Jump to content

Recommended Posts

Posted

I have 3 DC’s all Virtual servers DC1, DC and DC3.

Everything appears to be running fine apart from the odd group policy not applying to laptops.

 

DCDIAG /test:DNS on all 3 DCs are good.

Objects created on any DC replicate to the others, DNS records also replicate.

DC1 has all the FSMO roles

Netdom query fsmo confirms this.

This is also confirmed by DC1 and DC2 with Netdom query fsmo.

 

So now my problem….

I have restored DC1 to a test network to test the recovery. No problems with the recovery and DC1 started, I was able to login with the domain admin.

First thing I done was run Netdnom query fsmo which reported there was no domain.

Active directory user and computers will not start

Domains and trusts will not start

Group policy management will not start

All saying they cannot contact the domain

So if this domain controller is supposed to hold all the FSMO roles surly active directory users and computers would start. If the FSMO roles are on DC1 that is where the domain is

 

This would suggest to me all is not well in my live environment. Am I just being a plank?

Posted

Cheers

Yep DNS is on this DC1.

The network card points to itself.

I have also restored DC2 to the test environment. Still Domain cannot be contacted. DC2 also points to istself

Posted

What software are you using to backup?

 

When you say test environment can you explain a bit more?

 

You did say all 5 FSMO roles were on the server didn't you. Apart from the usual of checking event logs can't really thing of much else. You could do the same Diag checks you ran in live environment if you haven't done already.

  • Thanks 1
Posted

Cheers,

I use Veeam for backups. I've restored the DCs to a separate host on an isolated network. I've restored DC1 and DC2 and they can ping each other.

Yep all 5 FSMO roles are held by DC1. DC2 and DC3 both confirm DC1 has the roles when running netdom query fsmo in the live environment.

just going to run the dcdiag in the test enviro. Will post back in a tick

Posted

my instinct on this would still point to DNS. When you say you restored this on an isolated network, are the IP addresses the same or have they changed from your working setup?

 

Make sure DNS on your DC1 is looking for the right IP addresses for name servers etc!

  • Thanks 1
Posted

The IP addresses are the same in the live environment as they are on the recovered test DC.

The restored DC1 and DC2 in the isolated network can ping each other by ip address. didn't think to check till just now if they can ping each other via server name

 

Will let you know

Posted

started DC1 and DC2. I can start the DNS management on both servers (both have DNS role). I can ping each DC form the other by ip and domain name.

 

I added a static DNS entry to DC2. this is not replicating to the DC1

Posted

hmm....

 

What do the event logs say?

 

I assume ther global catalog is on at least one of these two restored servers?

 

It sounds a little like the FSMO roles aren't quite right. You could try transfering them to DC2 and see if that's a little happier? You can always transfer them back again if it works.

 

"Move-ADDirectoryServerOperationMasterRole -Identity “DC2″ -OperationMasterRole RIDMaster,PDCEmulator, InfrastructureMaster, SchemaMaster, DomainNamingMaster"

  • Thanks 2
Posted

 

"Move-ADDirectoryServerOperationMasterRole -Identity “DC2″ -OperationMasterRole RIDMaster,PDCEmulator, InfrastructureMaster, SchemaMaster, DomainNamingMaster"

 

Sorry off topic.

 

That's a nice command. Simple and quick rather than having to go through multiple GUI menu's

Posted

Hmmm.

 

Deleted and restored again from a different backup. Same problem.

 

I ran VMware converter and converted the live server DC1 to the same VM host I used before, same isolated network and resource pool.

Once I powered it on all was well. I could start active directory users and computers, dns, group policy etc.

I done the same with DC3. So DC1 and DC3 were happily replicating AD and DNS objects.

 

It must be something that happens during the Veeam restore process, or the settings I’m choosing ( I’m pretty much choosing the defaults)!

 

I do use Veeam’s Surebackup on the DC’s every other day so I am sure the backups are good.

 

Thanks for the replies

  • Thanks 1
Posted

That is weird - maybe post the question on the Veeam boards and see if anyone has seen this before?

 

Either way, thanks for the update and glad you got a partial solution! :)

Posted

That is weird - maybe post the question on the Veeam boards and see if anyone has seen this before?

 

Either way, thanks for the update and glad you got a partial solution! :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...