only 1 of 3 dcs allow logon


i have 2003 network 1 2003 sp2 dc , 2 2008r2 dcs.  global catlogue, dns-integrated.  when 1 2003 dc taken off line, no one(user or administrator) can log on domain.  fsmo operators on 1 of 2008r2 dcs. can't proceed upgrade 2008r2 without dcs functioning correctly , authenticating logons.  have been wrestling 10 days no luck.  body got ideas?

the authentication performed dc locate dc dns required. considering earlier dc windows 2003 & transferred windows 2008 r2, did make new 2008 r2 dc time server too, if not have because dc holding pdc fsmo role should time server.

dns reason, considering windows 2003 servers dns has been defined in clients nic & when switch off same dc, clients can't find other available dc, since there no dns specified point clients new dc/dns authentication.specify, domain clients(systems/servers/applications) point windows 2008 r2 machine in nic preferred dns server & alternate dns server other dc's in network. use local dns in clients dc system in nic, no public ip or other ip defined.

make sure windows 2008 r2 dc's not multihomed(dc's multiple live ip nic), multihomed dc not recommended. verify dc's health using dcdiag replication using repadmin /replsummary.

 

regards  


awinish vishwakarma

mvp-directory services

my blog:  http://awinish.wordpress.com 

this posting provided as-is no warranties/guarantees , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group