DNS problems - can't register test record

470 views
Skip to first unread message

Mike Leone

unread,
Feb 2, 2022, 11:05:30 AM2/2/22
to NTSysAdmin
Hoping someone can help. While running dcdiag (/c /v) today, one of my DCs is reporting this:

                  Warning: Failed to add the test record dcdiag-test-record in zone ads.pha.phila.gov
                  [Error details: -1 (Type: Win32 - Description: (unknown))]

The odd thing is that it's only 1 of the 5 in the domain that is having a problem.

I've verified that the zone is set for Dynamic updates to be Secure only (searches seem to indicate that setting "secure and non-secure" may cause this). Replication is fine, no errors.

The DNS settings on the NIC are the same as all DCS:

Primary DNS = other DC
Secondary DNS = itself (it's IP)
Tertiary DNS = 127.0.0.1

I tried "nltest /dsregdns"; that said it completed successfully. I looked in the event log of this server, didn't see any DNS errors like this.

At this point I'm stumped. Anyone have any suggestions? Since this test passes on 4 DCs, I know that the zone allows it. So it should allow it for this server, too ...

--

Mike. Leone, <mailto:tur...@mike-leone.com>

PGP Fingerprint: 0AA8 DC47 CB63 AE3F C739 6BF9 9AB4 1EF6 5AA5 BCDF
Photo Gallery: <http://www.flickr.com/photos/mikeleonephotos>

This space reserved for future witticisms ...

James Iversen

unread,
Feb 2, 2022, 11:36:00 AM2/2/22
to ntsys...@googlegroups.com
DNS does not register the 127.0.0.1 address.
James Iversen
Network Systems Analyst
IT Infrastructure


 
 


1899 Central Plaza East
Edmeston, NY 13335
Phone: (607) 965-2706

nycm.com






From:        "Mike Leone" <tur...@mike-leone.com>
To:        "NTSysAdmin" <ntsys...@googlegroups.com>
Date:        02/02/2022 11:05 AM
Subject:        [ntsysadmin] DNS problems - can't register test record
Sent by:        ntsys...@googlegroups.com





ATTENTION: This email was sent from someone outside of NYCM.
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2BjqX5K6tQ2f%2BoUYCiuxYet75rLocRvijY8JH0i8j6_EGA%40mail.gmail.com.









Join us on Facebook at
www.facebook.com/NYCMInsurance.


***CONFIDENTIALITY NOTICE***

This email and any attachments to it are confidential and intended solely for the individual or entity to whom it is addressed. Any unauthorized review, use, disclosure or distribution is prohibited. If you have received this email in error, please contact the sender by reply email and destroy all copies of the original message.




Mike Leone

unread,
Feb 2, 2022, 11:41:22 AM2/2/22
to ntsys...@googlegroups.com
On Wed, Feb 2, 2022 at 11:36 AM James Iversen <JIve...@nycm.com> wrote:
DNS does not register the 127.0.0.1 address.

OK ... but that doesn't explain why the test passes on the other 4 DCs, all of whom have 127.0.0.1 as the tertiary DNS setting ..


James Iversen

unread,
Feb 2, 2022, 11:45:34 AM2/2/22
to ntsys...@googlegroups.com
Guess I am missing the IP address of the test machine then.


Join us on Facebook at

www.facebook.com/NYCMInsurance.




***CONFIDENTIALITY NOTICE***

This email and any attachments to it are confidential and intended solely for the individual or entity to whom it is addressed. Any unauthorized review, use, disclosure or distribution is prohibited. If you have received this email in error, please contact the sender by reply email and destroy all copies of the original message.



--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/ntsysadmin/OF53287CA9.C53EB3C1-ON852587DD.005B26BD-852587DD.005B2EF7%40nycm.com.




--

Mike. Leone, <mailto:
tur...@mike-leone.com>

PGP Fingerprint: 0AA8 DC47 CB63 AE3F C739 6BF9 9AB4 1EF6 5AA5 BCDF
Photo Gallery: <
http://www.flickr.com/photos/mikeleonephotos>

This space reserved for future witticisms ...

--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com
.
To view this discussion on the web visit
https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2BjuBr2UXgpXGrVOM4Jj25z5wKZgBigxaCAoY4h%2Bqp57kA%40mail.gmail.com.

Mike Leone

unread,
Feb 2, 2022, 11:57:08 AM2/2/22
to ntsys...@googlegroups.com
On Wed, Feb 2, 2022 at 11:45 AM James Iversen <JIve...@nycm.com> wrote:
Guess I am missing the IP address of the test machine then.

I don't understand what you are asking here, I'm sorry. :-) I am not specifying an IP address to test with, this is just a test that the dcdiag program runs. I don't know what IP address, if any, that it is trying to register. I just know that this test fails on 1 DC, and passes on the others, yet the configuration seems to be the same on all 5. So I don't know what is causing this test to fail ..

The eventual plan is to demote al lWin 2012 R2 DCs (such as this one), leaving only the WIn 2019 DCs, so that I can raise the DFL/FFL to Win 2019. But I don't want to do that, unless the dcdiag runs cleanly on all servers that should be demoted ...


Reply all
Reply to author
Forward
0 new messages