Thanks for your help.
The following are the result of dcdiag and network, I run it from
mail01(win2k3 with exchange 2003):
And I also found some errors on AD01's event log after demote (the DC
I had demoted). Please see at the end of DIAG result.
DIAG result start below:
-------------------------------------------------
DCDIAG RESULT:
AD05 (running on win2k3 with exchange 2003 insalled) C:\Documents and
Settings\Administrator.HKCEC>dcdiag /s:ad05
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\AD05
Starting test: Connectivity
......................... AD05 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\AD05
Starting test: Replications
......................... AD05 passed test Replications
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes All
access rights for the naming context:
CN=Schema,CN=Configuration,DC=hkcec,DC=nws
Error BUILTIN\Administrators doesn't have
Replicating Directory Changes All
access rights for the naming context:
CN=Schema,CN=Configuration,DC=hkcec,DC=nws
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes All
access rights for the naming context:
CN=Configuration,DC=hkcec,DC=nws
Error BUILTIN\Administrators doesn't have
Replicating Directory Changes All
access rights for the naming context:
CN=Configuration,DC=hkcec,DC=nws
......................... AD05 failed test NCSecDesc
Starting test: NetLogons
......................... AD05 passed test NetLogons
Starting test: Advertising
......................... AD05 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... AD05 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... AD05 passed test RidManager
Starting test: MachineAccount
......................... AD05 passed test MachineAccount
Starting test: Services
......................... AD05 passed test Services
Starting test: ObjectsReplicated
......................... AD05 passed test ObjectsReplicated
Starting test: frssysvol
......................... AD05 passed test frssysvol
Starting test: frsevent
......................... AD05 passed test frsevent
Starting test: kccevent
......................... AD05 passed test kccevent
Starting test: systemlog
......................... AD05 passed test systemlog
Starting test: VerifyReferences
......................... AD05 passed test VerifyReferences
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test
CheckSDRefDom
Running partition tests on : hkcec
Starting test: CrossRefValidation
......................... hkcec passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... hkcec passed test CheckSDRefDom
Running enterprise tests on : hkcec.nws
Starting test: Intersite
......................... hkcec.nws passed test Intersite
Starting test: FsmoCheck
......................... hkcec.nws passed test FsmoCheck
C:\Documents and Settings\Administrator.HKCEC>
DCDIAG RESULT
AD06(running on win2k3 with exchange 2003 insalled) C:\Documents and
Settings\Administrator.HKCEC>dcdiag /s:ad06
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\AD06
Starting test: Connectivity
......................... AD06 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\AD06
Starting test: Replications
......................... AD06 passed test Replications
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes All
access rights for the naming context:
CN=Schema,CN=Configuration,DC=hkcec,DC=nws
Error BUILTIN\Administrators doesn't have
Replicating Directory Changes All
access rights for the naming context:
CN=Schema,CN=Configuration,DC=hkcec,DC=nws
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes All
access rights for the naming context:
CN=Configuration,DC=hkcec,DC=nws
Error BUILTIN\Administrators doesn't have
Replicating Directory Changes All
access rights for the naming context:
CN=Configuration,DC=hkcec,DC=nws
......................... AD06 failed test NCSecDesc
Starting test: NetLogons
......................... AD06 passed test NetLogons
Starting test: Advertising
......................... AD06 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... AD06 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... AD06 passed test RidManager
Starting test: MachineAccount
......................... AD06 passed test MachineAccount
Starting test: Services
......................... AD06 passed test Services
Starting test: ObjectsReplicated
......................... AD06 passed test ObjectsReplicated
Starting test: frssysvol
......................... AD06 passed test frssysvol
Starting test: frsevent
......................... AD06 passed test frsevent
Starting test: kccevent
......................... AD06 passed test kccevent
Starting test: systemlog
......................... AD06 passed test systemlog
Starting test: VerifyReferences
......................... AD06 passed test VerifyReferences
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test
CheckSDRefDom
Running partition tests on : hkcec
Starting test: CrossRefValidation
......................... hkcec passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... hkcec passed test CheckSDRefDom
Running enterprise tests on : hkcec.nws
Starting test: Intersite
......................... hkcec.nws passed test Intersite
Starting test: FsmoCheck
......................... hkcec.nws passed test FsmoCheck
NETDIAG RESULT (running on win2k3 with exchange 2003 insalled)
C:\Documents and Settings\Administrator.HKCEC>netdiag /d:hkcec.nws
...................................
Computer Name: MAIL01
DNS Host Name: mail01.hkcec.nws
System info : Windows 2000 Server (Build 3790)
Processor : x86 Family 15 Model 6 Stepping 8, GenuineIntel
List of installed hotfixes :
KB819696
KB822925
KB823182
KB823559
KB823728
KB823980
KB824105
KB824141
KB824145
KB824146
KB825119
KB828028
KB828035
KB828741
KB828750
KB830352
KB831464
KB832894
KB835732
KB837001
KB837009
KB837272
KB840374
KB893803v2
Q147222
Q828026
Netcard queries test . . . . . . . : Passed
Per interface results:
Adapter : Local Area Connection 4
Netcard queries test . . . : Passed
Host Name. . . . . . . . . : mail01
IP Address . . . . . . . . : 10.0.0.16
Subnet Mask. . . . . . . . : 255.255.252.0
Default Gateway. . . . . . : 10.0.0.2
Dns Servers. . . . . . . . : 10.0.0.63
10.0.0.68
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Failed
No gateway reachable for this adapter.
NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03>
'Messenge
r Service', <20> 'WINS' names is missing.
No remote names have been found.
WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{1685F764-98AF-4F78-B7A4-0ACC841B66CF}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Failed
[FATAL] NO GATEWAYS ARE REACHABLE.
You have no connectivity to other network segments.
If you configured the IP protocol manually then
you need to add at least one valid gateway.
NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00>
'WorkStation
Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{1685F764-98AF-4F78-B7A4-0ACC841B66CF}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{1685F764-98AF-4F78-B7A4-0ACC841B66CF}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Passed
Secure channel for domain 'HKCEC' is to '\\AD05.hkcec.nws'.
Kerberos test. . . . . . . . . . . : Failed
[FATAL] Kerberos does not have a ticket for
host/mail01.hkcec.nws.
LDAP test. . . . . . . . . . . . . : Passed
[WARNING] Failed to query SPN registration on DC 'ad02.hkcec.nws'.
[WARNING] Failed to query SPN registration on DC
'adtest.hkcec.nws'.
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Skipped
Note: run "netsh ipsec dynamic show /?" for more detailed
information
The command completed successfully
And errors found on AD01's event after demote (the DC I had demote),
the demote process was completed without warning
sYSTEM Event log
The Intersite Messaging service terminated unexpectedly. It has done
this 1
time(s). The following corrective action will be taken in 0
milliseconds: No
action.
APPLICATION Event log
Replication warning: Couldn't allocate memory. Replication may be
affected until more memory is available. Increase the amount of
virtual memory available. Stop and restart this Windows Domain
Controller and try again.
-----------------------------------
Thanks for your help again
Patrick
Meinolf Weber said:
Hello patrick,
What about dcdiag and netdiag on all dc's?
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.