Windows Server - dns integrated zones not replicated to new DCs in new site
Asked By eduard
17-Sep-08 05:32 PM
Hi, I recently added a new DC in a new site, the configuration, schme and
domain partitions replicated fine, but the domaindnszones and forestdnszones
are not being replicated even though the DNS service is installed on the new
server.
My current domain has been adprep to have WS2008 DCs, so I have one 2003 and
on 2008 en each of the sites. on the default first site there were no
problems replicating these AD partitions, but on the new site I can´t get
them replicated (the domain and forest dns zones). I did created the Site on
the AD Sites and Services and also created the subnet.
Is There any other configuration I´m am missing?
please advice!
thanks for all the help!
DNS
(1)
DC
(1)
DnsMgmt
(1)
AD
(1)
HiWhen
(1)
PDC
(1)
WS
(1)
NS
(1)
Meinolf Weber replied...
Hello eduardo,
How did you configure the "replication" on the _msdcs zone properties general
tab? And also on the domain zone properties general tab?
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
VipinChhabr replied...
Hi
When you open DnsMgmt.msc console on new DC do you see all the records
except DomainDNSZone & ForestDNSZone?
If not, then please try to point New DC to PDC for NS Name resolution
Run following commands:
Net stop Netlogon & Net stop DNS & Net Start Netlogon & Net Start DNS
Nic replied...
Hello,
Make sure you have Zone Transfers enable on the DNS properties.
DNS zone on other server should be Active directory Integrated.
Also make sure that your new DC is pointing to other DC for DNS & Seconday
DNS is empty.
If you still don't see zone populated > create a Zone with your domain &
right click on DNS server > Select Transfer from Master. This will transfer
the DNS Database from your previous DNS server.
Cheers!!
DCs. I transfered all FSMO roles to the new DCs and made them global catalogs, DNS servers and DHCP servers. I pointed all DCs to themselves and eachother for DNS. I then tried to demote the old 2003 DC to a member server to remove it from the network. It fails with and error that the "last domain controller in domain" check box in not checked, but no other DC could be contacted. I ran dcdiag. . . . it says that no global catalog could be contacted running on another 2003 server. In Exchange managment console, it only shows the one 2003 DC as well, nothing about the 2008 DCs. I looks like a DNS error somewhere, but I can't find the problem. Forest and Domain functional level are highestCommittedUSN (1) DC1A.isGlobalCatalogReady (1) Windows Server 2003 (1) Hello DKB, Make sure the 2003 DC is using the new DNS servers and also that all entries are listed in the DNS zones. Uncheck the GC
the pdc manually but could only add it to the domain using dcpromo as another dc, there didn't seem anyway of adding it as a primary domain controller. We seem highfield-pdc01. * Collecting site info. * Identifying all servers. * Identifying all NC cross-refs. * Found 2 DC(s). Testing 2 of them. Done gathering initial info. Doing initial required tests Testing server server: Default-First-Site-Name \ HIGHFIELD-BDC01 Starting test: Replications * Replications Check * Replication Latency Check DC = ForestDnsZones, DC = highfield, DC = local Latency information for 5 entries in the vector were ignored. 5 were retired Invocations 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC). DC = DomainDnsZones, DC = highfield, DC = local Latency information for 5 entries in the vector were ignored
1) Windows Server (1) RIDNextRID (1) RIDPreviousAllocationPool (1) DsBindWithSpnEx (1) Hello Andy, Start the other DC and check that replication is done correct with repadmin / showrepl or use replmon from the run line. Also run dcdiag / v and netdiag / v to check for errors on both DC's. If you have errors please post the output complete here. Before shutting down or removing a DC you should always check that the other DC is healthy. Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no v : Domain Controller Diagnosis Performing initial setup: * Verifying that the local machine fileserver, is a DC. * Connecting to directory service on server fileserver. * Collecting site info. * Identifying all servers. * Identifying all NC cross-refs. * Found 2 DC(s). Testing 1 of them. Done gathering initial info. Doing initial required tests Testing server Check [Replications Check, FILESERVER] A recent replication attempt failed: From FILE_SERVER to FILESERVER Naming Context: DC = ForestDnsZones, DC = Royalchemie, DC = com The replication generated an error (8524): The DSA operation is unable to
keep the explaintion fairly short. I have 2 new 2008 servers that I have added AD to. These are being added to a Domain that currently has 2 -2003 DC's. I did the Adprep for forest, domain and GPs. Everything went OK until it to replicate. . . . here is what I get. . . (by the way - the 2 2003 DCs have DNS on them) When I try to initiate a replication form either 2008 DC- to any server - I get this error - "the following occured during attempt to contact (current is not replicated for the speific server." I have looked at a lot of the DNS problem solving ideas. . . but everything looks to be OK with DNS. Could this be a 2008 issue rather then a DNS issue??? Has anyone run into this when introducing 2008 into the Domain. Any help or thanks in advance!!! ALso, the only odd thing I noticed was when installing the 2nd DC, a message said it ofund 3 DNS servers in the Domain. there are only 2
2008 DC Stops responding to local logins Windows Server We have a 2008 DC that seems to lose most network connectivity, but not all, every few days. We are in 2003 functional mode. We have an empty root domain and two child domains. . this DC is in the main resource child domain. When the problem occurs, our monitoring system immediately an exchange server under normal conditions. Our campus environment is forced to use a BIND DNS implementation for the SRV records. Although, I get numerous errors logged from this, it essentially RPC) and 1232 around the time on at least one occasion of the problem. The DNS errors in the dcdiag output can be ignored. Our DCs cannot always reach the DNS server so routine updates sometimes fail, but they work often enough that they are always that the local machine dcontroller05, is a Directory Server. Home Server = dcontroller05 snip . . . * Found 13 DC(s). Testing 1 of them. Done gathering initial info. Doing initial required tests Testing server dcontroller05 passed test Connectivity Doing primary tests Testing server: universityCampus \ dcontroller05 Starting test: Advertising The DC dcontroller05 is advertising itself as a DC and having a DS. The DC dcontroller05 is