 to 15103
* rIDNextRID: 14661
......................... GODZILLA passed test RidManager
Starting test: MachineAccount
Checking machine account for DC GODZILLA on DC GODZILLA.
* SPN found :LDAP/godzilla.office.eswcpc.net/office.eswcpc.net
* SPN found :LDAP/godzilla.office.eswcpc.net
* SPN found :LDAP/GODZILLA
* SPN found :LDAP/godzilla.office.eswcpc.net/OFFICE
* SPN found :LDAP/1529a0f5-2649-4c46-8aa3-77e87fdee157._msdcs.office.eswcpc.net
* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/1529a0f5-2649-4c46-8aa3-77e87fdee157/office.eswcpc.net
* SPN found :HOST/godzilla.office.eswcpc.net/office.eswcpc.net
* SPN found :HOST/godzilla.office.eswcpc.net
* SPN found :HOST/GODZILLA
* SPN found :HOST/godzilla.office.eswcpc.net/OFFICE
* SPN found :GC/godzilla.office.eswcpc.net/office.eswcpc.net
......................... GODZILLA passed test MachineAccount
Starting test: Services
* Checking Service: Dnscache
* Checking Service: NtFrs
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: RpcSs
* Checking Service: w32time
* Checking Service: NETLOGON
......................... GODZILLA passed test Services
Starting test: OutboundSecureChannels
* The Outbound Secure Channels test
** Did not run Outbound Secure Channels test
because /testdomain: was not entered
......................... GODZILLA passed test OutboundSecureChannels
Starting test: ObjectsReplicated
GODZILLA is in domain DC=office,DC=eswcpc,DC=net
Checking for CN=GODZILLA,OU=Domain Controllers,DC=office,DC=eswcpc,DC=net in domain
DC=office,DC=eswcpc,DC=net on 1 servers
Object is up-to-date on all servers.
Checking for CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net in
domain CN=Configuration,DC=office,DC=eswcpc,DC=net on 1 servers
Object is up-to-date on all servers.
......................... GODZILLA passed test ObjectsReplicated
Starting test: frssysvol
* The File Replication Service SYSVOL ready test
File Replication Service's SYSVOL is ready
......................... GODZILLA passed test frssysvol
Starting test: frsevent
* The File Replication Service Event log test
......................... GODZILLA passed test frsevent
Starting test: kccevent
* The KCC Event log test
An Error Event occured. EventID: 0xC00005C9
Time Generated: 06/22/2007 11:50:12
(Event String could not be retrieved)
(NUMEROUS REPEATED ERRORS LIKE ABOVE ARE LOGGED HERE)
......................... GODZILLA failed test kccevent
Starting test: systemlog
* The System Event log test
Found no errors in System Event log in the last 60 minutes.
......................... GODZILLA passed test systemlog
Starting test: VerifyReplicas
......................... GODZILLA passed test VerifyReplicas
Starting test: VerifyReferences
The system object reference (serverReference) CN=GODZILLA,OU=Domain
Controllers,DC=office,DC=eswcpc,DC=net and backlink on
CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net are
correct.
Some objects relating to the DC GODZILLA have problems:
[1] Problem: Missing Expected Value Base Object: CN=GODZILLA,OU=Domain
Controllers,DC=office,DC=eswcpc,DC=net Base Object Description: "DC Account Object" Value
Object Attribute Name: frsComputerReferenceBL Value Object Description: "SYSVOL FRS Member Object"
Recommended Action: See Knowledge Base Article: Q312862
[1] Problem: Missing Expected Value Base Object: CN=NTDS
Settings,CN=GODZILLA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=office,DC=eswcpc,DC=net
Base Object Description: "DSA Object" Value Object Attribute Name: serverReferenceBL
Value Object Description: "SYSVOL FRS Member Object" Recommended Action: See Knowledge Base Article:
Q312862
......................... GODZILLA failed test VerifyReferences
Starting test: VerifyEnterpriseReferences
The following problems were found while verifying various important DN references. Note, that
these problems can be reported because of latency in replication. So follow up to resolve the following
problems, only if the same problem is reported on all DCs for a given domain or if the problem persists
after replication has had reasonable time to replicate changes.
[1] Problem: Missing Expected Value Base Object: CN=GODZILLA,OU=Domain
Controllers,DC=office,DC=eswcpc,DC=net Base Object Description: "DC Account Object" Value
Object Attribute Name: frsComputerReferenceBL Value Object Description: "SYSVOL FRS Member Object"
Recommended Action: See Knowledge Base Article: Q312862
LDAP Error 0x5e (94) - No result present in message.
......................... GODZILLA failed test VerifyEnterpriseReferences
Starting test: CheckSecurityError
* Dr Auth: Beginning security errors check!
Found KDC GODZILLA for domain office.eswcpc.net in site Default-First-Site-Name
Checking machine account for DC GODZILLA on DC GODZILLA.
* SPN found :LDAP/godzilla.office.eswcpc.net/office.eswcpc.net
* SPN found :LDAP/godzilla.office.eswcpc.net
* SPN found :LDAP/GODZILLA
* SPN found :LDAP/godzilla.office.eswcpc.net/OFFICE
* SPN found :LDAP/1529a0f5-2649-4c46-8aa3-77e87fdee157._msdcs.office.eswcpc.net
* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/1529a0f5-2649-4c46-8aa3-77e87fdee157/office.eswcpc.net
* SPN found :HOST/godzilla.office.eswcpc.net/office.eswcpc.net
* SPN found :HOST/godzilla.office.eswcpc.net
* SPN found :HOST/GODZILLA
* SPN found :HOST/godzilla.office.eswcpc.net/OFFICE
* SPN found :GC/godzilla.office.eswcpc.net/office.eswcpc.net
[GODZILLA] No security related replication errors were found on this DC! To target the connection to a
specific source DC use /ReplSource:<DC>.
......................... GODZILLA passed test CheckSecurityError
DNS Tests are running and not hung. Please wait a few minutes...
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : office
Starting test: CrossRefValidation
......................... office passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... office passed test CheckSDRefDom
Running enterprise tests on : office.eswcpc.net
Starting test: Intersite
Skipping site Default-First-Site-Name, this site is outside the scope provided by the command line
arguments provided.
......................... office.eswcpc.net passed test Intersite
Starting test: FsmoCheck
GC Name: \\godzilla.office.eswcpc.net
Locator Flags: 0xe00003fd
PDC Name: \\godzilla.office.eswcpc.net
Locator Flags: 0xe00003fd
Time Server Name: \\godzilla.office.eswcpc.net
Locator Flags: 0xe00003fd
Preferred Time Server Name: \\godzilla.office.eswcpc.net
Locator Flags: 0xe00003fd
KDC Name: \\godzilla.office.eswcpc.net
Locator Flags: 0xe00003fd
......................... office.eswcpc.net passed test FsmoCheck
Starting test: DNS
Test results for domain controllers:
DC: godzilla.office.eswcpc.net
Domain: office.eswcpc.net
TEST: Authentication (Auth)
Authentication test: Successfully completed
TEST: Basic (Basc)
Microsoft(R) Windows(R) Server 2003, Enterprise Edition (Service Pack level: 2.0) is supported
NETLOGON service is running
kdc service is running
DNSCACHE service is running
DNS service is running
DC is a DNS server
Network adapters information:
Adapter [00000012] VMware Accelerated AMD PCNet Adapter:
MAC address is 00:0C:29:3B:71:3F
IP address is static
IP address: 192.168.1.133
DNS servers:
192.168.1.133 (<name unavailable>) [Valid]
Warning: 192.168.1.101 (<name unavailable>) [Invalid (unreachable)]
The A record for this DC was found
The SOA record for the Active Directory zone was found
The Active Directory zone on this DC/DNS server was found (primary)
Root zone on this DC/DNS server was not found
TEST: Forwarders/Root hints (Forw)
Recursion is enabled
Forwarders are not configured on this DNS server
Root hint Information:
Name: a.root-servers.net. IP: 198.41.0.4 [Invalid]
Name: b.root-servers.net. IP: 192.228.79.201 [Invalid]
Name: c.root-servers.net. IP: 192.33.4.12 [Invalid]
Name: d.root-servers.net. IP: 128.8.10.90 [Invalid]
Name: e.root-servers.net. IP: 192.203.230.10 [Invalid]
Name: f.root-servers.net. IP: 192.5.5.241 [Invalid]
Name: g.root-servers.net. IP: 192.112.36.4 [Invalid]
Name: h.root-servers.net. IP: 128.63.2.53 [Invalid]
Name: i.root-servers.net. IP: 192.36.148.17 [Invalid]
Name: j.root-servers.net. IP: 192.58.128.30 [Invalid]
Name: k.root-servers.net. IP: 193.0.14.129 [Invalid]
Name: l.root-servers.net. IP: 198.32.64.12 [Invalid]
Name: m.root-servers.net. IP: 202.12.27.33 [Invalid]
TEST: Delegations (Del)
No delegations were found in this zone on this DNS server
TEST: Dynamic update (Dyn)
Dynamic update is enabled on the zone office.eswcpc.net.
Test record _dcdiag_test_record added successfully in zone office.eswcpc.net.
Test record _dcdiag_test_record deleted successfully in zone office.eswcpc.net.
TEST: Records registration (RReg)
Network Adapter [00000012] VMware Accelerated AMD PCNet Adapter:
Matching A record found at DNS server 192.168.1.133:
godzilla.office.eswcpc.net
Matching CNAME record found at DNS server 192.168.1.133:
1529a0f5-2649-4c46-8aa3-77e87fdee157._msdcs.office.eswcpc.net
Matching DC SRV record found at DNS server 192.168.1.133:
_ldap._tcp.dc._msdcs.office.eswcpc.net
Matching GC SRV record found at DNS server 192.168.1.133:
_ldap._tcp.gc._msdcs.office.eswcpc.net
Matching PDC SRV record found at DNS server 192.168.1.133:
_ldap._tcp.pdc._msdcs.office.eswcpc.net
Summary of test results for DNS servers used by the above domain controllers:
DNS server: 128.63.2.53 (h.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 128.63.2.53
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 128.8.10.90 (d.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 128.8.10.90
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.112.36.4 (g.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.112.36.4
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]
DNS server: 192.168.1.101 (<name unavailable>)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.168.1.101
[Error details: 1460 (Type: Win32 - Description: This operation returned because the timeout period
expired.)]
Name resolution is not functional. _ldap._tcp.office.eswcpc.net. failed on the DNS server
192.168.1.101
[Error details: 1460 (Type: Win32 - Description: This operation returned because the timeout period
expired.)]
DNS server: 192.203.230.10 (e.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.203.230.10
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.228.79.201 (b.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.228.79.201
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.33.4.12 (c.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.33.4.12
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.36.148.17 (i.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.36.148.17
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.5.5.241 (f.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.5.5.241
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.58.128.30 (j.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 192.58.128.30
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]
DNS server: 193.0.14.129 (k.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 193.0.14.129
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 198.32.64.12 (l.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 198.32.64.12
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 198.41.0.4 (a.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 198.41.0.4
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 202.12.27.33 (m.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS
server 202.12.27.33
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
DNS server: 192.168.1.133 (<name unavailable>)
All tests passed on this DNS server
This is a valid DNS server.
Name resolution is funtional. _ldap._tcp SRV record for the forest root domain is registered
Summary of DNS test results:
Auth Basc Forw Del Dyn RReg Ext
________________________________________________________________
Domain: office.eswcpc.net
godzilla PASS WARN FAIL PASS PASS PASS n/a
......................... office.eswcpc.net failed test DNS