Kevin,
This is a long response.... but I wanted to give you all
the info I have...
1. The ipconfig from the original post is from the w2k
machine..
2. Yes I removed the isp dns.....
3. This is the ipconfig /all from w2k3 computer (FS1)
Windows IP Configuration
Host Name . . . . . . . . . . . . : FS1
Primary Dns Suffix . . . . . . . : example.company.net
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : example.company.net
company.net
Ethernet adapter Local Area Connection 2:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000
MT Dual Port Network Connection #2
Physical Address. . . . . . . . . : 00-07-E9-06-3E-87
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.10.152
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.10.1
DNS Servers . . . . . . . . . . . : 192.168.10.150
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000
MT Dual Port Network Connection
Physical Address. . . . . . . . . : 00-07-E9-06-3E-86
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.10.153
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.10.1
DNS Servers . . . . . . . . . . . : 192.168.10.150
4. Dcdiag /v from w2k computer
From w2k, dmc2dcdiag /v
Domain Controller Diagnosis
Performing initial setup:
* Verifying that the local machine dmc2, is a DC.
* Connecting to directory service on server dmc2.
* Collecting site info.
* Identifying all servers.
* Found 1 DC(s). Testing 1 of them.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\DMC2
Starting test: Connectivity
* Active Directory LDAP Services Check
* Active Directory RPC Services Check
......................... DMC2 passed test
Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\DMC2
Starting test: Replications
* Replications Check
......................... DMC2 passed test
Replications
Test omitted by user request: Topology
Test omitted by user request: CutoffServers
Starting test: NCSecDesc
* Security Permissions Check for
CN=Schema,CN=Configuration,DC=inet,DC=imagewright,DC=net
* Security Permissions Check for
CN=Configuration,DC=inet,DC=imagewright,DC=net
* Security Permissions Check for
DC=inet,DC=imagewright,DC=net
......................... DMC2 passed test
NCSecDesc
Starting test: NetLogons
* Network Logons Privileges Check
......................... DMC2 passed test
NetLogons
Starting test: Advertising
The DC DMC2 is advertising itself as a DC and
having a DS.
The DC DMC2 is advertising as an LDAP server
The DC DMC2 is advertising as having a writeable
directory
The DC DMC2 is advertising as a Key Distribution
Center
The DC DMC2 is advertising as a time server
The DS DMC2 is advertising as a GC.
......................... DMC2 passed test
Advertising
Starting test: KnowsOfRoleHolders
Role Schema Owner = CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t
Role Domain Owner = CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t
Role PDC Owner = CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t
Role Rid Owner = CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t
Role Infrastructure Update Owner = CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t
......................... DMC2 passed test
KnowsOfRoleHolders
Starting test: RidManager
* Available RID Pool for the Domain is 1819 to
1073741823
* dmc2.example.company.net is the RID Master
* DsBind with RID Master was successful
* rIDAllocationPool is 1319 to 1818
* rIDNextRID: 1324
* rIDPreviousAllocationPool is 1319 to 1818
......................... DMC2 passed test
RidManager
Starting test: MachineAccount
* SPN
found :LDAP/dmc2.example.company.net/example.company.net
* SPN found :LDAP/dmc2.example.company.net
* SPN found :LDAP/DMC2
* SPN found :LDAP/dmc2.example.company.net/INET
* SPN found :LDAP/3b368261-70cd-48bb-a115-
4a918f365b51._msdcs.example.company.net
* SPN found :E3514235-4B06-11D1-AB04-
00C04FC2DCD2/3b368261-70cd-48bb-a115-
4a918f365b51/example.company.net
* SPN
found :HOST/dmc2.example.company.net/example.company.net
* SPN found :HOST/dmc2.example.company.net
* SPN found :HOST/DMC2
* SPN found :HOST/dmc2.example.company.net/INET
* SPN
found :GC/dmc2.example.company.net/example.company.net
......................... DMC2 passed test
MachineAccount
Starting test: Services
* Checking Service: Dnscache
* Checking Service: NtFrs
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: RpcSs
* Checking Service: RPCLOCATOR
* Checking Service: w32time
* Checking Service: TrkWks
* Checking Service: TrkSvr
* Checking Service: NETLOGON
......................... DMC2 passed test
Services
Test omitted by user request: OutboundSecureChannels
Starting test: ObjectsReplicated
DMC2 is in domain DC=inet,DC=imagewright,DC=net
Checking for CN=DMC2,OU=Domain
Controllers,DC=inet,DC=imagewright,DC=net in domain
DC=inet,DC=imagewright,DC=net on 1 servers
Object is up-to-date on all servers.
Checking for CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t in domain CN=Configuration,DC=inet,DC=imagewright,DC=net
on 1 servers
Object is up-to-date on all servers.
......................... DMC2 passed test
ObjectsReplicated
Starting test: frssysvol
* The File Replication Service Event log test
The SYSVOL has been shared, and the AD is no
longer
prevented from starting by the File Replication
Service.
......................... DMC2 passed test
frssysvol
Starting test: kccevent
* The KCC Event log test
Found no KCC errors in Directory Service Event
log in the last 15 minutes.
......................... DMC2 passed test
kccevent
Starting test: systemlog
* The System Event log test
Found no errors in System Event log in the last
60 minutes.
......................... DMC2 passed test
systemlog
Running enterprise tests on : example.company.net
Starting test: Intersite
Skipping site Default-First-Site-Name, this site
is outside the scope
provided by the command line arguments provided.
......................... example.company.net
passed test Intersite
Starting test: FsmoCheck
GC Name: \\dmc2.example.company.net
Locator Flags: 0xe00001fd
PDC Name: \\dmc2.example.company.net
Locator Flags: 0xe00001fd
Time Server Name: \\dmc2.example.company.net
Locator Flags: 0xe00001fd
Preferred Time Server Name:
\\dmc2.example.company.net
Locator Flags: 0xe00001fd
KDC Name: \\dmc2.example.company.net
Locator Flags: 0xe00001fd
......................... example.company.net
passed test FsmoCheck
5. dcdiag /h:example.company.net /v from w2k3 computer
From w2k3 (FS1 (machine name))
dcdiag /h:example.company.net /v
Domain Controller Diagnosis
Performing initial setup:
* Connecting to directory service on server
dmc2.example.company.net.
* Collecting site info.
* Identifying all servers.
* Found 1 DC(s). Testing 1 of them.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\DMC2
Starting test: Connectivity
* Active Directory LDAP Services Check
* Active Directory RPC Services Check
......................... DMC2 passed test
Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\DMC2
Starting test: Replications
* Replications Check
......................... DMC2 passed test
Replications
Test omitted by user request: Topology
Test omitted by user request: CutoffServers
Starting test: NCSecDesc
* Security Permissions Check for
CN=Schema,CN=Configuration,DC=inet,DC=imagewright,DC=net
* Security Permissions Check for
CN=Configuration,DC=inet,DC=imagewright,DC=net
* Security Permissions Check for
DC=inet,DC=imagewright,DC=net
......................... DMC2 passed test
NCSecDesc
Starting test: NetLogons
* Network Logons Privileges Check
......................... DMC2 passed test
NetLogons
Starting test: Advertising
The DC DMC2 is advertising itself as a DC and
having a DS.
The DC DMC2 is advertising as an LDAP server
The DC DMC2 is advertising as having a writeable
directory
The DC DMC2 is advertising as a Key Distribution
Center
The DC DMC2 is advertising as a time server
The DS DMC2 is advertising as a GC.
......................... DMC2 passed test
Advertising
Starting test: KnowsOfRoleHolders
Role Schema Owner = CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t
Role Domain Owner = CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t
Role PDC Owner = CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t
Role Rid Owner = CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t
Role Infrastructure Update Owner = CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t
......................... DMC2 passed test
KnowsOfRoleHolders
Starting test: RidManager
* Available RID Pool for the Domain is 1819 to
1073741823
* dmc2.example.company.net is the RID Master
* DsBind with RID Master was successful
* rIDAllocationPool is 1319 to 1818
* rIDNextRID: 1324
* rIDPreviousAllocationPool is 1319 to 1818
......................... DMC2 passed test
RidManager
Starting test: MachineAccount
* SPN
found :LDAP/dmc2.example.company.net/example.company.net
* SPN found :LDAP/dmc2.example.company.net
* SPN found :LDAP/DMC2
* SPN found :LDAP/dmc2.example.company.net/INET
* SPN found :LDAP/3b368261-70cd-48bb-a115-
4a918f365b51._msdcs.example.company.net
* SPN found :E3514235-4B06-11D1-AB04-
00C04FC2DCD2/3b368261-70cd-48bb-a115-
4a918f365b51/example.company.net
* SPN
found :HOST/dmc2.example.company.net/example.company.net
* SPN found :HOST/dmc2.example.company.net
* SPN found :HOST/DMC2
* SPN found :HOST/dmc2.example.company.net/INET
* SPN
found :GC/dmc2.example.company.net/example.company.net
......................... DMC2 passed test
MachineAccount
Starting test: Services
* Checking Service: Dnscache
* Checking Service: NtFrs
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: RpcSs
* Checking Service: RPCLOCATOR
* Checking Service: w32time
* Checking Service: TrkWks
* Checking Service: TrkSvr
* Checking Service: NETLOGON
......................... DMC2 passed test
Services
Test omitted by user request: OutboundSecureChannels
Starting test: ObjectsReplicated
DMC2 is in domain DC=inet,DC=imagewright,DC=net
Checking for CN=DMC2,OU=Domain
Controllers,DC=inet,DC=imagewright,DC=net in domain
DC=inet,DC=imagewright,DC=net on 1 servers
Object is up-to-date on all servers.
Checking for CN=NTDS
Settings,CN=DMC2,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=inet,DC=imagewright,DC=ne
t in domain CN=Configuration,DC=inet,DC=imagewright,DC=net
on 1 servers
Object is up-to-date on all servers.
......................... DMC2 passed test
ObjectsReplicated
Starting test: frssysvol
* The File Replication Service Event log test
The SYSVOL has been shared, and the AD is no
longer
prevented from starting by the File Replication
Service.
......................... DMC2 passed test
frssysvol
Starting test: kccevent
* The KCC Event log test
Found no KCC errors in Directory Service Event
log in the last 15 minutes.
......................... DMC2 passed test
kccevent
Starting test: systemlog
* The System Event log test
Found no errors in System Event log in the last
60 minutes.
......................... DMC2 passed test
systemlog
Running enterprise tests on : example.company.net
Starting test: Intersite
Skipping site Default-First-Site-Name, this site
is outside the scope
provided by the command line arguments provided.
......................... example.company.net
passed test Intersite
Starting test: FsmoCheck
GC Name: \\dmc2.example.company.net
Locator Flags: 0xe00001fd
PDC Name: \\dmc2.example.company.net
Locator Flags: 0xe00001fd
Time Server Name: \\dmc2.example.company.net
Locator Flags: 0xe00001fd
Preferred Time Server Name:
\\dmc2.example.company.net
Locator Flags: 0xe00001fd
KDC Name: \\dmc2.example.company.net
Locator Flags: 0xe00001fd
......................... example.company.net
passed test FsmoCheck
6. dcdiag /test:dcpromo /DnsDomain:example.company.net
Starting test: DcPromo
Syntax Error: the test name must be followed by a
DNS domain name and the
operation,
e.g.: /test
cPromo /DnsDomain:domain.company.com /<operati
on>
......................... FS1 failed test DcPromo
Your help is greatly appreciated....
Jerry S
-----Original Message-----
In
[email protected],
Jerry S <
[email protected]> posted a question
Then Kevin replied below:
: These are the facts...
:
: We have one domain .... several servers ... mix of win nt
: 4.o and wk2....
:
: The PDC was a Win NT and no BDC....
:
: Our equipment is aging so I purchased a new server with
: w2k3 and wanted to make it the primary machine.....
:
: Took these steps....
: 1. Set up a temporary win nt BDC.. loaded all service
: packs etc and then promoted it to the PDC....
: 2. I upgraded this machine to a win 2k .... did all the
: upgrades etc.... installed AD on this machine... made it
: the DNS server
: 3. I installed AD client on all the NT machines (one of
: which is now the BDC.)
: 4. On the new machine I purchased I installed W2k3.... &
: joined the existing domain.... On the properties page it
: says it in in the domain.
: 5. It is at this point that I am trying to install AD with
: the wizard and make it a DC... or so says the selection
: screen on the w2k3 "Manage Your Computer"
:
: I don't want the new w2k3 machine in a "child" domain. The
: w2k machine is a DC in example.company.net .... This is
: where I want the w2k3.
:
: Sorry I am so confusing but I am on the verge of being in
: over my head.
:
OK, now I'm getting the picture, what was throughing me off was your DNS
search list in your ipconfig
DNS Suffix Search List. . . : example.company.net
company.net
It was giving me the picture that this was a child domain.
The ipconfig from your original post is for the Win2k, correct?
Did you remove the ISP's DNS from that NIC?
Can you post the ipconfig /all from the Win2k3?
Is there an Exchange 2000 in the mix?
Run dcdiag /v from the Win2k
and dcdiag /h:example.company.net /v from the Win2k3
and
dcdiag /test:dcpromo /DnsDomain:example.company.net /Replic
aDC from the