Re: FQDN cannot be managed because it is not running Windows NT



In news:ECC5B913-FA0D-44F1-B4B8-F86D026A3250@xxxxxxxxxxxxx,
JCCIT <JCCIT@xxxxxxxxxxxxxxxxxxxxxxxxx> requesting assistance, typed the following:
5. The browser service is not disabled on any of the systems.
6. The DHCP Client is not disabled on any of the systems.
7. Even Logs:
JCDC01
Application
ID# 1030 Source: Userenv
ID# 1058 Source: Userenv
System
ID# 7022 source: Service Control Manager

JCDC02
Application
ID# 1005 Source: dsrestor
ID# 3013 source: Windows Search Service


Assessor07
Application
ID# 1517 Source: Userenv

Taxpc04
Application
ID# 1517 Source: Userenv
ID# 1030 Source: Userenv
ID# 1097 Source: Userenv
System
ID# 7026 Source: Service Control Manager

Thank you for posting the responses.

The JCDC02 1005 dsrestor error is due to the DSRestore service not able to update the DSRM password since you've change the domain admin account password.

The userenv errors are based on GPOs not being able to apply. Can be due to not being able to resolve SRV records, or \\jacksoncountywv.local is not resolvable. That's how the client side extensions use to resolve the domain in order to find and apply GPOs.

Is port 445 blocked? Seems like you have numerous usrenv errors, especially on the DCs. This is not good. So if you have NetBIOS disabled, fine, but you still need to allow MicrosoftSMB or things can go south, such as these errors.

And my question I guess concerning the Browser service being disabled, would be moot since NetBIOS is disabled. Browser service is based on NetBIOS.

As for the workstations that are not working, is there a record in DNS for them under the jacksoncountywv.local zone? Can you query for it using ping or nslookup? Is the firewall enabled on the machines? Is there a security policy applied on it?

You mentioned that there are multiple VLANS and I assume that this subnet these machines are on are on this VLAN and not across another bridged VLAN. However if bridged, I would look into the VLAN config.

If I think of something else, I'll let you know.

Ace

.