Re: Windows 2003 Help



Hello Thomas,

Do NEVER stop DNS service on the domain. Reconfigure the DC's as also posted in DNS NG:

DC1:
ip address 192.168.69.10
subnet mask 255.255.255.0
defatul gw 192.168.10.1
pref DNS 192.168.69.10
sec DNS 192.168.69.15

DC2:
ip address 192.168.69.15
subnet mask 255.255.255.0
defatul gw 192.168.10.1
pref DNS 192.168.69.15
sec DNS 192.168.69.10

In the private ip range i would not enable the firewall between the DC's. You can also post "netdiag" only. But make first sure to reconfigure DNS and restart the new DC.

For DNS use AD integrated zones if not done.
And please try to stick to one posting and do not post that much different one's all belonging to the same problem.

You should think about using a newsreader where you can use crossposting and have all answers readable for anybody.
http://www.blakjak.demon.co.uk/mul_crss.htm


Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Update 2

Well turned on the firewall on the old dc and guess what

It is NOT working so it is something in the firewall

I have the following ports setup as exceptions in Windows Firewall

53211 TCP
53212 TCP
53213 TCP
135 TCP
53 TCP and UDP
139 TCP
445 TCP
137 UDP
138 UDP
42 TCP
42 UDP
593 TCP
80 TCP
88 TCP
88 UDP
464 TCP
464 UDP
636 TCP
636 UDP
3268 TCP
3269 TCP
123 UDP
3389 TCP
25 TCP
25 UDP
37 TCP
37 UDP
1433 TCP
I reviewed KB319553 KB555381 and KB224196 also KB832017

Any ideas

Thanks
Tom
"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news:ff16fb661bdc78cb6cca970a23cb@xxxxxxxxxxxxxxxxxxxxxxx

Hello Thomas,

You get the errors on the old DC when running the commands dcdiag and
netdiag?

What's with repadmin /showrepl command output?

Some reg changes requires a reboot, normally mentioned in the
article.

So is there a firewall between the DCs', you didn't answer this?

You can post the outputs here. You use private ip ranges, hopefully,
10.x.x.x, 172.x.x.x or 192.168.x.x? For your domain/server names you
can change them.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Meinolf

I am logging in as domain administrator

i reveiewed KB555381 made firewall changes
Also modified the registry on both servers.
I ran dcdiag and netdiag on my first dc
Still getting There are no more endpoints available from the
endpoint mapper.

Do you think I should restart the server after the changes to the
registry?

Can I send you a copy of the dcdiag and netdiag?

Thanks

Tom

"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news:ff16fb661bda38cb6cbbd6a42cbb@xxxxxxxxxxxxxxxxxxxxxxx

Hello Thomas,

What account are you using for the command?

If you have 2 DC's make sure they replicate correct, use repadmin
/showrepl or replmon form the run line(GUI version). On the DC's
run dcdiag /v and netdiag /v to check for errors.

You talk about firewall, are they used between the DC's? Check this
one
for needed open ports:
http://support.microsoft.com/kb/555381
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties,
and
confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Just added second Domain controller on my network
I have 2 Windows 2003 R2 Standard DC server Sp2
Both run DNS
I am getting this message on the new DC when I issue this command
netdom query fsmo
There are no more endpoints available from the endpoint mapper.
Just went thru all firewall settings and not sure why this is not
working
Any ideas or suggestions
Thanks

Tom



.



Relevant Pages

  • Re: SMTP delivery failure when NIC DNS server points to router
    ... I learned that the router's DNS server does not listen to TCP queries. ... Configure the SMTPSVC to use UDP for DNS queries. ...
    (microsoft.public.inetserver.iis.smtp_nntp)
  • SMTP Outgoing - Connection Dropped
    ... Searching for Exchange external DNS settings. ... Checking TCP/UDP SOA serial number using DNS server. ... TCP test failed. ... UDP test succeeded. ...
    (microsoft.public.windows.server.sbs)
  • Re: Definitive iptables configuration for DNS cache?
    ... > cannot get any other hosts to connect when the firewall is running. ... DNS is a little different than other ... UDP for queries, not TCP. ... if the reply to the query is too large for a single UDP packet. ...
    (comp.os.linux.security)
  • Re: Exchange TCP/IP ports
    ... 389 LDAP to GC/DC - TCP/UDP ... 53 DNS to DC - TCP/UDP ... DNS can sometimes use TCP even though most queries are UDP make sure you ...
    (microsoft.public.exchange.admin)
  • Re: new server 2003 slow login NOT a DNS problem
    ... If i see your DNS server ip's their is a mismatch with your current subnet ... UDP:138 ... TCP:445 ...
    (microsoft.public.windows.server.general)