GPO and server down errors

From: Rick (anonymous_at_discussions.microsoft.com)
Date: 09/01/04


Date: Wed, 1 Sep 2004 11:11:14 -0700

BACKGROUND:
We had an NT4 domain with one PDC and two BDCs [SP6a], we
upgraded one BDC to a Win2K3 DC with AD, DNS, WINs, &
DHCP and took the PDC offline so now we have one W2K3 DC
and one NT4 BDC.
We have made sure that the DC has all five roles,
everyone has connected to AD, and everything is still
mainly at default settings, BUT

Our three new W2K3 member servers are reporting 1030 and
1058 errors on a regular basis and the DC reports nothing
wrong with anything in the event log.
GPOTOOL reports validating DCs and 2 policies found and
are ok but it appears to be up and down because sometimes
it reports the DC list is empty and other times it states
that the DC is fine and both default policies are there???
this is the same on all W2K3 servers.
Netdiag /debug is also up and down, sometimes everything
passes with flying colors and sometimes it will report DC
list test...No DCs are up and when that happens I
immediately try \\domainname.com\sysvol\domainname.com in
the run command from the server that reported no DCs and
it connects just fine. The only error reported in Netdiag
during these down times is Cannot get information for DC
[ERROR_BAD_NETPATH].
I have verified that the existing DC is pointing to
itself for DNS and it passes all DNS testing.
My four subfolders are in place on the zone for AD.
Bypass Traverse Checking includes the Everyone group
Netlogon is set to automatic and is on,
Distributed File System service is set to automatic and
is on
Administrators and System have full control access to
GPT.INI
Q832215 lists a section of information from the
Userenv.log which also appears in our log but this KB is
for restarts and resumes and our situation is constant.
We have also tried dfsutil /PurgeMupCache with no results.
All information leading to the hotfix is close to our
situation but with differences so I don't know if we need
the hotfix or not and nothing has been said anywhere
about the DC being up and down.
Health_chk /ntfrs_errscan.log states something about
Error searching CN=T,OU=Domain
Controllers,DC=domain,DC=com for (&(objectCategory=*)
(sAMAccountName=T$)); Ldap Status: Server Down
Any help would be greastly appreciated,
thank you in advance

Rick



Relevant Pages

  • Re: Logon problems after beginning AD migration
    ... the machines that are logging into the non-2003 ... BDCs to the DNS servers in the 2003 domain, ... It was barely adequate for 2003 server, so after I had a BDC in place, I tried to transfer the FSMO roles to the BDC so I could demote and reload it. ...
    (microsoft.public.win2000.active_directory)
  • Re: Unable to authenticate users in windows 2003 SP1 secondary DC
    ... is it because my PDC hosts user folders and apps ... long as you have the domain setup to handle in accessible servers. ... domain in your forest) and that both dc's are dns servers for AD (The ... I have a PDC & BDC. ...
    (microsoft.public.windows.server.active_directory)
  • RE: BDC IP changed in DNS
    ... I suggest that you disable DNS Automatic ... talking about 2000 servers and above, PDC and BDC are for Windows NT, from ... I discovered that the IP for my BDC is incorrect. ...
    (microsoft.public.windows.server.dns)
  • Re: NT4 domain to 2003 server AD in place upgrade.
    ... And SMS 2 on a NT4 sp6a BDC. ... > of making NT host DNS since NT does not fully support DNS. ... > servers, will the se have any issues? ... the upgrade process will not infect them. ...
    (microsoft.public.windows.server.migration)
  • RE: BDC IP changed in DNS
    ... talking about 2000 servers and above, PDC and BDC are for Windows NT, from ... I discovered that the IP for my BDC is incorrect. ... Even though I have given it a static IP, DNS thinks it ...
    (microsoft.public.windows.server.dns)