Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

DCDIAG /test:DNS failure

Status
Not open for further replies.

aec106

MIS
Jul 19, 2007
3
0
0
US
I just ran dcdiag /test:DNS /DNSALL /e /v on my DNS server and received an error in the output. I am not having any problems with my network though. Could someone give me some advice how to fix this?


Domain Controller Diagnosis

Performing initial setup:
* Verifying that the local machine PE2900B, is a DC.
* Connecting to directory service on server PE2900B.
* Collecting site info.
* Identifying all servers.
* Identifying all NC cross-refs.
* Found 2 DC(s). Testing 2 of them.
Done gathering initial info.

Doing initial required tests

Testing server: Default-First-Site-Name\PE4600
Starting test: Connectivity
* Active Directory LDAP Services Check
* Active Directory RPC Services Check
......................... PE4600 passed test Connectivity

Testing server: Default-First-Site-Name\PE2900B
Starting test: Connectivity
* Active Directory LDAP Services Check
* Active Directory RPC Services Check
......................... PE2900B passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\PE4600
Test omitted by user request: Replications
Test omitted by user request: Topology
Test omitted by user request: CutoffServers
Test omitted by user request: NCSecDesc
Test omitted by user request: NetLogons
Test omitted by user request: Advertising
Test omitted by user request: KnowsOfRoleHolders
Test omitted by user request: RidManager
Test omitted by user request: MachineAccount
Test omitted by user request: Services
Test omitted by user request: OutboundSecureChannels
Test omitted by user request: ObjectsReplicated
Test omitted by user request: frssysvol
Test omitted by user request: frsevent
Test omitted by user request: kccevent
Test omitted by user request: systemlog
Test omitted by user request: VerifyReplicas
Test omitted by user request: VerifyReferences
Test omitted by user request: VerifyEnterpriseReferences
Test omitted by user request: CheckSecurityError

Testing server: Default-First-Site-Name\PE2900B
Test omitted by user request: Replications
Test omitted by user request: Topology
Test omitted by user request: CutoffServers
Test omitted by user request: NCSecDesc
Test omitted by user request: NetLogons
Test omitted by user request: Advertising
Test omitted by user request: KnowsOfRoleHolders
Test omitted by user request: RidManager
Test omitted by user request: MachineAccount
Test omitted by user request: Services
Test omitted by user request: OutboundSecureChannels
Test omitted by user request: ObjectsReplicated
Test omitted by user request: frssysvol
Test omitted by user request: frsevent
Test omitted by user request: kccevent
Test omitted by user request: systemlog
Test omitted by user request: VerifyReplicas
Test omitted by user request: VerifyReferences
Test omitted by user request: VerifyEnterpriseReferences
Test omitted by user request: CheckSecurityError

DNS Tests are running and not hung. Please wait a few minutes...

Running partition tests on : ForestDnsZones
Test omitted by user request: CrossRefValidation
Test omitted by user request: CheckSDRefDom

Running partition tests on : DomainDnsZones
Test omitted by user request: CrossRefValidation
Test omitted by user request: CheckSDRefDom

Running partition tests on : Schema
Test omitted by user request: CrossRefValidation
Test omitted by user request: CheckSDRefDom

Running partition tests on : Configuration
Test omitted by user request: CrossRefValidation
Test omitted by user request: CheckSDRefDom

Running partition tests on : mydomain
Test omitted by user request: CrossRefValidation
Test omitted by user request: CheckSDRefDom

Running enterprise tests on : mydomain.com
Test omitted by user request: Intersite
Test omitted by user request: FsmoCheck
Starting test: DNS
Test results for domain controllers:

DC: pe4600.mydomain.com
Domain: mydomain.com


TEST: Authentication (Auth)
Authentication test: Successfully completed

TEST: Basic (Basc)
Microsoft(R) Windows(R) Server 2003, Standard Edition (Service Pack level: 2.0) is supported
NETLOGON service is running
kdc service is running
DNSCACHE service is running
DNS service is running
DC is a DNS server
Network adapters information:
Adapter [00000002] Intel(R) PRO/100 Network Connection:
MAC address is 00:15:C5:ED:C3:B6
IP address is static
IP address: 192.168.6.5
DNS servers:
192.168.6.3 (<name unavailable>) [Valid]
The A record for this DC was found
The SOA record for the Active Directory zone was found
The Active Directory zone on this DC/DNS server was found (primary)
Root zone on this DC/DNS server was not found

TEST: Forwarders/Root hints (Forw)
Recursion is enabled
Forwarders are not configured on this DNS server
Root hint Information:
Name: a.root-servers.net. IP: 198.41.0.4 [Invalid]
Name: b.root-servers.net. IP: 192.228.79.201 [Invalid]
Name: c.root-servers.net. IP: 192.33.4.12 [Invalid]
Name: d.root-servers.net. IP: 128.8.10.90 [Invalid]
Name: e.root-servers.net. IP: 192.203.230.10 [Invalid]
Name: f.root-servers.net. IP: 192.5.5.241 [Invalid]
Name: g.root-servers.net. IP: 192.112.36.4 [Invalid]
Name: h.root-servers.net. IP: 128.63.2.53 [Invalid]
Name: i.root-servers.net. IP: 192.36.148.17 [Invalid]
Name: j.root-servers.net. IP: 192.58.128.30 [Invalid]
Name: k.root-servers.net. IP: 193.0.14.129 [Invalid]
Name: l.root-servers.net. IP: 198.32.64.12 [Invalid (unreachable)]
Name: l.root-servers.net. IP: 199.7.83.42 [Invalid (unreachable)]
Name: m.root-servers.net. IP: 202.12.27.33 [Invalid]

TEST: Delegations (Del)
No delegations were found in this zone on this DNS server

TEST: Dynamic update (Dyn)
Dynamic update is enabled on the zone mydomain.com.
Test record _dcdiag_test_record added successfully in zone mydomain.com.
Test record _dcdiag_test_record deleted successfully in zone mydomain.com.

TEST: Records registration (RReg)
Network Adapter [00000002] Intel(R) PRO/100 Network Connection:
Matching A record found at DNS server 192.168.6.3:
pe4600.mydomain.com

Matching CNAME record found at DNS server 192.168.6.3:
f87e4cab-26b6-4789-b2c8-17482fbc9ffc._msdcs.mydomain.com

Matching DC SRV record found at DNS server 192.168.6.3:
_ldap._tcp.dc._msdcs.mydomain.com


TEST: External name resolution (Ext)
Internet name was resolved successfully


DC: PE2900B.mydomain.com
Domain: mydomain.com


TEST: Authentication (Auth)
Authentication test: Successfully completed

TEST: Basic (Basc)
Microsoft(R) Windows(R) Server 2003, Standard Edition (Service Pack level: 2.0) is supported
NETLOGON service is running
kdc service is running
DNSCACHE service is running
DNS service is running
DC is a DNS server
Network adapters information:
Adapter [00000007] Broadcom BCM5708C NetXtreme II GigE (NDIS VBD Client):
MAC address is 00:18:8B:50:99:D7
IP address is static
IP address: 192.168.6.3
DNS servers:
192.168.6.3 (<name unavailable>) [Valid]
The A record for this DC was found
The SOA record for the Active Directory zone was found
The Active Directory zone on this DC/DNS server was found (primary)
Root zone on this DC/DNS server was not found

TEST: Forwarders/Root hints (Forw)
Recursion is enabled
Forwarders are not configured on this DNS server
Root hint Information:
Name: a.root-servers.net. IP: 198.41.0.4 [Invalid]
Name: b.root-servers.net. IP: 192.228.79.201 [Invalid]
Name: c.root-servers.net. IP: 192.33.4.12 [Invalid]
Name: d.root-servers.net. IP: 128.8.10.90 [Invalid]
Name: e.root-servers.net. IP: 192.203.230.10 [Invalid]
Name: f.root-servers.net. IP: 192.5.5.241 [Invalid]
Name: g.root-servers.net. IP: 192.112.36.4 [Invalid]
Name: h.root-servers.net. IP: 128.63.2.53 [Invalid]
Name: i.root-servers.net. IP: 192.36.148.17 [Invalid]
Name: j.root-servers.net. IP: 192.58.128.30 [Invalid]
Name: k.root-servers.net. IP: 193.0.14.129 [Invalid]
Name: l.root-servers.net. IP: 198.32.64.12 [Invalid (unreachable)]
Name: m.root-servers.net. IP: 202.12.27.33 [Invalid]

TEST: Delegations (Del)
No delegations were found in this zone on this DNS server

TEST: Dynamic update (Dyn)
Dynamic update is enabled on the zone mydomain.com.
Test record _dcdiag_test_record added successfully in zone mydomain.com.
Test record _dcdiag_test_record deleted successfully in zone mydomain.com.

TEST: Records registration (RReg)
Network Adapter [00000007] Broadcom BCM5708C NetXtreme II GigE (NDIS VBD Client):
Matching A record found at DNS server 192.168.6.3:
PE2900B.mydomain.com

Matching CNAME record found at DNS server 192.168.6.3:
66febbcd-9d1e-422f-8360-613e00885ceb._msdcs.mydomain.com

Matching DC SRV record found at DNS server 192.168.6.3:
_ldap._tcp.dc._msdcs.mydomain.com

Matching GC SRV record found at DNS server 192.168.6.3:
_ldap._tcp.gc._msdcs.mydomain.com

Matching PDC SRV record found at DNS server 192.168.6.3:
_ldap._tcp.pdc._msdcs.mydomain.com


TEST: External name resolution (Ext)
Internet name was resolved successfully

Summary of test results for DNS servers used by the above domain controllers:

DNS server: 128.63.2.53 (h.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 128.63.2.53
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 128.8.10.90 (d.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 128.8.10.90
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 192.112.36.4 (g.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.112.36.4
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 192.203.230.10 (e.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.203.230.10
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 192.228.79.201 (b.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.228.79.201
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 192.33.4.12 (c.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.33.4.12
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 192.36.148.17 (i.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.36.148.17
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 192.5.5.241 (f.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.5.5.241
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 192.58.128.30 (j.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.58.128.30
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 193.0.14.129 (k.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 193.0.14.129
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 198.32.64.12 (l.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 198.32.64.12
[Error details: 1460 (Type: Win32 - Description: This operation returned because the timeout period expired.)]

DNS server: 198.41.0.4 (a.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 198.41.0.4
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 202.12.27.33 (m.root-servers.net.)
2 test failures on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 202.12.27.33
[Error details: 9002 (Type: Win32 - Description: DNS server failure.)]

DNS server: 199.7.83.42 (l.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 199.7.83.42
[Error details: 1460 (Type: Win32 - Description: This operation returned because the timeout period expired.)]

DNS server: 192.168.6.3 (<name unavailable>)
All tests passed on this DNS server
This is a valid DNS server.
Name resolution is funtional. _ldap._tcp SRV record for the forest root domain is registered

Summary of DNS test results:

Auth Basc Forw Del Dyn RReg Ext
________________________________________________________________
Domain: mydomain.com
pe4600 PASS PASS FAIL PASS PASS PASS PASS
PE2900B PASS PASS FAIL PASS PASS PASS PASS

......................... mydomain.com failed test DNS
 
If you are referring to the errors with regards to root hints, it's possible that there not considered valid because you can't resolve them directly from your AD DNS server. I am not sure if your domain controller is allowed to go out on the internet, but as far as I recall you don't typically need internet domain root hints for an Internal DNS server supporting your AD infrastructure (other can chime in on this).
I don't see any other problem (unless I missed something)as your AD/DNS name resolution looks fine.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top