Re: NT4 -> Win2K3 question
- From: v-xuwen@xxxxxxxxxxxxxxxxxxxx (Vincent Xu [MSFT])
- Date: Tue, 04 Jul 2006 05:19:02 GMT
Hi,
Check following article:
839499 You cannot open file shares or Group Policy snap-ins when you
disable SMB signing for the Workstation or Server service on a domain
controller
http://support.microsoft.com/default.aspx?scid=kb;EN-US;839499
Regarding the GC aspect, Is tempBDC still available? If it is not available
now, please choose another DC to GC ASAP.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================
--------------------
<C$oyBqlmGHA.4528@xxxxxxxxxxxxxxxxxxxxx>From: "tony@i-cable" <tony@xxxxxxxxxxxx>
References: <uqW0VocmGHA.1576@xxxxxxxxxxxxxxxxxxxx>
<#L$hx0omGHA.4992@xxxxxxxxxxxxxxxxxxxx>
<Frt4FT0mGHA.5268@xxxxxxxxxxxxxxxxxxxxx>
<#YVhoFDnGHA.2264@xxxxxxxxxxxxxxxxxxxx>
<TGLEd9knGHA.4260@xxxxxxxxxxxxxxxxxxxxx>
<OKs7R3mnGHA.3440@xxxxxxxxxxxxxxxxxxxx>
<JdOnZnnnGHA.4188@xxxxxxxxxxxxxxxxxxxxx>
microsoft.public.windows.server.migration:24300Subject: Re: NT4 -> Win2K3 question
Date: Mon, 3 Jul 2006 18:18:21 +0800
Lines: 541
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2800.1437
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441
Message-ID: <OglYEoonGHA.5056@xxxxxxxxxxxxxxxxxxxx>
Newsgroups: microsoft.public.windows.server.migration
NNTP-Posting-Host: 59.188.32.186
Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP02.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
hostsX-Tomcat-NG: microsoft.public.windows.server.migration
"not allow me logon to domain." I suspect you still unable to join the
client into domain, right?
Yes
1. Can you ping the DC by IP & Netbios & FQDN?Yes, I did ping 192.168.1.32, ping dc2 and ping dc2.int.abc.com. All work
2. Did you set the DNS settings on the client properly?Yes, all workstation get those setting from the same DHCP server which
aton DC2. I double check the DNS and WINS setting, all correct and same as
the others.
3. Check the PDC's event log, can you see any error ?Use DCDIAG -v to test, got the following error
Starting test: frsevent
* The File Replication Service Event log test
There are warning or error events within the last 24 hours after
the
SYSVOL has been shared. Failing SYSVOL replication problems may
cause
Group Policy problems.
An Warning Event occured. EventID: 0x800034C4
Time Generated: 07/01/2006 17:15:43
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x800034C4
Time Generated: 07/01/2006 18:15:42
(Event String could not be retrieved)
......................... DC2 failed test frsevent
************This error I believe I have fixed by repadmin /forestprep and
repaadmin /domainprep. Becuase after run that 2 commands, it said all
updated.
======================================================================
Starting test: kccevent
* The KCC Event log test
An Warning Event occured. EventID: 0x8000059B
Time Generated: 07/01/2006 18:11:38
Event String: The Knowledge Consistency Checker (KCC)
encountered an unexpected error while performing
an Active Directory operation.
Operation type:
KccAddEntry
Object distinguished name:
CN=bf624d1e-5126-4c28-9486-ad8806b83276,CN=NTDS
Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configur
ation,DC=int,DC=abc,DC=com
The operation will be retried at the next KCC
interval.
Additional Data
Error value:
5
0000200E: SvcErr: DSID-020C014B, problem 5001 (BUSY), data -1102
Internal ID:
f02030f
An Error Event occured. EventID: 0xC000046B
Time Generated: 07/01/2006 18:11:38
Event String: The Knowledge Consistency Checker (KCC)
encountered an error while adding a Connection
object from the following source domain
controller to the following destination domain
controller.
Source domain controller:
CN=NTDS
Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configur
ation,DC=int,DC=abc,DC=com
Destination domain controller:
CN=NTDS
Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configur
willion,DC=int,DC=abc,DC=com
Additional Data
Creation Point Internal ID:
f0a025d
......................... DC2 failed test kccevent
Starting test: systemlog
* The System Event log test
An Error Event occured. EventID: 0x40011006
Time Generated: 07/01/2006 18:13:55
Event String: The connection was aborted by the remote WINS.
Remote WINS may not be configured to replicate
with the server.
......................... DC2 failed test systemlog
********I think this related to I cannot seize Global Catalog.
==============================================================
Event ID 1655 Active Directory attempted to communicate with the following
global catalog and the attempts were unsuccessful.
Global catalog:
\\tempBDC.int.abc.com
The operation in progress might be unable to continue. Active Directory
cataloguse the domain controller locator to try to find an available global
rights.server.
Additional Data
Error value:
1722 The RPC server is unavailable.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
******I think this also related to Global Catalog issue
4. Rename the client and join into domain to see if it works.I did not try to do this one.
"Vincent Xu [MSFT]" <v-xuwen@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:JdOnZnnnGHA.4188@xxxxxxxxxxxxxxxxxxxxxxxx
Hi,
"not allow me logon to domain." I suspect you still unable to join the
client into domain, right?
Let me consider following things:
1. Can you ping the DC by IP & Netbios & FQDN?
2. Did you set the DNS settings on the client properly?
3. Check the PDC's event log, can you see any error ?
4. Rename the client and join into domain to see if it works.
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no
fill-in======================================================LMHOSTS
--------------------
<C$oyBqlmGHA.4528@xxxxxxxxxxxxxxxxxxxxx>From: "tony@i-cable" <tony@xxxxxxxxxxxx>
References: <uqW0VocmGHA.1576@xxxxxxxxxxxxxxxxxxxx>
<#L$hx0omGHA.4992@xxxxxxxxxxxxxxxxxxxx>
<Frt4FT0mGHA.5268@xxxxxxxxxxxxxxxxxxxxx>
<#YVhoFDnGHA.2264@xxxxxxxxxxxxxxxxxxxx>
<TGLEd9knGHA.4260@xxxxxxxxxxxxxxxxxxxxx>
microsoft.public.windows.server.migration:24297Subject: Re: NT4 -> Win2K3 question
Date: Mon, 3 Jul 2006 14:56:31 +0800
Lines: 323
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2800.1437
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441
Message-ID: <OKs7R3mnGHA.3440@xxxxxxxxxxxxxxxxxxxx>
Newsgroups: microsoft.public.windows.server.migration
NNTP-Posting-Host: 59.188.32.186
Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP04.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
X-Tomcat-NG: microsoft.public.windows.server.migration
For the LMHOSTS, I followed MS advise put the follow 2 lines in to
RSoP's<00><20>(1B)file and check Enable LMHOSTS Lookup on the NT workstation.
192.168.1.32 #PRE #DOM:EPO
192.168.1.32 "EPO \0x1b" #PRE
I logon locally, use nbtstat -c, it shows correctly. all <03>
records show correctly but still not allow me logon to domain.
After that, I base on http://support.microsoft.com/kb/323276 check
Resultant Set of Policy (Logging), it show Access Denied after I
denied.PC'sthat computer name.
Then I open Active Directory Users and Computers on DC2-> Select that
name-> Manage. When I click the Device Manager, it said Access
thenIt
also has a circle with cross icon at User and Group. I removed and
newsreaderadd
that computer into my DC again but still not work.
"Vincent Xu [MSFT]" <v-xuwen@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:TGLEd9knGHA.4260@xxxxxxxxxxxxxxxxxxxxxxxx
Hi Tony,
Glad to provide information. :)
Have a good day!
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your
I'mso
TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP04.phx.gblrights.that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no
======================================================
--------------------
<C$oyBqlmGHA.4528@xxxxxxxxxxxxxxxxxxxxx>From: "tony@i-cable" <tony@xxxxxxxxxxxx>
References: <uqW0VocmGHA.1576@xxxxxxxxxxxxxxxxxxxx>
<#L$hx0omGHA.4992@xxxxxxxxxxxxxxxxxxxx>
<Frt4FT0mGHA.5268@xxxxxxxxxxxxxxxxxxxxx>
Subject: Re: NT4 -> Win2K3 question
Date: Fri, 30 Jun 2006 18:39:01 +0800
Lines: 220
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2800.1437
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441
Message-ID: <#YVhoFDnGHA.2264@xxxxxxxxxxxxxxxxxxxx>
Newsgroups: microsoft.public.windows.server.migration
NNTP-Posting-Host: 59.188.32.186
Path:
microsoft.public.windows.server.migration:24281Xref: TK2MSFTNGXA01.phx.gbl
X-Tomcat-NG: microsoft.public.windows.server.migration
In the lm hosts file, I only have "192.168.1.32 #PRE #DOM:EPO".
yournot
membersure it is the reason or not because I demote all the DC back to
server and turn the backup BDC back to the normal. Thanks for
messageSat.information. Hope I can smoothly migrate to Windows 2003 in next
Thanks for your help.
"Vincent Xu [MSFT]" <v-xuwen@xxxxxxxxxxxxxxxxxxxx> wrote in
nonamenews:Frt4FT0mGHA.5268@xxxxxxxxxxxxxxxxxxxxxxxx
Hi,
After you disjoin the domain, can you ping DC1 & DC2 by netbios
check&IP?
results.Please try to ping either netbios name & IP and let mek know the
I suspect it can be a name resolution issue and I suggest you
otherthe
lmhosts file. See following article:
180094 How to write an Lmhosts file for domain validation and
Othername
resolution issues
http://support.microsoft.com/default.aspx?scid=kb;EN-US;180094
314108 How to Write an LMHOSTS File for Domain Validation and
theName
Resolution Issues
http://support.microsoft.com/default.aspx?scid=kb;EN-US;314108
BTW: I see another thread in this Migration queue and I suspect
worktwo
thread are talking about the same issue. Therefore, I'd like to
newsreaderwith
you in this thread? Let me know if I'm wrong.
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your
so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers
saidNetLogonrights.TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP03.phx.gbl
======================================================
--------------------
<C$oyBqlmGHA.4528@xxxxxxxxxxxxxxxxxxxxx>From: "tony@i-cable" <tony@xxxxxxxxxxxx>
References: <uqW0VocmGHA.1576@xxxxxxxxxxxxxxxxxxxx>
Subject: Re: NT4 -> Win2K3 question
Date: Wed, 28 Jun 2006 16:30:36 +0800
Lines: 132
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2800.1437
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441
Message-ID: <#L$hx0omGHA.4992@xxxxxxxxxxxxxxxxxxxx>
Newsgroups: microsoft.public.windows.server.migration
NNTP-Posting-Host: 59.188.32.186
Path:
microsoft.public.windows.server.migration:24263Xref: TK2MSFTNGXA01.phx.gbl
X-Tomcat-NG: microsoft.public.windows.server.migration
3. For your description: Those 6 PCs *CAN* list DC1 & DC2
or
Sysvol directory even I logon as domain Administrator. It
DC1andAccess
denied. I'm confused. Please check the symptoms you listed
let
me
know
if there are any incorrect.
Sorry, typo error. It should be "Those 6 PCs *CANNOT* list
http://support.microsoft.com/default.aspx?scid=kb;en-us;288358&
Administrator.DC2
NetLogon or Sysvol directory even I logon as domain
listedIt
said
Access denied. I'm confused. Please check the symptoms you
seeand
let
me know if there are any incorrect."
5. Try to dis-join one client out of domain and rejoin it to
dsclientmessagethe
workgroup,results.
Tried. One of the PC dis-join the domain (change to join a
cannotnamed
"WORKGROUP"), then I try to re-join the domain. But it should
find
the domain.
"Vincent Xu [MSFT]" <v-xuwen@xxxxxxxxxxxxxxxxxxxx> wrote in
news:C$oyBqlmGHA.4528@xxxxxxxxxxxxxxxxxxxxxxxx
Hi,
I have following suggestions:
1. Change the dynamic update to nosecure & secure.
2. Verify if PDC emulator is working or you can install
on
the
NT4
client.
DosaidNetLogon
3. For your description: Those 6 PCs *CAN* list DC1 & DC2
or
Sysvol directory even I logon as domain Administrator. It
andAccess
denied. I'm confused. Please check the symptoms you listed
seelet
me
know
if there are any incorrect.
4. Try: ipconfig /flushdns
ipconfig /registerdns
5. Try to dis-join one client out of domain and rejoin it to
confersthe
newsreaderresults.
thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your
so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and
no
(Windowsrights.TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP05.phx.gbl
======================================================
--------------------
From: "tony@i-cable" <tony@xxxxxxxxxxxx>
Subject: NT4 -> Win2K3 question
Date: Tue, 27 Jun 2006 17:14:12 +0800
Lines: 37
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2800.1437
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441
Message-ID: <uqW0VocmGHA.1576@xxxxxxxxxxxxxxxxxxxx>
Newsgroups: microsoft.public.windows.server.migration
NNTP-Posting-Host: 59.188.32.186
Path:
microsoft.public.windows.server.migration:24253Xref: TK2MSFTNGXA01.phx.gbl
X-Tomcat-NG: microsoft.public.windows.server.migration
I fail in my last migration due to some of the computers
NT
workstation /w SP6) fail to access Windows 2003 server.
Workstationyou
have
any
idea why? Thanks.
Background
==========
We have total 50 PCs most of them are Windows NT
TCP/IPand
the
rest
is
Windows 2000 in the network. All of them get IP and
isintegratedsetting
fromintegrated
DC1
DHCP server
We have 2 Win2003 standard edition DCs. DC1 installed DNS
with
AD and secure DDNS, WINS and DHCP. DC2 installed DNS
directorywith
AD
and
secure DDNS, WINS and printer server.
We has 6 Windows NT Workstation PCs has problem.
Symptoms
=========
1. Those 6 PCs can get IP from DC1 DHCP server.
2. Those 6 PCs can logon to the domain
3. Those 6 PCs can ping DC1 and DC2.
4. Those 6 PCs can list DC1 & DC2 NetLogon or Sysvol
even
I
logon
as domain Administrator. It said Access denied.
5. Those 6 PCs do not run the logon script. I believe it
onlybecause
those
PCs cannot access DC1/DC2 NetLogon directory
6. After change DNS integrated with AD and secure DDNS,
few
PCs
name
and IP address show in the zone under Forward Lookup Zone.
.
- References:
- Re: NT4 -> Win2K3 question
- From: Vincent Xu [MSFT]
- Re: NT4 -> Win2K3 question
- From: tony@i-cable
- Re: NT4 -> Win2K3 question
- From: Vincent Xu [MSFT]
- Re: NT4 -> Win2K3 question
- From: tony@i-cable
- Re: NT4 -> Win2K3 question
- Prev by Date: Re: How can I Seize/Transfer Global Catalog to another DC?
- Next by Date: Re: SID Hitory Not Working after ADMT 3 Migration
- Previous by thread: Re: NT4 -> Win2K3 question
- Next by thread: RE: nt4 -> server 2003 upgrade. Where are my logon scripts?
- Index(es):
Relevant Pages
|