ozydave Posted March 8, 2017 Posted March 8, 2017 I have 3 DC’s all Virtual servers DC1, DC and DC3. Everything appears to be running fine apart from the odd group policy not applying to laptops. DCDIAG /test:DNS on all 3 DCs are good. Objects created on any DC replicate to the others, DNS records also replicate. DC1 has all the FSMO roles Netdom query fsmo confirms this. This is also confirmed by DC1 and DC2 with Netdom query fsmo. So now my problem…. I have restored DC1 to a test network to test the recovery. No problems with the recovery and DC1 started, I was able to login with the domain admin. First thing I done was run Netdnom query fsmo which reported there was no domain. Active directory user and computers will not start Domains and trusts will not start Group policy management will not start All saying they cannot contact the domain So if this domain controller is supposed to hold all the FSMO roles surly active directory users and computers would start. If the FSMO roles are on DC1 that is where the domain is This would suggest to me all is not well in my live environment. Am I just being a plank?
Davit2005 Posted March 8, 2017 Posted March 8, 2017 (edited) What DNS does the DC1 point to in it's network settings. Is DNS also on this server?? Edited March 8, 2017 by Davit2005 1
ozydave Posted March 8, 2017 Author Posted March 8, 2017 Cheers Yep DNS is on this DC1. The network card points to itself. I have also restored DC2 to the test environment. Still Domain cannot be contacted. DC2 also points to istself
Davit2005 Posted March 8, 2017 Posted March 8, 2017 What software are you using to backup? When you say test environment can you explain a bit more? You did say all 5 FSMO roles were on the server didn't you. Apart from the usual of checking event logs can't really thing of much else. You could do the same Diag checks you ran in live environment if you haven't done already. 1
ozydave Posted March 8, 2017 Author Posted March 8, 2017 Cheers, I use Veeam for backups. I've restored the DCs to a separate host on an isolated network. I've restored DC1 and DC2 and they can ping each other. Yep all 5 FSMO roles are held by DC1. DC2 and DC3 both confirm DC1 has the roles when running netdom query fsmo in the live environment. just going to run the dcdiag in the test enviro. Will post back in a tick
ozydave Posted March 8, 2017 Author Posted March 8, 2017 just run dcdiag. Amongst the output is the primary domain controller could not be contacted.
mtillbrook Posted March 8, 2017 Posted March 8, 2017 my instinct on this would still point to DNS. When you say you restored this on an isolated network, are the IP addresses the same or have they changed from your working setup? Make sure DNS on your DC1 is looking for the right IP addresses for name servers etc! 1
ozydave Posted March 8, 2017 Author Posted March 8, 2017 The IP addresses are the same in the live environment as they are on the recovered test DC. The restored DC1 and DC2 in the isolated network can ping each other by ip address. didn't think to check till just now if they can ping each other via server name Will let you know
ozydave Posted March 8, 2017 Author Posted March 8, 2017 started DC1 and DC2. I can start the DNS management on both servers (both have DNS role). I can ping each DC form the other by ip and domain name. I added a static DNS entry to DC2. this is not replicating to the DC1
mtillbrook Posted March 8, 2017 Posted March 8, 2017 hmm.... What do the event logs say? I assume ther global catalog is on at least one of these two restored servers? It sounds a little like the FSMO roles aren't quite right. You could try transfering them to DC2 and see if that's a little happier? You can always transfer them back again if it works. "Move-ADDirectoryServerOperationMasterRole -Identity “DC2″ -OperationMasterRole RIDMaster,PDCEmulator, InfrastructureMaster, SchemaMaster, DomainNamingMaster" 2
ozydave Posted March 8, 2017 Author Posted March 8, 2017 Cheers, I'll move the roles tomorrow, run backups and restore to test again.
Davit2005 Posted March 9, 2017 Posted March 9, 2017 "Move-ADDirectoryServerOperationMasterRole -Identity “DC2″ -OperationMasterRole RIDMaster,PDCEmulator, InfrastructureMaster, SchemaMaster, DomainNamingMaster" Sorry off topic. That's a nice command. Simple and quick rather than having to go through multiple GUI menu's
ozydave Posted March 9, 2017 Author Posted March 9, 2017 Hmmm. Deleted and restored again from a different backup. Same problem. I ran VMware converter and converted the live server DC1 to the same VM host I used before, same isolated network and resource pool. Once I powered it on all was well. I could start active directory users and computers, dns, group policy etc. I done the same with DC3. So DC1 and DC3 were happily replicating AD and DNS objects. It must be something that happens during the Veeam restore process, or the settings I’m choosing ( I’m pretty much choosing the defaults)! I do use Veeam’s Surebackup on the DC’s every other day so I am sure the backups are good. Thanks for the replies 1
mtillbrook Posted March 10, 2017 Posted March 10, 2017 That is weird - maybe post the question on the Veeam boards and see if anyone has seen this before? Either way, thanks for the update and glad you got a partial solution!
mtillbrook Posted March 10, 2017 Posted March 10, 2017 That is weird - maybe post the question on the Veeam boards and see if anyone has seen this before? Either way, thanks for the update and glad you got a partial solution!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now