 | |
06-21-2003, 10:56 PM
|
#1 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Coquitlam BC
Posts: 705
| » 
Active Directory is dead!
Can't access AD! I'm not sure what happened. When I try to open AD either through admin tools or one of my custom mmc's I get the hour glass for a couple of seconds then nothing.
The only thing my event viewer is showing is a DNS error because it can't open my domains zone in the AD! Event ID: 4001.
I'm running W2K server w/sp3
Any thoughts?
Thanks
Al
__________________
Eat, drink and be merry... |
| |
06-22-2003, 09:24 AM
|
#2 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Ohio
Posts: 5,577
|
Is the DNS server IP setting the same as the IP address of your AD integrated DNS server?
|
| |
06-22-2003, 02:17 PM
|
#3 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Coquitlam BC
Posts: 705
|
Yes it is. My AD server is is my DNS server as well. When I was setting up DNS, I set it up as Standard Primary and not AD Integrated.
__________________
Eat, drink and be merry... |
| |
06-23-2003, 03:27 AM
|
#4 (permalink)
| | Banned
Join Date: Feb 2003 Location: Houston, TX
Posts: 1,595
|
Does the DNS still work? Can you do an nslookup using it? Have you tried restarting the DNS Server service or bouncing the box?
AD Integrated or not as long as the correct resource records are there it will work, just changes where the records are stored and security I believe. I have used Bind 9 with AD so I know it doesnt have to be integrated.
Oh yeah, and can you reach the DNS server?
|
| |
06-23-2003, 05:49 AM
|
#5 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Ohio
Posts: 5,577
|
The two additional requirements for AD DNS is...
1) Support for Service Location (SRV) records, as per RFC 2782
2) Support for dynamic updates
...this is often called AD integrated (even BIND DNS 4.9.7 versions and alter). Hence, you need an AD integrated DNS server.
If this W2K box your only AD compatible DNS server, you need to choose AD integrated when setting it up. Else you can not reach your AD.
|
| |
06-23-2003, 09:33 AM
|
#6 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Coquitlam BC
Posts: 705
|
Thanks
I'm at the office right now, I'll try out your suggestions tonight when I get home.
Al
__________________
Eat, drink and be merry... |
| |
06-23-2003, 09:52 AM
|
#7 (permalink)
| | Registered User
Join Date: Jun 2003 Location: NJ
Posts: 1,096
|
You can use a Standard Primary DNS zone with AD. Actually when you want to setup an Active Directory Domain Controller, before you run dcpromo, you should get DNS setup first with a Standard Primary Zone. Once you create your forward and reverse lookup zones, you NEED to go to the properties of the zone and set "Allow dynamic updates" to "Yes". This is critical, because if you forget and you run dcpromo, you will have to run dcpromo again to bump it back down to a member to fix the problem. Once you have successfully setup AD, you can change your DNS zone to AD Integrated if you want.
|
| |
06-23-2003, 08:35 PM
|
#8 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Coquitlam BC
Posts: 705
|
After checking the properties I found that It is AD integrated (although I don't remember setting it up that way). Allow Dynamic updates is set to "yes". The status is "Running". I forgot to mention (and this is probably important) that this was sudden. AD and DNS were working fine up to a couple of months. I was playing around with some Group Policies (studying for 215). I'm sure the only thing I did was delete the policies that I had put in place.
NSlookup is not working. This is what I get.
*** Can't find server name for address 192.168.*.*: Non-existent domain
*** Default servers are not available
Default Server: UnKnown
Address: 192.168.*.*
Al
__________________
Eat, drink and be merry... |
| |
06-23-2003, 08:39 PM
|
#9 (permalink)
| | Banned
Join Date: Feb 2003 Location: Houston, TX
Posts: 1,595
|
Your DNS is broken. Look in event viewer, there is a log there just for the DNS server. Have you bounced it yet?
|
| |
06-23-2003, 09:39 PM
|
#10 (permalink)
| | Registered User
Join Date: Oct 2001 Location: Coquitlam BC
Posts: 705
|
I don't think I understand what you mean by bouning. I posted the error in event viewer in the opening thread,
it is
Event ID: 4001
The DNS server was unable to open zone piperni.com in the Active Directory. This DNS Server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code.
and it was logged on 29/05.
DNS is starting, and name resolution on the network is still working. Am I barking up the wrong tree here?
Thanks for your help
Al
__________________
Eat, drink and be merry... |
| | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | | | Thread Tools | | | | Display Modes | Linear Mode |
Posting Rules
| You may not post new threads You may not post replies You may not post attachments You may not edit your posts HTML code is Off | | | | Most Active Discussions  | | | | | Recent Discussions  | | | | | |