Re: stranger DNS zone creation error after Windows 2003 DC upgrade

Tech-Archive recommends: Speed Up your PC by fixing your registry



In news:FADF19B6-42A0-4C0A-934C-22F93B118EEF@xxxxxxxxxxxxx,
Antoine Habert <AntoineHabert@xxxxxxxxxxxxxxxxxxxxxxxxx> stated, which I
then commented on below:
> Hi all,
>
> I got a strange problem on a migration test lab :
>
> We got 1 root domain and 3 child domain (native Windows 2000)
>
> DNS zone are forwarded to a Windows 2000 DNS that serves test lab and
> production as well (integrated zones, forwarder ok)
>
> We migrated one dc of each domain to Windows 2003
> (forestprep/domainprep ok, in place upgrade)
>
> here is our problem : windows 2003 DC try to create zone from 2 of
> our child domains on themselves when we reboot the servers ! no
> problem with Windows 2000 DC. the zone failed to load and of course
> mess up our dns resolution. We got a 4001 Error in event viewer that
> tell that the current DC seek for the zone on the forestdnszone of
> the root dns.
>
> Previously, Forwarder where configured to 'any server', now they point
> directly to our windows 2000 DNS, problem still here.
>
> Does anyone got an idea on why our child domain W2K3 DC try to
> replicate zone of 2 other child domain while our zone replication is
> domainwide only?
>
> I don't have any clue about this strange behavior.
>
> thank you!

Did you upgrade the forest root DCs first? IIRC, you need to upgrade the
first DC in a forest, you need to upgrade the DC that holds the Domain Name
Master role first (which is usually the first DC that was created in the
domain).

If you upgraded a child DC first, it will create the _msdcs.domain.com zone
and set the replication scope to forest wide by placing it in the
ForestDnsZones app partition. This partition can replicate to a 2000 DC
(once forest and domain prep are done), but a Win2000 DC/DNS doesn't know
what to do with it. Also, if your current AD Integrated zone went into the
DomainDnsZones app partition (another one that Win2000 DC/DNS doesn't know
what to do wtih), and the zone on your 2000 DC/DNS stil thinks it's AD
Integrated, then we have a conflict and the zone may not load.

You will need to check using ADSI Edit to find out if there is a conflict
(or duplicate zones) in AD, specifically the DomainNC and in either of the
default app partitions.

Here;s more info on the partitions:
Application directory partitions and domain controller demotion:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/1572d8a2-622c-4879-bb0b-76e26c400129.mspx

kbAlertz (867464) - Explains how to use ADSI Edit to resolve a problem where
the DNS service logs event ID 4515 in the DNS Server log.:
http://www.kbalertz.com/kb_867464.aspx


--
Regards,
Ace

Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.

This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services
Infinite Diversities in Infinite Combinations.
=================================


.



Relevant Pages

  • Re: Forward Lookup Zone missing when new tree added to forest
    ... The problem with the DNS Forward lookup zones not ... all DNS servers in the Active Directory forest company.biz'. ... The real concern I have is that there is no forward lookup zone for ... partitions, the DomainNC (Domain Name Context, or some call the Domain ...
    (microsoft.public.windows.server.dns)
  • Re: Correct DNS Setup for Domain
    ... If it is well-connected WAN you could make the forest root ... DCs of each child domain act as secondaries, receiving zone ... Any DC that has its DNS set to forward to internet DNS servers ...
    (microsoft.public.windows.server.dns)
  • Re: Protected Forest with One Child domain
    ... The forest is in native mode. ... so your child DNS servers can resolve both their ... INTERNAL zone on every DNS server using AD-Integrated Forest ...
    (microsoft.public.windows.server.dns)
  • Re: http://support.microsoft.com/?id=255248 => GC
    ... we all speak this way) find names in the PARENT zone? ... now i have a DNS problem: ... but important Secondaries sufficient ... by definition in some domain) but rather are a FOREST ...
    (microsoft.public.win2000.dns)
  • RE: exchange server cannot mount mailbox store
    ... What's the exact detailed DNS Events ... Type desired internal IP address of your SBS server. ... it will delete the reverse lookup zone if the zone no longer ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)