Unable to create DNS Records on 2 of 3 DCs


we have 3 dcs, 2 @ our hq, , 1 @ our dr site.

2 dcs @ our hq server 2008 r2 sp1 standard,  1 dc @ our dr site server 2008 sp2.

whenever try create new dns record on either 1 of 2 dcs @ our hq following error:

dns
---------------------------
host record testing.ourdomain.local cannot created.
refused
---------------------------
ok   

i checked event viewer , found following:

event id 4015 - dns-server-services

dns server has encountered critical error active directory. check active directory functioning properly. extended error debug information (which may empty) "0000051b: atrerr: dsid-030f1f8d, #1:

0: 0000051b: dsid-030f1f8d, problem 1005 (constraint_att_type), data 0, att 20119 (ntsecuritydescriptor)". event data contains error.

dcdiag /test:dns results on 3 dcs , 2 dcs @ hq can't create dns records on both pass without errors.   1 server @ our dr site 1 throws errors , errors follow:

______________________________________


directory server diagnosis


performing initial setup:

   trying find home server...

   home server = dr-dc-01s

   * identified ad forest. 
   done gathering initial info.


doing initial required tests

   
   testing server: our-company-dr\dr-dc-01s

      starting test: connectivity

         ......................... dr-dc-01s passed test connectivity



doing primary tests

   
   testing server: our-company-dr\dr-dc-01s

   
      starting test: dns

         

         dns tests running , not hung. please wait few minutes...

         ......................... dr-dc-01s passed test dns

   
   running partition tests on : forestdnszones

   
   running partition tests on : domaindnszones

   
   running partition tests on : schema

   
   running partition tests on : configuration

   
   running partition tests on : ourcompany

   
   running enterprise tests on : ourcompany.local

      starting test: dns

         test results domain controllers:

            
            dc: dr-dc-01s.ourcompany.local

            domain: ourcompany.local

            

                  
               test: basic (basc)
                  warning: aaaa record dc not found
                  
               test: records registration (rreg)
                  network adapter

                  [00000012] broadcom bcm5709c netxtreme ii gige (ndis vbd client):

                  

                     warning: 
                     missing aaaa record @ dns server 192.168.hq.23: 
                     dr-dc-01s.ourcompany.local
                     
                     warning: 
                     missing aaaa record @ dns server 192.168.hq.23: 
                     gc._msdcs.ourcompany.local
                     
                     warning: 
                     missing aaaa record @ dns server 192.168.hq.22: 
                     dr-dc-01s.ourcompany.local
                     
                     warning: 
 
                     missing aaaa record @ dns server 192.168.hq.22: 
                     gc._msdcs.ourcompany.local
                     
                     warning: 
                     missing aaaa record @ dns server 192.168.dr.51: 
                     dr-dc-01s.ourcompany.local
                     
                     warning: 
                     missing aaaa record @ dns server 192.168.dr.51: 
                     gc._msdcs.ourcompany.local
                     
               warning: record registrations not found in network adapters

         
               dr-dc-01s                   pass warn pass pass pass warn n/a  
         ......................... ourcompany.local passed test dns

_____________________________________________________________________________________________

for it's not emergency, need fix.   other directory services seem functioning correctly , i've done ton of googling , searching try figure out how fix this, haven't found right resource yet.   can create new dns records logging onto our dr server , creating dns records there, waiting few minutes changes replicate other dcs, no means permanent solution.

if have suggestions on how fix or suggestions on at/for next i'm ears.


i called ms support , opened case.   called few hours later, got connected , took look.   changed "dynamic updates" on ourdomain.local "secure only" "nonsecure , secure" , able create new dns records.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B

DFSR RPC replication errors 5014 1726 with large files over VPN