Strange active directory problem

  • Thread starter Thread starter alamb200
  • Start date Start date
A

alamb200

Hi,
We have two servers on our network a Windows 2000 server with
Exchange
and a Windows 2003 server. The Windows 2000 server is the main server
for the network with the 2003 server added later.
All was fine until recently when I was trying to edit the Default
Group Policy from the Windows 2003 server but I was unable to do so I
could only look at its properties. I was also trying to install
Serveraid software but I did not have permission to add the service
even though I was logged on as the Administrator.
I did a DCPROMO down on the 2003 server then back up again to try and
resolve it but it made no difference.
Has anyone got any ideas what is going wrong.
Please help.
Thanks
alamb200
 
What kind of errors did you get? Were there any messages in the Event Log?

Run diagnostics against your Active Directory domain.

If you don't have the tools installed, install them from your server install
disk.
d:\support\tools\setup.exe

Run dcdiag, netdiag and repadmin in verbose mode.
-> DCDIAG /V /C /D /E /s:yourdcname > c:\dcdiag.log
-> netdiag.exe /v > c:\netdiag.log (On each dc)
-> repadmin.exe /showrepl dc* /verbose /all /intersite > c:\repl.txt

**Note: Using the /E switch in dcdiag will run diagnostics against ALL dc's
in the forest. If you have significant numbers of DC's this test could
generate significant detail and take a long time. You also want to take
into account slow links to dc's will also add to the testing time.

If you download a gui script I wrote it should be simple to set and run
(DCDiag and NetDiag). It also has the option to run individual tests
without having to learn all the switch options. The details will be output
in notepad text files that pop up automagically.

The script is located in the download section on my website at
http://www.pbbergs.com

Just select both dcdiag and netdiag make sure verbose is set. (Leave the
default settings for dcdiag as set when selected)

When complete search for fail, error and warning messages.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
 
Hi

I have the results of the DCDIAG there were some errors I have added
these below this text

Starting test: frssysvol
* The File Replication Service Event log test
The registry lookup failed to determine the state of
the SYSVOL. Using the systems event log instead.
The SYSVOL has been shared, and the AD is no longer
prevented from starting by the File Replication Service.
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
An Warning Event occured. EventID: 0x800034C4
Time Generated: 02/12/2007 17:43:00
Event String: The File Replication Service is having
trouble

enabling replication from RDSMERTEX to DCMAIL1

for c:\winnt\sysvol\domain using the DNS name

rdsmertex.reflexdata.co.uk. FRS will keep

retrying.

Following are some of the reasons you would see

this warning.



[1] FRS can not correctly resolve the DNS name

rdsmertex.reflexdata.co.uk from this computer.

[2] FRS is not running on

rdsmertex.reflexdata.co.uk.

[3] The topology information in the Active

Directory for this replica has not yet replicated

to all the Domain Controllers.



This event log message will appear once per

connection, After the problem is fixed you will

see another event log message indicating that the

connection has been established.
An Warning Event occured. EventID: 0x800034C5
Time Generated: 02/12/2007 17:43:51
Event String: The File Replication Service has enabled

replication from RDSMERTEX to DCMAIL1 for

c:\winnt\sysvol\domain after repeated retries.
An Warning Event occured. EventID: 0x800034FC
Time Generated: 02/21/2007 02:46:11
Event String: The File Replication Service has detected
that

the volume holding the FRS debug logs is running

out of disk space. This will not affect

replication unless this volume hosts database,

staging, or replica root paths as well.



Path to the logs directory = C:\WINNT\debug



You can change the number and size of logs by

adjusting the following registry values. Sample

values are shown below. These values are under

the registry key

"HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/

Services/NtFrs/Parameters



Debug Log Files REG_DWORD 0x5

Debug Log Severity REG_DWORD 0x2

Debug Maximum Log Messages REG_DWORD 0x2710



You can also change the path to the logs

directory by changing the following value at the

same location.



Debug Log File REG_SZ windir\debug



Changes to the registry values will take affect

at the next polling cycle.


......................... DCMAIL1 passed test frssysvol

Starting test: systemlog
* The System Event log test
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:02:23
Event String: The JET Database call returned the following

error : -1808. Additional Debug Information:

JetBackup.
An Error Event occured. EventID: 0x000003F8
Time Generated: 02/21/2007 08:02:23
Event String: The DHCP service encountered the following
error

when backing up the database:

An error occurred while accessing the DHCP database. Look at the

DHCP server event log for more information on this error.




An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

DhcpJetCommitUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

RemoveClientEntry:Delete.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:44
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:48
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:55
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:37:12
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
......................... DCMAIL1 failed test systemlog

I also got this message from Netdiag

The DNS registration for dcmail1.reflexdata.co.uk is correct on
all DNS servers
Check the DNS registration for DCs entries on DNS server
'192.9.200.14'
The Record is different on DNS server '192.9.200.14'.
DNS server has more than one entries for this name, usually this means
there are multiple DCs for this domain.
Your DC entry is one of them on DNS server '192.9.200.14', no need to
re-register.

Please can you explain what these mean.

Thanks

alamb200
 
alamb200 said:
Hi

I have the results of the DCDIAG there were some errors I have added
these below this text

Starting test: frssysvol
* The File Replication Service Event log test
The registry lookup failed to determine the state of
the SYSVOL. Using the systems event log instead.
The SYSVOL has been shared, and the AD is no longer
prevented from starting by the File Replication Service.
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
An Warning Event occured. EventID: 0x800034C4
Time Generated: 02/12/2007 17:43:00
Event String: The File Replication Service is having
trouble

enabling replication from RDSMERTEX to DCMAIL1

for c:\winnt\sysvol\domain using the DNS name

rdsmertex.reflexdata.co.uk. FRS will keep

retrying.

Following are some of the reasons you would see

this warning.



[1] FRS can not correctly resolve the DNS name

rdsmertex.reflexdata.co.uk from this computer.

[2] FRS is not running on

rdsmertex.reflexdata.co.uk.

[3] The topology information in the Active

Directory for this replica has not yet replicated

to all the Domain Controllers.



This event log message will appear once per

connection, After the problem is fixed you will

see another event log message indicating that the

connection has been established.
An Warning Event occured. EventID: 0x800034C5
Time Generated: 02/12/2007 17:43:51
Event String: The File Replication Service has enabled

replication from RDSMERTEX to DCMAIL1 for

c:\winnt\sysvol\domain after repeated retries.
An Warning Event occured. EventID: 0x800034FC
Time Generated: 02/21/2007 02:46:11
Event String: The File Replication Service has detected
that

the volume holding the FRS debug logs is running

out of disk space. This will not affect

replication unless this volume hosts database,

staging, or replica root paths as well.



Path to the logs directory = C:\WINNT\debug



You can change the number and size of logs by

adjusting the following registry values. Sample

values are shown below. These values are under

the registry key

"HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/

Services/NtFrs/Parameters



Debug Log Files REG_DWORD 0x5

Debug Log Severity REG_DWORD 0x2

Debug Maximum Log Messages REG_DWORD 0x2710



You can also change the path to the logs

directory by changing the following value at the

same location.



Debug Log File REG_SZ windir\debug



Changes to the registry values will take affect

at the next polling cycle.


......................... DCMAIL1 passed test frssysvol

Starting test: systemlog
* The System Event log test
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:02:23
Event String: The JET Database call returned the following

error : -1808. Additional Debug Information:

JetBackup.
An Error Event occured. EventID: 0x000003F8
Time Generated: 02/21/2007 08:02:23
Event String: The DHCP service encountered the following
error

when backing up the database:

An error occurred while accessing the DHCP database. Look at the

DHCP server event log for more information on this error.




An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

DhcpJetCommitUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

RemoveClientEntry:Delete.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:44
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:48
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:55
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:37:12
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
......................... DCMAIL1 failed test systemlog

I also got this message from Netdiag

The DNS registration for dcmail1.reflexdata.co.uk is correct on
all DNS servers
Check the DNS registration for DCs entries on DNS server
'192.9.200.14'
The Record is different on DNS server '192.9.200.14'.
DNS server has more than one entries for this name, usually this means
there are multiple DCs for this domain.
Your DC entry is one of them on DNS server '192.9.200.14', no need to
re-register.

Please can you explain what these mean.

Thanks

alamb200











What kind of errors did you get? Were there any messages in the Event
Log?

Run diagnostics against your Active Directory domain.

If you don't have the tools installed, install them from your server
install
disk.
d:\support\tools\setup.exe

Run dcdiag, netdiag and repadmin in verbose mode.
-> DCDIAG /V /C /D /E /s:yourdcname > c:\dcdiag.log
-> netdiag.exe /v > c:\netdiag.log (On each dc)
-> repadmin.exe /showrepl dc* /verbose /all /intersite > c:\repl.txt

**Note: Using the /E switch in dcdiag will run diagnostics against ALL
dc's
in the forest. If you have significant numbers of DC's this test could
generate significant detail and take a long time. You also want to take
into account slow links to dc's will also add to the testing time.

If you download a gui script I wrote it should be simple to set and run
(DCDiag and NetDiag). It also has the option to run individual tests
without having to learn all the switch options. The details will be
output
in notepad text files that pop up automagically.

The script is located in the download section on my website
athttp://www.pbbergs.com

Just select both dcdiag and netdiag make sure verbose is set. (Leave the
default settings for dcdiag as set when selected)

When complete search for fail, error and warning messages.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.






- Show quoted text -
Start by cleaning up your c: disk and getting the system some free space,
the report is squawking on low disk space. Check in the c:\windows (Or
Winnt) folder and see if all the backup files from your patches have
consumed the space. If so offload them to another location, this can save a
lot of space.

It appears there are problems with dhcp when it is trying to backup your
system, after researching this, it appears others have had this same problem
when they have run out of disk space. I would try to clean up your disk and
see if this helps.

The multiple names is probably due to the fact that you have multiple nics
in the same dc. Multi-homing a dc is a bad idea. Disable one of the nics.


--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
 
I have the results of the DCDIAG there were some errors I have added
these below this text
Starting test: frssysvol
* The File Replication Service Event log test
The registry lookup failed to determine the state of
the SYSVOL. Using the systems event log instead.
The SYSVOL has been shared, and the AD is no longer
prevented from starting by the File Replication Service.
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
An Warning Event occured. EventID: 0x800034C4
Time Generated: 02/12/2007 17:43:00
Event String: The File Replication Service is having
trouble
enabling replication from RDSMERTEX to DCMAIL1
for c:\winnt\sysvol\domain using the DNS name
rdsmertex.reflexdata.co.uk. FRS will keep

Following are some of the reasons you would see
this warning.
[1] FRS can not correctly resolve the DNS name
rdsmertex.reflexdata.co.uk from this computer.
[2] FRS is not running on
rdsmertex.reflexdata.co.uk.

[3] The topology information in the Active
Directory for this replica has not yet replicated
to all the Domain Controllers.
This event log message will appear once per
connection, After the problem is fixed you will
see another event log message indicating that the
connection has been established.
An Warning Event occured. EventID: 0x800034C5
Time Generated: 02/12/2007 17:43:51
Event String: The File Replication Service has enabled
replication from RDSMERTEX to DCMAIL1 for
c:\winnt\sysvol\domain after repeated retries.
An Warning Event occured. EventID: 0x800034FC
Time Generated: 02/21/2007 02:46:11
Event String: The File Replication Service has detected
that
the volume holding the FRS debug logs is running
out of disk space. This will not affect
replication unless this volume hosts database,
staging, or replica root paths as well.
Path to the logs directory = C:\WINNT\debug
You can change the number and size of logs by
adjusting the following registry values. Sample
values are shown below. These values are under
the registry key


Debug Log Files REG_DWORD 0x5
Debug Log Severity REG_DWORD 0x2
Debug Maximum Log Messages REG_DWORD 0x2710
You can also change the path to the logs
directory by changing the following value at the
same location.
Debug Log File REG_SZ windir\debug
Changes to the registry values will take affect
at the next polling cycle.
......................... DCMAIL1 passed test frssysvol
Starting test: systemlog
* The System Event log test
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:02:23
Event String: The JET Database call returned the following
error : -1808. Additional Debug Information:
JetBackup.
An Error Event occured. EventID: 0x000003F8
Time Generated: 02/21/2007 08:02:23
Event String: The DHCP service encountered the following
error
when backing up the database:
An error occurred while accessing the DHCP database. Look at the
DHCP server event log for more information on this error.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
DhcpJetCommitUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
RemoveClientEntry:Delete.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:44
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:48
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:55
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:37:12
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
......................... DCMAIL1 failed test systemlog
I also got this message from Netdiag
The DNS registration for dcmail1.reflexdata.co.uk is correct on
all DNS servers
Check the DNS registration for DCs entries on DNS server
'192.9.200.14'
The Record is different on DNS server '192.9.200.14'.
DNS server has more than one entries for this name, usually this means
there are multiple DCs for this domain.
Your DC entry is one of them on DNS server '192.9.200.14', no need to
re-register.
Please can you explain what these mean.

Start by cleaning up your c: disk and getting the system some free space,
the report is squawking on low disk space. Check in the c:\windows (Or
Winnt) folder and see if all the backup files from your patches have
consumed the space. If so offload them to another location, this can save a
lot of space.

It appears there are problems with dhcp when it is trying to backup your
system, after researching this, it appears others have had this same problem
when they have run out of disk space. I would try to clean up your disk and
see if this helps.

The multiple names is probably due to the fact that you have multiple nics
in the same dc. Multi-homing a dc is a bad idea. Disable one of the nics.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.- Hide quoted text -

- Show quoted text -

Hi Paul,

Sorry about that I had run out of space on the c drive this was
causing the issue with DHCP as well.

Back to the real problem I am still having problems on my second DC I
tried to access the Domain Controller Policy and get told that Access
Denied I also tried to install Serveraid Software but do not have
permission to start the service.

On the second DC I tried the command netdom query pdc and got the
correct reply, I have also tried following Microsoft KB article 294257
to no avail

Please help

alamb200
 
Is this something that works on one dc and not the other? If so then you
could do a non-authoritative restore on the failing dc.

http://support.microsoft.com/?id=840674


--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

alamb200 said:
I have the results of the DCDIAG there were some errors I have added
these below this text
Starting test: frssysvol
* The File Replication Service Event log test
The registry lookup failed to determine the state of
the SYSVOL. Using the systems event log instead.
The SYSVOL has been shared, and the AD is no longer
prevented from starting by the File Replication Service.
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
An Warning Event occured. EventID: 0x800034C4
Time Generated: 02/12/2007 17:43:00
Event String: The File Replication Service is having
trouble
enabling replication from RDSMERTEX to DCMAIL1
for c:\winnt\sysvol\domain using the DNS name
rdsmertex.reflexdata.co.uk. FRS will keep

Following are some of the reasons you would see
this warning.
[1] FRS can not correctly resolve the DNS name
rdsmertex.reflexdata.co.uk from this computer.
[2] FRS is not running on
rdsmertex.reflexdata.co.uk.

[3] The topology information in the Active
Directory for this replica has not yet replicated
to all the Domain Controllers.
This event log message will appear once per
connection, After the problem is fixed you will
see another event log message indicating that the
connection has been established.
An Warning Event occured. EventID: 0x800034C5
Time Generated: 02/12/2007 17:43:51
Event String: The File Replication Service has enabled
replication from RDSMERTEX to DCMAIL1 for
c:\winnt\sysvol\domain after repeated retries.
An Warning Event occured. EventID: 0x800034FC
Time Generated: 02/21/2007 02:46:11
Event String: The File Replication Service has detected
that
the volume holding the FRS debug logs is running
out of disk space. This will not affect
replication unless this volume hosts database,
staging, or replica root paths as well.
Path to the logs directory = C:\WINNT\debug
You can change the number and size of logs by
adjusting the following registry values. Sample
values are shown below. These values are under
the registry key


Debug Log Files REG_DWORD 0x5
Debug Log Severity REG_DWORD 0x2
Debug Maximum Log Messages REG_DWORD 0x2710
You can also change the path to the logs
directory by changing the following value at the
same location.
Debug Log File REG_SZ windir\debug
Changes to the registry values will take affect
at the next polling cycle.
......................... DCMAIL1 passed test frssysvol
Starting test: systemlog
* The System Event log test
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:02:23
Event String: The JET Database call returned the following
error : -1808. Additional Debug Information:
JetBackup.
An Error Event occured. EventID: 0x000003F8
Time Generated: 02/21/2007 08:02:23
Event String: The DHCP service encountered the following
error
when backing up the database:
An error occurred while accessing the DHCP database. Look at the
DHCP server event log for more information on this error.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
DhcpJetCommitUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
RemoveClientEntry:Delete.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:44
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:48
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:55
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:37:12
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
......................... DCMAIL1 failed test systemlog
I also got this message from Netdiag
The DNS registration for dcmail1.reflexdata.co.uk is correct on
all DNS servers
Check the DNS registration for DCs entries on DNS server
'192.9.200.14'
The Record is different on DNS server '192.9.200.14'.
DNS server has more than one entries for this name, usually this means
there are multiple DCs for this domain.
Your DC entry is one of them on DNS server '192.9.200.14', no need to
re-register.
Please can you explain what these mean.

On 16 Feb, 14:06, "Paul Bergson [MVP-DS]" <pbergson@allete_nospam.com>
wrote:
What kind of errors did you get? Were there any messages in the Event
Log?
Run diagnostics against your Active Directory domain.
If you don't have the tools installed, install them from your server
install
disk.
d:\support\tools\setup.exe
Run dcdiag, netdiag and repadmin in verbose mode.
-> DCDIAG /V /C /D /E /s:yourdcname > c:\dcdiag.log
-> netdiag.exe /v > c:\netdiag.log (On each dc)
-> repadmin.exe /showrepl dc* /verbose /all /intersite > c:\repl.txt
**Note: Using the /E switch in dcdiag will run diagnostics against ALL
dc's
in the forest. If you have significant numbers of DC's this test
could
generate significant detail and take a long time. You also want to
take
into account slow links to dc's will also add to the testing time.
If you download a gui script I wrote it should be simple to set and
run
(DCDiag and NetDiag). It also has the option to run individual tests
without having to learn all the switch options. The details will be
output
in notepad text files that pop up automagically.
The script is located in the download section on my website
athttp://www.pbbergs.com
Just select both dcdiag and netdiag make sure verbose is set. (Leave
the
default settings for dcdiag as set when selected)
When complete search for fail, error and warning messages.
--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.
Hi,
We have two servers on our network a Windows 2000 server with
Exchange
and a Windows 2003 server. The Windows 2000 server is the main
server
for the network with the 2003 server added later.
All was fine until recently when I was trying to edit the Default
Group Policy from the Windows 2003 server but I was unable to do so
I
could only look at its properties. I was also trying to install
Serveraid software but I did not have permission to add the service
even though I was logged on as the Administrator.
I did a DCPROMO down on the 2003 server then back up again to try
and
resolve it but it made no difference.
Has anyone got any ideas what is going wrong.
Please help.
Thanks
alamb200- Hide quoted text -
- Show quoted text -

Start by cleaning up your c: disk and getting the system some free space,
the report is squawking on low disk space. Check in the c:\windows (Or
Winnt) folder and see if all the backup files from your patches have
consumed the space. If so offload them to another location, this can
save a
lot of space.

It appears there are problems with dhcp when it is trying to backup your
system, after researching this, it appears others have had this same
problem
when they have run out of disk space. I would try to clean up your disk
and
see if this helps.

The multiple names is probably due to the fact that you have multiple
nics
in the same dc. Multi-homing a dc is a bad idea. Disable one of the
nics.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.- Hide quoted text -

- Show quoted text -

Hi Paul,

Sorry about that I had run out of space on the c drive this was
causing the issue with DHCP as well.

Back to the real problem I am still having problems on my second DC I
tried to access the Domain Controller Policy and get told that Access
Denied I also tried to install Serveraid Software but do not have
permission to start the service.

On the second DC I tried the command netdom query pdc and got the
correct reply, I have also tried following Microsoft KB article 294257
to no avail

Please help

alamb200
 
Did you check all DNS server to ensure all Host (A) records and machines
names are properly aligned?

Did you recently promote a server that is generating the error?

Are you sites and services properly configured?

Gene Vinyard


Hi

I have the results of the DCDIAG there were some errors I have added
these below this text

Starting test: frssysvol
* The File Replication Service Event log test
The registry lookup failed to determine the state of
the SYSVOL. Using the systems event log instead.
The SYSVOL has been shared, and the AD is no longer
prevented from starting by the File Replication Service.
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
An Warning Event occured. EventID: 0x800034C4
Time Generated: 02/12/2007 17:43:00
Event String: The File Replication Service is having
trouble

enabling replication from RDSMERTEX to DCMAIL1

for c:\winnt\sysvol\domain using the DNS name

rdsmertex.reflexdata.co.uk. FRS will keep

retrying.

Following are some of the reasons you would see

this warning.



[1] FRS can not correctly resolve the DNS name

rdsmertex.reflexdata.co.uk from this computer.

[2] FRS is not running on

rdsmertex.reflexdata.co.uk.

[3] The topology information in the Active

Directory for this replica has not yet replicated

to all the Domain Controllers.



This event log message will appear once per

connection, After the problem is fixed you will

see another event log message indicating that the

connection has been established.
An Warning Event occured. EventID: 0x800034C5
Time Generated: 02/12/2007 17:43:51
Event String: The File Replication Service has enabled

replication from RDSMERTEX to DCMAIL1 for

c:\winnt\sysvol\domain after repeated retries.
An Warning Event occured. EventID: 0x800034FC
Time Generated: 02/21/2007 02:46:11
Event String: The File Replication Service has detected
that

the volume holding the FRS debug logs is running

out of disk space. This will not affect

replication unless this volume hosts database,

staging, or replica root paths as well.



Path to the logs directory = C:\WINNT\debug



You can change the number and size of logs by

adjusting the following registry values. Sample

values are shown below. These values are under

the registry key

"HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/

Services/NtFrs/Parameters



Debug Log Files REG_DWORD 0x5

Debug Log Severity REG_DWORD 0x2

Debug Maximum Log Messages REG_DWORD 0x2710



You can also change the path to the logs

directory by changing the following value at the

same location.



Debug Log File REG_SZ windir\debug



Changes to the registry values will take affect

at the next polling cycle.


......................... DCMAIL1 passed test frssysvol

Starting test: systemlog
* The System Event log test
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:02:23
Event String: The JET Database call returned the following

error : -1808. Additional Debug Information:

JetBackup.
An Error Event occured. EventID: 0x000003F8
Time Generated: 02/21/2007 08:02:23
Event String: The DHCP service encountered the following
error

when backing up the database:

An error occurred while accessing the DHCP database. Look at the

DHCP server event log for more information on this error.




An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

DhcpJetCommitUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

RemoveClientEntry:Delete.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:44
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:48
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:55
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:37:12
Event String: The JET Database call returned the following

error : -529. Additional Debug Information:

CreateClientEntry:JetUpdate.
......................... DCMAIL1 failed test systemlog

I also got this message from Netdiag

The DNS registration for dcmail1.reflexdata.co.uk is correct on
all DNS servers
Check the DNS registration for DCs entries on DNS server
'192.9.200.14'
The Record is different on DNS server '192.9.200.14'.
DNS server has more than one entries for this name, usually this means
there are multiple DCs for this domain.
Your DC entry is one of them on DNS server '192.9.200.14', no need to
re-register.

Please can you explain what these mean.

Thanks

alamb200











What kind of errors did you get? Were there any messages in the Event Log?

Run diagnostics against your Active Directory domain.

If you don't have the tools installed, install them from your server install
disk.
d:\support\tools\setup.exe

Run dcdiag, netdiag and repadmin in verbose mode.
-> DCDIAG /V /C /D /E /s:yourdcname > c:\dcdiag.log
-> netdiag.exe /v > c:\netdiag.log (On each dc)
-> repadmin.exe /showrepl dc* /verbose /all /intersite > c:\repl.txt

**Note: Using the /E switch in dcdiag will run diagnostics against ALL dc's
in the forest. If you have significant numbers of DC's this test could
generate significant detail and take a long time. You also want to take
into account slow links to dc's will also add to the testing time.

If you download a gui script I wrote it should be simple to set and run
(DCDiag and NetDiag). It also has the option to run individual tests
without having to learn all the switch options. The details will be output
in notepad text files that pop up automagically.

The script is located in the download section on my website
athttp://www.pbbergs.com

Just select both dcdiag and netdiag make sure verbose is set. (Leave the
default settings for dcdiag as set when selected)

When complete search for fail, error and warning messages.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.






- Show quoted text -

Sent using the Microsoft Entourage 2004 for Mac Test Drive.
 
Did you check all DNS server to ensure all Host (A) records and machines
names are properly aligned?

Did you recently promote a server that is generating the error?

Are you sites and services properly configured?

Gene Vinyard

I have the results of the DCDIAG there were some errors I have added
these below this text
Starting test: frssysvol
* The File Replication Service Event log test
The registry lookup failed to determine the state of
the SYSVOL. Using the systems event log instead.
The SYSVOL has been shared, and the AD is no longer
prevented from starting by the File Replication Service.
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
An Warning Event occured. EventID: 0x800034C4
Time Generated: 02/12/2007 17:43:00
Event String: The File Replication Service is having
trouble
enabling replication from RDSMERTEX to DCMAIL1
for c:\winnt\sysvol\domain using the DNS name
rdsmertex.reflexdata.co.uk. FRS will keep

Following are some of the reasons you would see
this warning.
[1] FRS can not correctly resolve the DNS name
rdsmertex.reflexdata.co.uk from this computer.
[2] FRS is not running on
rdsmertex.reflexdata.co.uk.

[3] The topology information in the Active
Directory for this replica has not yet replicated
to all the Domain Controllers.
This event log message will appear once per
connection, After the problem is fixed you will
see another event log message indicating that the
connection has been established.
An Warning Event occured. EventID: 0x800034C5
Time Generated: 02/12/2007 17:43:51
Event String: The File Replication Service has enabled
replication from RDSMERTEX to DCMAIL1 for
c:\winnt\sysvol\domain after repeated retries.
An Warning Event occured. EventID: 0x800034FC
Time Generated: 02/21/2007 02:46:11
Event String: The File Replication Service has detected
that
the volume holding the FRS debug logs is running
out of disk space. This will not affect
replication unless this volume hosts database,
staging, or replica root paths as well.
Path to the logs directory = C:\WINNT\debug
You can change the number and size of logs by
adjusting the following registry values. Sample
values are shown below. These values are under
the registry key


Debug Log Files REG_DWORD 0x5
Debug Log Severity REG_DWORD 0x2
Debug Maximum Log Messages REG_DWORD 0x2710
You can also change the path to the logs
directory by changing the following value at the
same location.
Debug Log File REG_SZ windir\debug
Changes to the registry values will take affect
at the next polling cycle.
......................... DCMAIL1 passed test frssysvol
Starting test: systemlog
* The System Event log test
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:02:23
Event String: The JET Database call returned the following
error : -1808. Additional Debug Information:
JetBackup.
An Error Event occured. EventID: 0x000003F8
Time Generated: 02/21/2007 08:02:23
Event String: The DHCP service encountered the following
error
when backing up the database:
An error occurred while accessing the DHCP database. Look at the
DHCP server event log for more information on this error.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
DhcpJetCommitUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
RemoveClientEntry:Delete.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:44
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:48
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:55
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:37:12
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
......................... DCMAIL1 failed test systemlog
I also got this message from Netdiag
The DNS registration for dcmail1.reflexdata.co.uk is correct on
all DNS servers
Check the DNS registration for DCs entries on DNS server
'192.9.200.14'
The Record is different on DNS server '192.9.200.14'.
DNS server has more than one entries for this name, usually this means
there are multiple DCs for this domain.
Your DC entry is one of them on DNS server '192.9.200.14', no need to
re-register.
Please can you explain what these mean.

Sent using the Microsoft Entourage 2004 for Mac Test Drive.- Hide quoted text -

- Show quoted text -

To follow on from this the problem does not appear to be a dns
problem, I have logged a call with MS and they have been working on it
for around four days so far.

They think there is a permission key missing and are hoping to resolve
it soon.

When they do I will post the answer here as it might come in handy to
someone else in the future.

Anthony
 
Did you check all DNS server to ensure all Host (A) records and machines
names are properly aligned?
Did you recently promote a server that is generating the error?
Are you sites and services properly configured?
Gene Vinyard
On 2/21/07 4:30 AM, in article
(e-mail address removed), "alamb200"
Hi
I have the results of the DCDIAG there were some errors I have added
these below this text
Starting test: frssysvol
* The File Replication Service Event log test
The registry lookup failed to determine the state of
the SYSVOL. Using the systems event log instead.
The SYSVOL has been shared, and the AD is no longer
prevented from starting by the File Replication Service.
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
An Warning Event occured. EventID: 0x800034C4
Time Generated: 02/12/2007 17:43:00
Event String: The File Replication Service is having
trouble
enabling replication from RDSMERTEX to DCMAIL1
for c:\winnt\sysvol\domain using the DNS name
rdsmertex.reflexdata.co.uk. FRS will keep
retrying.
Following are some of the reasons you would see
this warning.
[1] FRS can not correctly resolve the DNS name
rdsmertex.reflexdata.co.uk from this computer.
[2] FRS is not running on
rdsmertex.reflexdata.co.uk.
[3] The topology information in the Active
Directory for this replica has not yet replicated
to all the Domain Controllers.
This event log message will appear once per
connection, After the problem is fixed you will
see another event log message indicating that the
connection has been established.
An Warning Event occured. EventID: 0x800034C5
Time Generated: 02/12/2007 17:43:51
Event String: The File Replication Service has enabled
replication from RDSMERTEX to DCMAIL1 for
c:\winnt\sysvol\domain after repeated retries.
An Warning Event occured. EventID: 0x800034FC
Time Generated: 02/21/2007 02:46:11
Event String: The File Replication Service has detected
that
the volume holding the FRS debug logs is running
out of disk space. This will not affect
replication unless this volume hosts database,
staging, or replica root paths as well.
Path to the logs directory = C:\WINNT\debug
You can change the number and size of logs by
adjusting the following registry values. Sample
values are shown below. These values are under
the registry key
"HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/
Services/NtFrs/Parameters
Debug Log Files REG_DWORD 0x5
Debug Log Severity REG_DWORD 0x2
Debug Maximum Log Messages REG_DWORD 0x2710
You can also change the path to the logs
directory by changing the following value at the
same location.
Debug Log File REG_SZ windir\debug
Changes to the registry values will take affect
at the next polling cycle.
......................... DCMAIL1 passed test frssysvol
Starting test: systemlog
* The System Event log test
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:02:23
Event String: The JET Database call returned the following
error : -1808. Additional Debug Information:
JetBackup.
An Error Event occured. EventID: 0x000003F8
Time Generated: 02/21/2007 08:02:23
Event String: The DHCP service encountered the following
error
when backing up the database:
An error occurred while accessing the DHCP database. Look at the
DHCP server event log for more information on this error.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
DhcpJetCommitUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:43
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
RemoveClientEntry:Delete.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:44
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:48
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:36:55
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
An Error Event occured. EventID: 0x000003F6
Time Generated: 02/21/2007 08:37:12
Event String: The JET Database call returned the following
error : -529. Additional Debug Information:
CreateClientEntry:JetUpdate.
......................... DCMAIL1 failed test systemlog
I also got this message from Netdiag
The DNS registration for dcmail1.reflexdata.co.uk is correct on
all DNS servers
Check the DNS registration for DCs entries on DNS server
'192.9.200.14'
The Record is different on DNS server '192.9.200.14'.
DNS server has more than one entries for this name, usually this means
there are multiple DCs for this domain.
Your DC entry is one of them on DNS server '192.9.200.14', no need to
re-register.
Please can you explain what these mean.
Thanks
alamb200
On 16 Feb, 14:06, "Paul Bergson [MVP-DS]" <pbergson@allete_nospam.com>
wrote:
What kind of errors did you get? Were there any messages in the Event Log?
Run diagnostics against your Active Directory domain.
If you don't have the tools installed, install them from your server install
disk.
d:\support\tools\setup.exe
Run dcdiag, netdiag and repadmin in verbose mode.
-> DCDIAG /V /C /D /E /s:yourdcname > c:\dcdiag.log
-> netdiag.exe /v > c:\netdiag.log (On each dc)
-> repadmin.exe /showrepl dc* /verbose /all /intersite > c:\repl.txt
**Note: Using the /E switch in dcdiag will run diagnostics against ALL dc's
in the forest. If you have significant numbers of DC's this test could
generate significant detail and take a long time. You also want to take
into account slow links to dc's will also add to the testing time.
If you download a gui script I wrote it should be simple to set and run
(DCDiag and NetDiag). It also has the option to run individual tests
without having to learn all the switch options. The details will be output
in notepad text files that pop up automagically.
The script is located in the download section on my website
athttp://www.pbbergs.com
Just select both dcdiag and netdiag make sure verbose is set. (Leave the
default settings for dcdiag as set when selected)
When complete search for fail, error and warning messages.
--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT
http://www.pbbergs.com
Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

Hi,
We have two servers on our network a Windows 2000 server with
Exchange
and a Windows 2003 server. The Windows 2000 server is the main server
for the network with the 2003 server added later.
All was fine until recently when I was trying to edit the Default
Group Policy from the Windows 2003 server but I was unable to do so I
could only look at its properties. I was also trying to install
Serveraid software but I did not have permission to add the service
even though I was logged on as the Administrator.
I did a DCPROMO down on the 2003 server then back up again to try and
resolve it but it made no difference.
Has anyone got any ideas what is going wrong.
Please help.
Thanks
alamb200- Hide quoted text -
- Show quoted text -
Sent using the Microsoft Entourage 2004 for Mac Test Drive.- Hide quoted text -
- Show quoted text -

To follow on from this the problem does not appear to be a dns
problem, I have logged a call with MS and they have been working on it
for around four days so far.

They think there is a permission key missing and are hoping to resolve
it soon.

When they do I will post the answer here as it might come in handy to
someone else in the future.

Anthony- Hide quoted text -

- Show quoted text -

Right this is fixed.

According to MS this was caused by running in Native mode while not
having the PDC emulator running on the Windows 2003 server.

They swapped this accross and now all looks okay.

I hope this helps someone in the future.

alamb200
 
Back
Top