Jump to content

Recommended Posts

Posted (edited)

Hi Chaps,

 

Ok, so I have an issue where by when I demote my last 2012 R2 DC it complains that it’s the last DNS server hosting the Zone as it is unable to contact any other DC despite seeing them.

 

The new 2016 DC has an IP that has never been used before, has all the FSMO roles, DHCP services look to work fine according to the Event logs, Best practices and DNS look fine according to dcdiag.exe /test:dns and FSMO checks out fine too.

 

Below is the error it comes up with. I have already proceeded with it yesterday and it does in fact remove the entire DNS Zone, which is not helpful. That goodness for Checkpoints and Virtualisation.

 

 

DNS1.PNG

 

DNS2.PNG

 

DNS3.PNG

 

Please help.... I did this on my SVR-DC-02 yesterday and it said the same. Today I demoted the SVR-DC-02 with no issues but the SVR-DC-01 now say the message despite yesterday being ok, so it looks like an actual issue. Maybe I need to do somthing I dont know about?

 

Also in AD SS it has a DNS Settings file which seems odd...

 

DNS4.PNG

 

@Oaktech and @FN-GM any ideas?

Edited by Dan_ATR
Added in people.
Posted
Looks like even my DFS File server cant find the name space even though I can browse it via a file explorer. So, restore original DC1 and DC2 again... back to Tuesday morning again.... This is doing my wick in.... It would have been faster to recreate my domain from scratch and import evening in....
Posted

Sorry about the delay, I am holidaying in Australia at the moment.

 

On your new and old DC's run this in the command line and post up the results please?

 

NetDOM /query FSMO

 

- - - Updated - - -

 

Also on the DNS zone that is removes can you right click and hit properties and screenshot the settings on the tabs please?

Posted (edited)

Do you know if you are replicating the sysvol/ netlogon shares via FRS or DFSR? If it's via DFS can you check on the original DC(s) for event 2213 in the DFS replication logs(if it's FRS then the 2016 DC will never get the sysvol/ netlogon and that needs sorting first). When you are browsing to the netlogon/ sysvol shares where are you doing this from? As don't be fooled in to thinking that these are being replicated if you are just \\ ing these from a client. A quick way to verify that each DC has these shares is to \\ each DC directly so \\SVR-DC-02\ you can even try creating a file directly in each servers netlogon folder and then watch it appear in all the other servers netlogon folders for a quick a dirty test.

 

Also when you say restored what have you actually restored? The whole DC the contance of the sysvol / netlogon shares?

 

I see you used the PowerShell to move the FSMO roles from a post a few days ago like @FN-GM has said just check what DC thinks it's holding the FSMO roles.

 

The following tool is really useful

 

https://www.microsoft.com/en-us/download/details.aspx?id=30005

Edited by HPlum78
Posted (edited)
hold on a second I have just reread your initial post can you check in each of your domain controllers for event id 2095 (in the directory service log)... Let's rule out any usn rollback issues here as well. Edited by HPlum78
Posted

Hi Guys,

 

The issue seems to be with the original two DCs about 4 weeks ago. I dont know what has happened but they seem to not replicate from the SYSVOL folders. I basically went back as far as I could with the restore on both DC's and looks to be from then rather than when I added a 2016 server.

 

It might have been after I moved the FSMO roles from SCR-DC-01 to SVR-DC-02 or a corrupt GPO or permission some how.

 

If anyone would like to talk to me about the issue, please PM me and ill send you my number.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...