Re: FSMO roles



Hello pepps,

I see in your config that you point with DNS to 127.0.0.1 In your config with 2 dc's in one domain that's not the best solution. I would change it to the real ip of the server itself for the primary dns and the ip address from the other dc to the secondary dns. I assume that also the new one is DNS server because you talk about having the first one off a long time. Also you should make dns active directory integrated. If both dc's know each other with theire fixed ip's, then your error about Cannot contact dc2 should disappear.
And don't forget to run dcdiag after it also, not only netdiag.

Best regards

Myweb
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.

right i chanced it and did it anyway

this is netdiag from dc1 which was the secound installed dc

Computer Name: DC1
DNS Host Name: dc1.linkmicrotek.com
System info : Windows 2000 Server (Build 3790)
Processor : x86 Family 6 Model 7 Stepping 3, GenuineIntel
List of installed hotfixes :
KB819696
KB823182
KB823353
KB823559
KB824105
KB825119
KB828035
KB828741
KB833987
KB835732
KB837001
KB839643
KB839645
KB840315
KB840374
KB840987
KB841356
KB841533
KB842773
KB867282
KB867460
KB871250
KB873333
KB873376
KB883939
KB885250
KB885834
KB885835
KB885836
KB886903
KB888113
KB890046
KB890047
KB890175
KB890859
KB890923
KB891711
KB891781
KB893066
KB893086
KB893756
KB893803
KB893803v2
KB896358
KB896422
KB896423
KB896424
KB896426
KB896428
KB896688
KB896727
KB897715
KB899587
KB899588
KB899589
KB899591
KB900725
KB901017
KB901214
KB902400
KB903235
KB904706
KB905414
KB905495
KB905915
KB908519
KB908531
KB910437
KB911280
KB911562
KB911564
KB911565
KB911567
KB911897
KB911927
KB912812
KB912919
KB913446
KB913580
KB914388
KB914389
KB914798
KB916281
KB917159
KB917344
KB917422
KB917734_WMP9
KB917953
KB918118
KB918439
KB918899
KB920213
KB920670
KB920683
KB920685
KB921398
KB921883
KB922616
KB922760
KB922819
KB923191
KB923414
KB923689
KB923694
KB923980
KB924191
KB924496
KB924667
KB925398_WMP64
KB925454
KB925486
KB925902
KB926255
KB926436
KB927779
KB928090
KB928255
KB928843
KB929969
KB930178
KB931784
KB931836
KB932168
Q147222
Q828026
Netcard queries test . . . . . . . : Passed

Per interface results:

Adapter : Local Area Connection

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : dc1
IP Address . . . . . . . . : 10.0.0.4
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 10.0.0.124
Dns Servers. . . . . . . . : 127.0.0.1
AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03>
'Messenger Service', <20> 'WINS' names is missing.
No remote names have been found.
WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.
Global results:

Domain membership test . . . . . . : Passed

NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{C7D8FE86-753E-49B0-AA9C-54B074EAE1F3}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed

IP loopback ping test. . . . . . . : Passed

Default gateway test . . . . . . . : Passed

NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00>
'WorkStation
Service', <03> 'Messenger Service', <20> 'WINS' names defined.
Winsock test . . . . . . . . . . . : Passed

DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server
'127.0.0.1' and other DCs also have some of the names registered.
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{C7D8FE86-753E-49B0-AA9C-54B074EAE1F3}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{C7D8FE86-753E-49B0-AA9C-54B074EAE1F3}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed

DC list test . . . . . . . . . . . : Passed

Trust relationship test. . . . . . : Skipped

Kerberos test. . . . . . . . . . . : Passed

LDAP test. . . . . . . . . . . . . : Passed

Bindings test. . . . . . . . . . . : Passed

WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

Note: run "netsh ipsec dynamic show /?" for more detailed
information

The command completed successfully

This is the netdiag result from dc2

Computer Name: LINKSERVER
DNS Host Name: linkserver.linkmicrotek.com
System info : Windows 2000 Server (Build 2195)
Processor : x86 Family 6 Model 8 Stepping 6, GenuineIntel
List of installed hotfixes :
KB819696
KB823182
KB823559
KB824105
KB824141
KB824146
KB825119
KB826232
KB828028
KB828035
KB828749
KB837001
KB839643
KB839645
KB840315
KB841872
KB841873
KB842526
KB867282-IE6SP1-20050127.163319
KB891781
Q147222
Q816093
Netcard queries test . . . . . . . : Passed

Per interface results:

Adapter : Local Area Connection

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : linkserver
IP Address . . . . . . . . : 10.0.0.1
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 10.0.0.124
Dns Servers. . . . . . . . : 127.0.0.1
AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed
No remote names have been found.
WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.
Global results:

Domain membership test . . . . . . : Passed

NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{10BDA2F9-443D-4A4A-A3A7-9702E0EC51CD}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed

IP loopback ping test. . . . . . . : Passed

Default gateway test . . . . . . . : Passed

NetBT name test. . . . . . . . . . : Passed

Winsock test . . . . . . . . . . . : Passed

DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server
'127.0.0.1' and other DCs also have some of the names registered.
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{10BDA2F9-443D-4A4A-A3A7-9702E0EC51CD}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{10BDA2F9-443D-4A4A-A3A7-9702E0EC51CD}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed

DC list test . . . . . . . . . . . : Passed

Trust relationship test. . . . . . : Failed
[FATAL] Secure channel to domain 'LINKMICROTEK' is broken.
[ERROR_NO_LOGON_SERVERS]
Kerberos test. . . . . . . . . . . : Passed

LDAP test. . . . . . . . . . . . . : Passed
[WARNING] Failed to query SPN registration on DC
'dc1.linkmicrotek.com'.
Bindings test. . . . . . . . . . . : Passed

WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Passed
IPSec policy service is active, but test failed to get current
policy
information.
The command completed successfully

THis is dcdiag from dc2(linkserver)

Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.
Doing initial required tests

Testing server: Default-First-Site-Name\LINKSERVER
Starting test: Connectivity
......................... LINKSERVER passed test Connectivity
Doing primary tests

Testing server: Default-First-Site-Name\LINKSERVER
Starting test: Replications
......................... LINKSERVER passed test Replications
Starting test: NCSecDesc
......................... LINKSERVER passed test NCSecDesc
Starting test: NetLogons
......................... LINKSERVER passed test NetLogons
Starting test: Advertising
......................... LINKSERVER passed test Advertising
Starting test: KnowsOfRoleHolders
......................... LINKSERVER passed test
KnowsOfRoleHolders
Starting test: RidManager
......................... LINKSERVER passed test RidManager
Starting test: MachineAccount
......................... LINKSERVER passed test
MachineAccount
Starting test: Services
......................... LINKSERVER passed test Services
Starting test: ObjectsReplicated
......................... LINKSERVER passed test
ObjectsReplicated
Starting test: frssysvol
......................... LINKSERVER passed test frssysvol
Starting test: kccevent
......................... LINKSERVER passed test kccevent
Starting test: systemlog
An Error Event occured. EventID: 0x00000457
Time Generated: 03/04/2003 09:32:33
Event String: Driver Acrobat PDFWriter required for
printer
An Error Event occured. EventID: 0x00000451
Time Generated: 03/04/2003 09:32:33
Event String: Printer security information for the printer
An Error Event occured. EventID: 0x00000452
Time Generated: 03/04/2003 09:32:33
Event String: The printer could not be installed.
An Error Event occured. EventID: 0x00000457
Time Generated: 03/04/2003 09:32:34
Event String: Driver Epson Stylus COLOR 760 ESC/P 2
required
An Error Event occured. EventID: 0x00000451
Time Generated: 03/04/2003 09:32:34
Event String: Printer security information for the printer
An Error Event occured. EventID: 0x00000452
Time Generated: 03/04/2003 09:32:34
Event String: The printer could not be installed.
An Error Event occured. EventID: 0x00000457
Time Generated: 03/04/2003 09:32:35
Event String: Driver hp deskjet 940c required for printer
An Error Event occured. EventID: 0x00000451
Time Generated: 03/04/2003 09:32:35
Event String: Printer security information for the printer
An Error Event occured. EventID: 0x00000452
Time Generated: 03/04/2003 09:32:35
Event String: The printer could not be installed.
An Error Event occured. EventID: 0x8000003E
Time Generated: 03/04/2003 09:36:48
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 03/04/2003 10:16:40
Event String: Driver Acrobat PDFWriter required for
printer
An Error Event occured. EventID: 0x00000451
Time Generated: 03/04/2003 10:16:40
Event String: Printer security information for the printer
An Error Event occured. EventID: 0x00000452
Time Generated: 03/04/2003 10:16:40
Event String: The printer could not be installed.
An Error Event occured. EventID: 0x00000457
Time Generated: 03/04/2003 10:16:41
Event String: Driver Epson Stylus COLOR 760 ESC/P 2
required
An Error Event occured. EventID: 0x00000451
Time Generated: 03/04/2003 10:16:41
Event String: Printer security information for the printer
An Error Event occured. EventID: 0x00000452
Time Generated: 03/04/2003 10:16:41
Event String: The printer could not be installed.
An Error Event occured. EventID: 0x00000457
Time Generated: 03/04/2003 10:16:41
Event String: Driver hp deskjet 940c required for printer
An Error Event occured. EventID: 0x00000451
Time Generated: 03/04/2003 10:16:41
Event String: Printer security information for the printer
An Error Event occured. EventID: 0x00000452
Time Generated: 03/04/2003 10:16:41
Event String: The printer could not be installed.
......................... LINKSERVER failed test systemlog
Running enterprise tests on : linkmicrotek.com
Starting test: Intersite
......................... linkmicrotek.com passed test
Intersite
Starting test: FsmoCheck
......................... linkmicrotek.com passed test
FsmoCheck
interestingly enough i cannot seem to find the output file for the
dcdiag on dc1 and also DC2 cannot seem to resolve server names, also
nothing is showing in event viewer and i cannot access the DNS
management on it

hope this sheds some light

"Myweb" wrote:

Hello pepps,

For the long time problem check out this one:
http://technet2.microsoft.com/windowsserver/en/library/34c15446-b47f-
4d51-8e4a-c14527060f901033.mspx
dcdiag and netdiag you will find on the installation cd under
support\tools either on 2000 or 2003

Best time for this work i think is after the users go home, so you
don't disturb each other.

Best regards

Myweb
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
Hi thanks for the quick reply, the server has been disconected for a
few
months now
first problem how do install and use dcdiag, can i run it on both
the
2000
and 2003 server, and also when i plug the win2k one back in to run
the
tool
some of my pop users will not be able to login but that should not
matter to
much should it?
thanks again
"Myweb" wrote:

Hello pepps,

Before removing it, i would try to fix the problem. Check your DNS
configuration for both servers, run dcdiag and netdiag on both
dc's. Post the result here and also post an ipconfig /all from both
dc's. How many days have you disconnected the server?

Best regards

Myweb
Disclaimer: This posting is provided "AS IS" with no warranties,
and
confers
no rights.
Please help

I have a small domain where i have two domain controllers running
DC1= Win 2003
dc2= Win 2000 (First dc ever installed) , on checking the FSMO
roles
of the
dc's i noticed that dc1 holds all roles except for Schema Master
and
Domain
naming, when trying to transfer the two roles to dc 1 i get an
error
message
stating that it cannot contact the server, DC2 which is the first
dc
Installed has been offline for a while, until today when i put it
back
on the
network to try and transger the two existing roles, i also noticed
that while
that one was back on line some of our remote users were being
asked
login
details to collect there pop email, as soon as i took it of the
network again
all was ok,
I need to completly remove this from the network and rebuild it i
know
i can seize the two roles if need be but have read to do this as a
last resort.
Also i am worrired that if i do this no users will be able to
login
at all.
Any help as to why this is happening will be greatly Appreciated.

Thanks

John



.



Relevant Pages

  • Re: Cannot replicate AD integrated DNS on third Domain Controller
    ... Did you then clenaup DNS witht he old records and check after that that replication has occured and removes all old entries about this machine BEFORE starting the new install? ... I've configured all three DC as Gobal Catalog server. ... EventID: 0xC00038C2 ... (Event String could not be retrieved) ...
    (microsoft.public.windows.server.active_directory)
  • Cannot replicate AD integrated DNS on third Domain Controller
    ... I am having trouble to setup AD integrated DNS on the 3rd Domain Controller. ... I've configured all three DC as Gobal Catalog server. ... EventID: 0xC00038C2 ... (Event String could not be retrieved) ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS stops responding
    ... DNS domain name i DHCP options is inko and DNS is 192.168.1.100 ... EventID: 0x00000457 ... (Event String could not be retrieved) ... Starting test: CrossRefValidation ...
    (microsoft.public.windows.server.dns)
  • Re: FSMO roles
    ... PASS - All the DNS entries for DC are registered on DNS server ... EventID: 0x00000457 ... Event String: Driver Acrobat PDFWriter required for printer ... dcdiag and netdiag you will find on the installation cd under support\tools ...
    (microsoft.public.windows.server.active_directory)
  • Re: SA hungs on starting state (re post)
    ... Event String: NTDS Synchronous read page checksum error ... restore the databases from a previous backup. ... EventID: 0xC000043C ... A full synchronization is in progress ...
    (microsoft.public.exchange2000.admin)

Loading