Re: problem with AD dns auto registration and subdomain

From: Ace Fekay [MVP] (PleaseSubstituteMyActualFirstName&LastNameHere_at_hotmail.com)
Date: 10/05/04


Date: Tue, 5 Oct 2004 01:01:43 -0400

In news:b9qdnaVF1ZkYMfzcRVn-oA@giganews.com,
Paul Smith <pjsmith@microtech.coDOTgg> made a post then I commented below
> Hello,
>
> I am trying to setup 2 dc's for a child domain,
> domain1.int.mydomain.com. The problem is that some of the DC dns
> records are not getting registered. The ones like '
> 3189c2ac-f684-42ab-ae65-939df4bd34c0._msdcs.int.mydomain.com'.
>
> The current setup is this
>
> 2 2003 domain controllers in the subdomain domain1.int.mydomain.com.
> 1 DC running dns with a forward looking zone domain1.int.mydomain.com
> that allows secure dynamic updates. The 1st dc was setup on site in
> the parent domain and the DC records are all resolvable as they
> should be. The 2nd dc was setup off site at the child domain
> location. It joined the subdomain fine but there are replication
> problems because of the missing dns entries. netdiag /fix shows lots
> of entries such as
> DNS Error code: ERROR_TIMEOUT (Dns server may be down.)
> [FATAL] Failed to fix: DC DNS entry
> _ldap._tcp.RFH._sites.gc._msdcs.INT.mydomain.com. re-registeration on
> DNS server '192.168.0.1' failed.
>
> This only happens with the parent domain records. The local subdomain
> entries ending in domain1.int.mydomain.com are all ok on the
> subdomains dns server. The server 192.168.0.1 is definately up and
> running and accepting dynamic updates for the subdomain.
>
> I have the 2 dns servers of the parent domain as forwarders on my own
> child domain dc.
>
> I have tried removing and re-creating the zone on the dns server. The
> domain1.int.mydomain.com records are all recreated as they should be
> but the dc records for the parent domain are not. I do not have a
> zone for the parent domain on the subdomains dns server.
>
> Can anyone suggest what might be wrong?
>
> Thanks.

Is the whole infrastructure Win2003 or is it mixed?

What shows up in the _msdcs zone on the child?

When you created it, did you make the zone AD integrated and set it to
Forest wide replication? If so, and communication and AD replication is
working, then the zone should just pop up.

What errors are you getting in your Event viewer in relation to AD? Are
there firewalls between the locations?

-- 
Regards,
Ace
Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.
This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.
Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services
Security Is Like An Onion, It Has Layers
HAM AND EGGS: A day's work for a chicken;
A lifetime commitment for a pig.
-- 
=================================


Relevant Pages

  • Re: DNS Redesign Issue
    ... This is because tbe TLD DNS server is the only ... set the new child domain DNS server as primary for the domain controllers? ... -Using DNS console you can right-click the zone and export to a File, ...
    (microsoft.public.windows.server.dns)
  • Re: DNS Redesign Issue
    ... set the new child domain DNS server as primary for the domain controllers? ... -If you are going to create a new AD Integrated Zone in each child domain, ...
    (microsoft.public.windows.server.dns)
  • Re: Is my two domain setup correct?
    ... This is a new job and I don't wish to delete a zone then get the sack. ... The name server tab only has the DNS server in mydomin.local. ... When I log onto a DNS server in the child domain and view the forward lookup ... record for one the DNS servers from the child domain. ...
    (microsoft.public.windows.server.dns)
  • Re: Delegated zones - question for an MCSE or MCSA..
    ... After you delegate a zone to a child domain the dns servers ... parent DNS server for the child DNS server. ... 255248 How to Create a Child Domain in Active Directory and Delegate the DNS ...
    (microsoft.public.cert.exam.mcse)
  • Re: Wild cards in conditional forwarding
    ... However, you don't need wildcards. ... Setup one forward zone for each domain you want to forward - ... use the NS records for the respective dns server that is authoritive for ...
    (microsoft.public.windows.server.dns)