Currently we have an issue with getting policies over a forest trust and accessing an dfs over an forest trust.
Main issues:
- We cannot access data on DFS in domain A from domain B
- Neither can we access data on DFS in domain B from domain A
- logging in on a workstation in domain B with a useraccount from domain A is possible, though userpolicies (gpo's) (from domain A) are not applied.
Our situation:
Domain A in Forest A
Domain B in Forest B
Between the two forests is an two-way transitive forest trust in place.
Accessing the DFS-folders in domain A from domain A = OK
Accessing the DFS-folders in domain A from domain B = ERROR
"Configuration information could not be read from the domaincontroller, either because the machine in unavailable, or access has been denied"
Accessing the DFS-folders in domain B from domain B = OK
Accessing the DFS-folders in domain B from domain A = ERROR
"Configuration information could not be read from the domaincontroller, either because the machine in unavailable, or access has been denied"
Note: DFS in Domain A is not the same as DFS in Domain B
So we have a DFS in Domain A and we have a DFS in Domain B with both different content
Running dcdiag with target domain A from domain A = all test succeeded
Running dcdiag with target domain B from domain B = all test succeeded
Running dcdiag with target domain A from domain B = ERRORS
Running dcdiag with target domain B from domain A = ERRORS
Output of dcdiag:
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\DC1
Starting test: Connectivity
......................... DC1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\DC1
Starting test: Replications
......................... DC1 passed test Replications
Starting test: NCSecDesc
......................... DC1 passed test NCSecDesc
Starting test: NetLogons
[DC1] An net use or LsaPolicy operation failed with error 1203, No
network provider accepted the given network path..
......................... DC1 failed test NetLogons
Starting test: Advertising
Fatal ErrorsGetDcName (DC1) call failed, error 1722
The Locator could not find the server.
......................... DC1 failed test Advertising
Starting test: KnowsOfRoleHolders
......................... DC1 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... DC1 passed test RidManager
Starting test: MachineAccount
Could not open pipe with [DC1]:failed with 1203: No network provid
er accepted the given network path.
Could not get NetBIOSDomainName
Failed can not test for HOST SPN
Failed can not test for HOST SPN
* Missing SPN null)
* Missing SPN null)
......................... DC1 failed test MachineAccount
Starting test: Services
Could not open Remote ipc to [DC1]:failed with 1203: No network provider accepted the given network path.
......................... DC1 failed test Services
Starting test: ObjectsReplicated
......................... DC1 passed test ObjectsReplicated
Starting test: frssysvol
[DC1] An net use or LsaPolicy operation failed with error 1203, No
network provider accepted the given network path..
......................... DC1 failed test frssysvol
Starting test: frsevent
......................... DC1 failed test frsevent
Starting test: kccevent
Failed to enumerate event log records, error No network provider accept
ed the given network path.
......................... DC1 failed test kccevent
Starting test: systemlog
Failed to enumerate event log records, error No network provider accept
ed the given network path.
......................... DC1 failed test systemlog
Starting test: VerifyReferences
......................... DC1 passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : domaina
Starting test: CrossRefValidation
......................... domaina passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... domaina passed test CheckSDRefDom
Running enterprise tests on : domaina.local
Starting test: Intersite
......................... domaina.local passed test Intersite
Starting test: FsmoCheck
Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1722
A Global Catalog Server could not be located - All GC's are down.
Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1722
A Primary Domain Controller could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(TIME_SERVER) call failed, error 1722
A Time Server could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 172
2
A Good Time Server could not be located.
Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1722
A KDC could not be located - All the KDCs are down.
......................... domaina.local failed test FsmoCheck
We checked ADSS and NO items of historical servers were found.
Any ideas ? Cause i'm pretty stuck on this ... (
Main issues:
- We cannot access data on DFS in domain A from domain B
- Neither can we access data on DFS in domain B from domain A
- logging in on a workstation in domain B with a useraccount from domain A is possible, though userpolicies (gpo's) (from domain A) are not applied.
Our situation:
Domain A in Forest A
Domain B in Forest B
Between the two forests is an two-way transitive forest trust in place.
Accessing the DFS-folders in domain A from domain A = OK
Accessing the DFS-folders in domain A from domain B = ERROR
"Configuration information could not be read from the domaincontroller, either because the machine in unavailable, or access has been denied"
Accessing the DFS-folders in domain B from domain B = OK
Accessing the DFS-folders in domain B from domain A = ERROR
"Configuration information could not be read from the domaincontroller, either because the machine in unavailable, or access has been denied"
Note: DFS in Domain A is not the same as DFS in Domain B
So we have a DFS in Domain A and we have a DFS in Domain B with both different content
Running dcdiag with target domain A from domain A = all test succeeded
Running dcdiag with target domain B from domain B = all test succeeded
Running dcdiag with target domain A from domain B = ERRORS
Running dcdiag with target domain B from domain A = ERRORS
Output of dcdiag:
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\DC1
Starting test: Connectivity
......................... DC1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\DC1
Starting test: Replications
......................... DC1 passed test Replications
Starting test: NCSecDesc
......................... DC1 passed test NCSecDesc
Starting test: NetLogons
[DC1] An net use or LsaPolicy operation failed with error 1203, No
network provider accepted the given network path..
......................... DC1 failed test NetLogons
Starting test: Advertising
Fatal ErrorsGetDcName (DC1) call failed, error 1722
The Locator could not find the server.
......................... DC1 failed test Advertising
Starting test: KnowsOfRoleHolders
......................... DC1 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... DC1 passed test RidManager
Starting test: MachineAccount
Could not open pipe with [DC1]:failed with 1203: No network provid
er accepted the given network path.
Could not get NetBIOSDomainName
Failed can not test for HOST SPN
Failed can not test for HOST SPN
* Missing SPN null)
* Missing SPN null)
......................... DC1 failed test MachineAccount
Starting test: Services
Could not open Remote ipc to [DC1]:failed with 1203: No network provider accepted the given network path.
......................... DC1 failed test Services
Starting test: ObjectsReplicated
......................... DC1 passed test ObjectsReplicated
Starting test: frssysvol
[DC1] An net use or LsaPolicy operation failed with error 1203, No
network provider accepted the given network path..
......................... DC1 failed test frssysvol
Starting test: frsevent
......................... DC1 failed test frsevent
Starting test: kccevent
Failed to enumerate event log records, error No network provider accept
ed the given network path.
......................... DC1 failed test kccevent
Starting test: systemlog
Failed to enumerate event log records, error No network provider accept
ed the given network path.
......................... DC1 failed test systemlog
Starting test: VerifyReferences
......................... DC1 passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : domaina
Starting test: CrossRefValidation
......................... domaina passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... domaina passed test CheckSDRefDom
Running enterprise tests on : domaina.local
Starting test: Intersite
......................... domaina.local passed test Intersite
Starting test: FsmoCheck
Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1722
A Global Catalog Server could not be located - All GC's are down.
Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1722
A Primary Domain Controller could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(TIME_SERVER) call failed, error 1722
A Time Server could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 172
2
A Good Time Server could not be located.
Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1722
A KDC could not be located - All the KDCs are down.
......................... domaina.local failed test FsmoCheck
We checked ADSS and NO items of historical servers were found.
Any ideas ? Cause i'm pretty stuck on this ... (