Jump to content

Recommended Posts

Posted

Hi there,

 

I need some kind person to check their AD DNS so I can reset mine correctly (if needed).

 

A long time ago (in a ....etc ) our AD was rebuilt. This was initially with one domain controller but that one has passed on and we have two new DCs. All the FSMO roles were transferred and everything has been working for well over a year.

 

However, I have recently had a couple of problem joinging a PC to the domain and the help has pointed me towards DNS. In looking around I noticed that we still have a couple of DNS entry pointing at the original DC. Most of these areas also have entries for the new DCs so I am planning to just remove the entries for the old DC.

 

Unfortunately, there is one area that there is *only* an entry for the old DC. This is in "Forward Lookup Zones/AD site name/_msdcs". This folder is a different shade from the others, although I dont think the shade indicates a problem.

 

Could some kind people have a look in their DNS and tell me what they have in that folder? I just have a NS record for the old DC - so I would like to know:

- Are there just NS entries in here, or should there be other records as well

- Are all the DCs listed, or just one? If there is not all the DCs listed, is it and particular FSMO roles that are listed (e.g. global catalog servers etc).

 

Many thanks for any help

 

Cheers

 

Jonathan

Posted

the _msdcs folder is a delegated folder - hence it is grayed out. The server entry indicated the server it is delegated to. By default, the first domain controller on the domain.

 

You will notice in the root of the forward lookup zone you have _msdcs.domain.com.

 

If that server no longer exists, then any changes to this zone will not be available. I would edit it and make it an existing domain controller.

Posted

Whilst I agree with the posts, are you positive that the issue is DNS?

 

Bit more info about the PC in question - has it been on the domain before? Has it recently been renamed?

Posted
Download DCDiag and Netdiag from microsoft and run them. That should highlight any other issues you are having.

 

Thanks - these do not highlight any problems, which is wierd as I can see DNS entries in there for the server that no longer exists!

 

Whilst I agree with the posts, are you positive that the issue is DNS?

 

Bit more info about the PC in question - has it been on the domain before? Has it recently been renamed?

 

Fairly sure that DNS has a problem - there are references to servers that no longer exist, which doesn't feel like a good thing. While it may not fix the issue I am having it is probably something that I should sort out sooner rather than later.

 

As to the new PC - it was actually a bank of ten new laptops all being built from an OSD image that has worked before. My suspicion was that the load caused by all 10 being built at once was causing it to try to find other name servers rather than just using the normal one and this might be why it was trying to find a different server from normal (and so possibly picking up the references to the old server). I am not sure if the entries in the DNS are the cause of this issue, but they are a problem to solve on the way.

 

Cheers

 

Jonathan

Posted

Tut tut tut, whose been switching DC's off and deleting them from AD without doing a proper demotion.

 

We had same problem (not my causing i hasten to add), went un-noticed for ages, then we installed exchange and this highlighted the problem as email would stop working when the GC / DC's replicated and got stuck on the DC that didnt exist anymore. Wasnt pretty to fix.

 

If this is the problem you will need ADSIedit which allows you to edit the AD schema. If i remember correctly the dead DC should still be under domain --> DC="school" --> CN=System --> CN=File Replication Service --> CN-Domain System Volume (SYSVOL share) --> CN="Dead DC".

 

You *should* be able to delete it in here without any major repercussions.

These should help.

http://support.microsoft.com/kb/555846

http://support.microsoft.com/kb/216498

 

I will not be held responsible for any problems though! Good luck! Hope this solves your problems.

Posted
Tut tut tut, whose been switching DC's off and deleting them from AD without doing a proper demotion.

 

Thanks for the helpful links - I have followed them all and there were no references to the old DC anywhere (other than this one entry in DNS).

 

For peoples interest I have added the DCs into that DNS folder and am now happier that the DNS is correct. Unfortunately it hasnt yet solved my joining the domain problem. I think I will have to get a sniffer setup and try to see what traffic is failing - automatic builds are OK until they are going wrong!

 

Cheers

 

Jonathan

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...