Re: Unable to create domain trust: a device not functioning
- From: Joshua Perry <JoshuaPerry@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Fri, 21 Jul 2006 11:02:02 -0700
I have all of the NTDS logging turned up and the only entries I get that may
be bad are some info entries that say problem 2001 (NO_OBJECT) for a number
of objects:
DC=ferraricolor.com,CN=MicrosoftDNS,DC=DomainDnsZones,DC=ferraricolor,DC=com
CN=409,CN=DisplaySpecifiers,CN=Configuration,DC=ferraricolor,DC=com
CN=Dfs-Configuration,CN=System,DC=ferraricolor,DC=com
These errors happen randomly and not in response to running the trust setup.
The repadmin command you gave me showed the last attempted replication
failed to the removed DC, but the date of the last attempt was the day that
we demoted it. And repadmin does not show any replication partners either.
All of the other commands including dcdiag show no failures. I also turned
up NTDS logging on the target domain and do not get any errors their either.
Here is the output to netdom command to setup the trust:
--------------------------------------------------------------------------------------------
Establishing a session with \\SAC-DC-01.ferraricolor.net
Reading LSA domain policy information
Establishing a session with \\digitaldata2.ferraricolor.com
Reading LSA domain policy information
To improve the security of this external trust, security identifier (SID)
filtering is enabled. However, if users have been migrated to the trusted
domain and their SID histories have been preserved, you may choose to turn
off this feature.
For more information about SID filtering and how to turn it off, see the help
for netdom trust /FilterSids or see Help and Support.
Deleting the session with \\digitaldata2.ferraricolor.com
Deleting the session with \\SAC-DC-01.ferraricolor.net
A device attached to the system is not functioning.
The command failed to complete successfully.
--------------------------------------------------------------------------------------------
Josh
"Paul Bergson" wrote:
No errors in the event logs?.
netdiag.exe /v (network diagnostics)
repadmin.exe /showrepl dc* /verbose /all /intersite
(replication testing)
From your dc try running dnslint /ad /s "ip address of your dc"
/v (dns testing)
I don't know if any of these will help but it should dive you plenty more
details
--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com
Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
- References:
- Re: Unable to create domain trust: a device not functioning
- From: Paul Bergson
- Re: Unable to create domain trust: a device not functioning
- Prev by Date: Re: Active Directory Security permissions
- Next by Date: Re: Default tombstone lifetime
- Previous by thread: Re: Unable to create domain trust: a device not functioning
- Next by thread: Re: Unable to create domain trust: a device not functioning
- Index(es):
Relevant Pages
|