Re: No logon server available - Windows 2003 Trust Issue? NS Issue?



More info -

Following error popped up a few times in Domain A -

<error>

This computer was not able to set up a secure session with a domain
controller in domain (Domain B) due to the following:
The remote procedure call failed and did not execute.
This may lead to authentication problems. Make sure that this computer
is connected to the network. If the problem persists, please contact
your domain administrator.

ADDITIONAL INFO
If this computer is a domain controller for the specified domain, it
sets up the secure session to the primary domain controller emulator in
the specified domain. Otherwise, this computer sets up the secure
session to any domain controller in the specified domain.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

</error>



newsgroups.jd@xxxxxxxxx wrote:
Michael,

Thank you for the response, getting another set of eyes before I call
MS is always helpful. I had already verifed the LMHOST lookup was
enabled, but double checked again and it was. Here is the result from
the nbtstat on both DCs


Local Area Connection:
Node IpAddress: [x.x.156.151] Scope Id: [] - DOMAIN A

NetBIOS Remote Cache Name Table


Name Type Host Address Life [sec]
------------------------------------------------------------
Domain B DC <03> UNIQUE x.x.6.67 -1
Domain B DC <00> UNIQUE x.x.6.67 -1
Domain B DC <20> UNIQUE x.x.6.67 -1
Domain B <1C> GROUP x.x.6.67 -1
Domain B.... <03> UNIQUE x.x.6.67 -1
Domain B.... <00> UNIQUE x.x.6.67 -1
Domain B.... <20> UNIQUE x.x.6.67 -1


Local Area Connection 2:
Node IpAddress: [x.x.6.67] Scope Id: [] - DOMAIN B

NetBIOS Remote Cache Name Table

Name Type Host Address Life [sec]
------------------------------------------------------------
DOMAIN A <1C> GROUP x.x.156.151 -1
DOMAIN A... <03> UNIQUE x.x.156.151 -1
DOMAIN A... <00> UNIQUE x.x.156.151 -1
DOMAIN A... <20> UNIQUE x.x.156.151 -1
Domain A DC <03> UNIQUE x.x.156.151 -1
Domain A DC <00> UNIQUE x.x.156.151 -1
Domain A DC <20> UNIQUE x.x.156.151 -1


As for secondary domain - are you refering to a secondary DNS zone? I
had never heard it refered to as a secondary domain? but again - the
name resolution seems to be functioning, which is why I am baffled....

JD

Michael Giorgio - MS MVP wrote:
Try adding them as secondary domains and see if this resolves
your issue.. W2k or higher uses DNS for this type of connectivity.
NetBIOS which use WINS or lmhosts is necessary in NT 4.0.

Well to be sure your lmhosts are configured properly you have to
make sure the adapters are configured for NetBIOS and lmhosts
lookup. Open a dos prompt on each machine and run nbtstat -c
and post the results. You can mask the names and tcp/ip addresses.

<newsgroups.jd@xxxxxxxxx> wrote in message news:
For DNS - I actually created a conditional forwarder on each domain -
which also seems to be working fine -

From each domain I am able to ping or at least resolve names on each
side with either FQDNs or with netbios names....

I did this before...

So still getting the error :(

JD



Michael Giorgio - MS MVP wrote:
Since these are W2k3 domains you should be able to use DNS
to get them communicating properly. Add the remote DNS servers
as secondary DNS servers on each W2k3 DC.
<newsgroups.jd@xxxxxxxxx> wrote in message news:
THanks for any input ahead of time...

I have 2 - Windows 2003 R2 Domains with a two way trust set up.

Domain A

Windows Firewall - turned off
LMHOST Entries

DC IP x.x.x.x DCHostName #PRE #DOM: "DomainBName
DC IP x.x.x.x "DomainBNAME \0x1b" #PRE


Domain B

Windows Firewall - turned off
LMHOST Entries

DC IP x.x.x.x DCHostName #PRE #DOM: "DomainAName
DC IP x.x.x.x "DomainANAME \0x1b" #PRE


Trust created fine

Domain A tries to access shared folder on Domain B - I get auth box
- which is good. Once I assign NTFS and Share permissions, that will
go away.


Domain B tries to access shared folder on Domain A - I get following

<error>

\\dcname\test is not accessible. You might not have permission to use
this network
resource. Contact the administrator of this server to find out if you
have access
permissions.

There are currently no logon servers available to service this logon
request.

</error>

I have read alot of Q articles and alot of post regarding this error,
and it mostly relates to name resolution. I have verified my entries
on both domain controllers. I can ping back and forth using wins name.
I have added DC entries in WINS just to make sure... shouldn't have
to if they are in lmhost.

I have run nslookup on both servers to verify what it sees as the name
server for each domain.

I cant see to figure out what is going on - I ran a sniff on the port
for DC B while trying to access DC A and do not see anything out of the
ordinary...

Any thoughts?



.



Relevant Pages

  • Re: No logon server available - Windows 2003 Trust Issue? NS Issue?
    ... NetBIOS Remote Cache Name Table ... NetBIOS which use WINS or lmhosts is necessary in NT 4.0. ... as secondary DNS servers on each W2k3 DC. ... Domain B tries to access shared folder on Domain A - I get following ...
    (microsoft.public.windows.server.networking)
  • RE: Strange Irregular DNS/Networking Problems
    ... Never heard about this kind of problem with IPv6, but think this is because it is not used so much until now. ... What i heard is that firefox or some other not MS browsers and addons make problems with DNS resolving after changing DNS servers. ... After resetting the domain controller and booting up things are back ...
    (microsoft.public.windows.server.dns)
  • Re: Replication Issues with A/D
    ... site link BRIDGING is that is connecting the spokes together and because ... Site A's subnet can talk with ALL subnets in our network ... the first problem I have is that Site D's domain controller (it ... "All servers in that can replicate partition ...
    (microsoft.public.windows.server.active_directory)
  • Re: machine account password replication not working
    ... This is checking FRS replication. ... > Install the Support Tools on each Domain Controller and on each Member ... Run netdiag /v on all servers. ... The member servers reported access denied ...
    (microsoft.public.win2000.active_directory)
  • Re: Help attempting to get hacked?
    ... I am experiancing similar issues with Win98 Clients ... >indicate that you are also using a W2K rras vpn? ... If your rras servers are all W2K, ... >domain controller. ...
    (microsoft.public.win2000.security)