Re: Server 2003 add user problem

From: birdto (birdto_at_mail.hongkong.com)
Date: 10/24/04


Date: Sun, 24 Oct 2004 13:38:05 +0800

Thanks.

When I try to run "dcdiag /v" in my first DC, it shown the following error
message:-

Testing server: Default-First-Site\WCLSERVER
      Starting test: Connectivity
         * Active Directory LDAP Services Check
         The host 1a4da01a-6b3a-4dd4-9682-f1081898142d._msdcs.Wclnet.local
could not be resolved to an
         IP address. Check the DNS server, DHCP, server name, etc
         Although the Guid DNS name

         (1a4da01a-6b3a-4dd4-9682-f1081898142d._msdcs.Wclnet.local)

         couldn't be resolved, the server name

         (wclserver.Wclnet.local) resolved to the IP address

         (192.168.0.11) and was pingable. Check that the IP address is

         registered correctly with the DNS server.
         ......................... WCLSERVER failed test Connectivity

What should be the problem of it?

"Steve Duff [MVP]" <ergodic@ergodic-systems.com> ¼¶¼g©ó¶l¥ó·s»D:ewJ7fkLuEHA.1280@TK2MSFTNGP10.phx.gbl...
> What you are seeing is a symptom of something much more
> serious that is broken in Active Directory replication between
> your domain controllers. You need to fix this.
>
> It is almost impossible to give you any specifics, because there
> are so many ways for AD to break.
>
> If you look in the system and FRS event logs on both DCs you no doubt will
> see a lot of errors invoving AD and replication. Posting these would help
> us figure out where your problem could be.
>
> A few general ideas:
>
> 1) Make sure the time and time zone are set correctly and
> are in sync with each other on the two DCs.
>
> 2) Go in to AD Sites and services and make sure there
> is a functional replication path established between the two
> DCs if they are in different sites. You probably want to make
> both DCs global catalog servers, but I don't recommend that
> you make any change like that at this time as it might make
> your problem harder to figure out.
>
> 3) Run a netdiag /fix and a dcdiag /fix on both servers
> (if these are not already on your servers then you can install them
> from the \tools folder on the CD.) If a second pass of a /fix
> is not reasonably clean, then something is wrong in
> the AD configuration, and the log from these also will help figure
> out your problem.
>
> Steve Duff, MCSE, MVP
> Ergodic Systems, Inc.
>
> "birdto" <birdto@mail.hongkong.com> wrote in message
> news:eGnBi$KuEHA.3392@TK2MSFTNGP10.phx.gbl...
>> Hi All,
>>
>> I have a problem in adding a user in my AD.
>>
>> I have a single AD and have 2 DC on it. 2 of them are Windows 2003
>> Server.
>>
>> When I try to add a user in one of the DC, which should be the first DC
>> in
>> the AD, the user added cannot be shown in the next DC.
>>
>> Besides, when I try to add an user in another DC, the following message
>> shown:
>> "Windows cannot verify that the user name is unique because the
>> following
>> error occured while contacting the global catalog: The server is not
>> operational.
>> Windows will create this user account, but the user can log on only
>> after
>> the user name is verified to be unique. Make sure the global is
>> available.
>>
>>
>
>



Relevant Pages

  • Different Directory Information Trees
    ... The DCs were not able to apply group policy to themselves. ... I noticed some NTDS Replication 1955 and 1083 errors that come together. ... Weird side-effect I also noticed was that I can no longer launch the Active Directory related Management tools from my workstation unless I use the Active Directory Management MMC. ... I noticed a lot if DNS 4015 errors on the server it appears that the DNS or Active Directory is "busy". ...
    (microsoft.public.windows.server.active_directory)
  • Replication errors -BuiltinAdministrators doesnt have access ri
    ... * Connecting to directory service on server agfvads1. ... Replication Service,CN=System,DC=andrew,DC=com ... clean up this DCs ... Running partition tests on: Configuration ...
    (microsoft.public.windows.server.active_directory)
  • Re: Missing NTDS Settings object
    ... the AD database on ALL the DCs within that domain ... That's when the replication broke and the ISTG settings in the NTDS Site ... NO server for that domain appears in ANY site, ... and services on one of the domain controllers in that domain - then they show ...
    (microsoft.public.windows.server.active_directory)
  • Re: Replication Problem
    ... You could try resetting the secure channel with the DCs in the other site. ... We have setup the iner-site replication topology in Sites and Services snap-in and everything works fine. ... About two mounth ago on of the servers has been shout-down, that server was the bridge-head server in it site. ... I hope this will resync the computer account passwords and the replication will restart to work * Demote the bridge-head server in the problematic site, remove any leftover objects in the domain and promote the DC again. ...
    (microsoft.public.win2000.active_directory)
  • Re: SYSVOL GPOs re:copying
    ... If you create a test user account on each DC, does it successfully replicate to each of the other DCs? ... Stop FRS on each of the new DCs. ... open a command prompt and change directory into the GPMC scripts folder. ... The effort and/or risk in fixing this server seems to exceed the ...
    (microsoft.public.win2000.active_directory)