Help a non-idiot newbie! :) Domain Controller Problem
- From: Chris Mitchell <Chris Mitchell@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Sun, 26 Mar 2006 21:46:02 -0800
Hi all.. Hoping someone can help with this. I'm a .Net programmer type but
have never had to handle much of the infrastructure side of things. This has
changed recently with a home developer network.. So I'm fairly newbie on this
stuff but I do research and try to figure out as much as I can.. </disclaimer>
A friend and I have home developer networks set up that are connected via a
router-to-router 24/7 VPN tunnel. My network is 192.168.100.x where his is
192.168.0.x. We have/had a domain set up called xxxx.com. As far as I know,
the setup of the domain was done correctly; everything was working perfectly
until 2 days ago.
The following hardware exists on the domain:
My router (192.168.100.100)
BART - My Workstation (192.168.100.101) - XP Pro
XXXXDC - The PDC for the network (192.168.100.150) - 2003 Server (Standard)
XXXXSQL - SQL (192.168.100.160) - 2003 Server (Standard)
WWW - IIS (192.168.100.170) - 2003 Server (Standard)
WWW2 - IIS (192.168.100.171) - 2003 Server (Standard)
Friend's Router (192.168.0.1)
HOMER - Friend's Workstation (192.168.0.2)
XXXXBDC - BDC (192.168.0.150) - 2003 Server (Standard)
On Saturday after a reboot, I could not log in to the domain - I would
receive a message that (paraphrased) told me that the domain controller could
not be contacted. So I grabbed my laptop (which does not belong to the domain
for a variety of reasons) and terminal-serviced in to the domain controller.
It *appeared* to be fine. I didn't see any sign of any problems. Just for the
heck of it, I figured I would try rebooting in case some driver had gotten
pooched in memory.
The DC could not reboot; during the DOS boot process I got an error that
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM was corrupted or missing. I looked up the
error and found that this meant that the SYSTEM hive of the registry had
gotten trashed. I tried the various tricks I could find on MSDN to try to
restore from an old version but to no avail. So, since that machine only
performed PDC duties, I decided to reformat it and start from scratch,
figuring I could rebuild the PDC afterwards from the BDC (is there even a
PDC/BDC relationship in 2003 or do all DCs act equally?).
I can't seem to accomplish this though.. I have to be honest, I've forgotten
the exact steps that we went through when we brought the BDC online as it was
the first time that I had done it. It appeared to work though as his BDC has
a replicated copy of all the user and computer accounts for the domain in its
active directory.
The trouble is, I can't seem to get my DC back up online, nor can I get any
of my machines here back on the domain. When I try to join the domain with my
workstation (I dropped it out to the workgroup as a test before everything
went wrong, thinking a rejoin might help) I have a strange scenario when it
prompts me for a domain administrator account. I use my account (its a domain
admin acct) or the 'Administrator' account.. If I type the password wrong, I
get the correct 'nonexistant user or bad password' error message as would be
expected. However, if I type everything *RIGHT*, then it comes up and tells
me that the user name is "incorrect" and it refuses to join the domain.
When I try to take my freshly installed DC and run through the 'Add Domain
Controller Role' through 'Manage Your Server' (which, as I understand it, is
basically like running dcpromo), it again prompts me for a domain
administrator password which it then cannot seem to authenticate (I can get
exact error messages if need be). I know it is seeing the domain, however,
because if I try to let the new DC create the domain from scratch it will
come up and suggest an alternate domain name, stating that XXXX.COM is taken
(it suggests XXXX0).
As far as I know, my friend isn't having any trouble on his end, although
given the way we leave our computers running, he probably hasn't logged out
and back in since this started. I'm really curious what would happen if he
tried. My gut feeling is that he would have no issues as his authentication
is likely going through the DC that sits on his network. I am loathe to ask
him to try though, given that this could result in him being trapped outside
the domain as well.
Oh and there are no network issues between us. The VPN tunnel is alive and
well. I can ping any of the machines on his side, remote-desktop into his DC,
etc.
Any help would be massively appreciated as I am over my head here.. If
anyone wants to contact me directly, I'm hoelo @ yahoo .. Thanks much in
advance for any assistance!
.
- Prev by Date: Re: CAN WE LOGIN TO A WINDOWS 2003 ACTIVE DIRECTORY DOMAIN OVER TH
- Next by Date: Re: CAN WE LOGIN TO A WINDOWS 2003 ACTIVE DIRECTORY DOMAIN OVER TH
- Previous by thread: Bypass screensaver timeout set by global group policy?
- Next by thread: Username list & Active Directory in Windows 2000 Server
- Index(es):
Relevant Pages
|
Loading