DNS Nightmare - Can't create forward zone



Hi,

I am having trouble with Active Directory and DNS on a new Windows 2003
box. The default entries (_ldap etc.) which are usually created by
netlogon are not there, nor can I manage to create them. I have tried
creating the forward zone from scratch, however I am not able to.

When I try to create a new forward zone, I get the message:

"The zone cannot be replicated to all DNS servers in the (null) Active
Directory domain because the required application directory partition
does not exist. Only Enterprise Administrators have the appropriate
permissions to create an application directory partition."

As I'm logged on as Administrator, which is in the Enterprise Admins
group, this is somewhat worrying!

The message goes on to advise me to try using "Replicate to All Domain
Controllers in the Active Directory Domain" option. When I do this I
get:

"The zone can not be created - The data is invalid"


netdiag /fix gives the following output:

<snip>

DNS test . . . . . . . . . . . . . : Failed
[WARNING] Cannot find a primary authoritative DNS server for
the name
'dbsvr.domain.net.'. [ERROR_TIMEOUT]
The name 'dbsvr.domain.net.' may not be registered in DNS.
[WARNING] Cannot find a primary authoritative DNS server for
the name
'dbsvr.domain.net.'. [ERROR_TIMEOUT]
The name 'dbsvr.domain.net.' may not be registered in DNS.
[FATAL] Failed to fix: DC DNS entry domain.net. re-registeration on
DNS server '100.200.52.145' failed.
DNS Error code: 0x00002339
[FATAL] Failed to fix: DC DNS entry _ldap._tcp.domain.net.
re-registeration on DNS server '100.200.52.145' failed.
DNS Error code: 0x00002339
[FATAL] Failed to fix: DC DNS entry
_ldap._tcp.Default-First-Site-Name._sites.domain.net. re-registeration
on DNS server '100.200.52.145' failed.
DNS Error code: 0x00002339
[FATAL] Failed to fix: DC DNS entry
_ldap._tcp.ec198d88-e0cb-4344-8703-b17839ed5ebd.domains._msdcs.domain.net.
re-registeration on DNS server '100.200.52.145' failed.
DNS Error code: 0x00002339
[FATAL] Failed to fix: DC DNS entry
1750286d-b0a6-4633-a9d0-63967c9a5fcb._msdcs.domain.net.
re-registeration on DNS server '100.200.52.145' failed.
DNS Error code: 0x00002339
[FATAL] Failed to fix: DC DNS entry
_kerberos._tcp.dc._msdcs.domain.net. re-registeration on DNS server
'100.200.52.145' failed.

<snip>

Does anyone know what steps I can take to get me back on my feet with
regards to DNS? Just let me know if you want the output from any more
commands.

As I'm sure you can imagine, this lack of DNS is causing me all sorts
of problems with AD, so any advice you can give will be immensely
appreciated!

Thanks,

Berty

(I'm afraid I've also posted this in .sbs, as I wasn't sure which was
the best location)

.



Relevant Pages

  • Re: DHCP Clients getting DNS lookup failures
    ... It sounds to me like you had a DNS issue but you fixed it, ... The DNS server has encountered a critical error from the Active ... Check that the Active Directory is functioning properly. ... Active Directory for this zone and is unable to load the zone without ...
    (microsoft.public.windows.server.sbs)
  • Re: event 4015 and 4004 on W2K2 DC
    ... How is DNS setup, Active directory integrated zones? ... Check that you have configured the forwarders tab on all DNS server properties in the DNS management console, pointing to your ISP's DNS server and of course all clients have to know the second DNS servers ip. ... Directory for this zone and is unable to load the zone without it. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Split-Brain DNS
    ... > What do I need to do to setup split-brain DNS for the company? ... > external DNS server I have setup on our DMZ, ... Deploying and Designing Active Directory [DNS Design, Migration, Cert Auth, ... Download details Windows Server 2003 Active Directory Branch Office Guide: ...
    (microsoft.public.windows.server.dns)
  • [LONG - PLS HELP] Issues on DNS
    ... Active Directory successfully replicated using the NetBIOS ... or fully qualified computer name of the source domain controller. ... DNS Server: ... The DNS server was unable to open zone mydomain.local in the Active ...
    (microsoft.public.windows.server.dns)
  • Re: DNS Error 4011 on Active Directory-Integrated DNS
    ... Integrated DNS, and I've recently been getting the following error ... Active Directory is functioning properly and add or update this ... DOMAIN\Administrators -- Full Control ... The DNS server seems to function properly, but I'd like to fix this ...
    (microsoft.public.windows.server.dns)