'Missing' Domain Controllers on startup


ok, have weird issue here. 2 sites, 3 dc's in each site (1 physical, 2 virtual).

site absolutely fine, site b member servers , client pcs report in event viewer;

level: error
source: netlogon
event id: 5719
description: computer not able set secure session domain controller in domain <domain> due following:
there no logon servers available service logon request.
may lead authentication problems. make sure computer connected network. if problem persists, please contact domain administrator. 

additional info
if computer domain controller specified domain, sets secure session primary domain controller emulator in specified domain. otherwise, computer sets secure session domain controller in specified domain.

level: error
source: grouppolicy
event id: 1129
description: processing of group policy failed because of lack of network connectivity domain controller. may transient condition. success message generated once machine gets connected domain controller , group policy has succesfully processed. if not see success message several hours, contact administrator.

now worried, except logging on fine, using computers fine. it's if there's problem before offering ctrl + alt + del prompt fine.

except because of machines in site not software deployed them through group policy.

i have tried:

removing , rejoining domain
static ip address
changing switches
re-installing windows on pc
moving fsmo roles dc in 'problem' site
meta-data cleanup using ntdsutil (couldn't no missing dcs detected)

member servers affected.

below ports should opened in dcs ad/dns.

service

port/protocol

rpc endpoint mapper

135/tcp, 135/udp

network basic input/output system (netbios)   name service

137/tcp, 137/udp

netbios datagram service

138/udp

netbios session service

139/tcp

rpc dynamic assignment

win 2k/2003:1024-65535/tcp
  win 2008+:49152-65535/tcp
 

server message block (smb) on ip   (microsoft-ds)

445/tcp, 445/udp

lightweight directory access protocol (ldap)

389/tcp

ldap ping

389/udp

ldap on ssl

636/tcp

global catalog ldap

3268/tcp

global catalog ldap on ssl

3269/tcp

kerberos

88/tcp, 88/udp

domain name service (dns)

53/tcp1, 53/udp

use port query that.
http://www.microsoft.com/en-in/download/details.aspx?id=17148

also disable windows firewall in dcs.


regards
biswajit biswas

my blogs|mcc |tnwiki ninja

best regards biswajit biswas disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. mcp 2003,mcsa 2003, mcsa:m 2003, ccna, mcts, enterprise admin




Windows Server  >  Directory Services



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...