After restoring the system state backup Netlog on issues


hi,

after restoring system state backup not able access shares on machine. have restored system sate on bdc

here dcdiag report of problem server

c:\documents , settings\administrator.cit\desktop>dcdiag.exe

domain controller diagnosis

performing initial setup:
   done gathering initial info.

doing initial required tests

   testing server: default-first-site\matrix
      starting test: connectivity
         ......................... matrix passed test connectivity

doing primary tests

   testing server: default-first-site\matrix
      starting test: replications
         replication latency warning
         error: expected notification link missing.
         source jacana
         replication of new changes along path delayed.
         problem should self-correct on next periodic sync.
         replication latency warning
         error: expected notification link missing.
         source jacana
         replication of new changes along path delayed.
         problem should self-correct on next periodic sync.
         replication latency warning
         error: expected notification link missing.
         source jacana
         replication of new changes along path delayed.
         problem should self-correct on next periodic sync.
         ......................... matrix passed test replications
      starting test: ncsecdesc
         ......................... matrix passed test ncsecdesc
      starting test: netlogons
         unable connect netlogon share! (\\matrix\netlogon)
         [matrix] net use or lsapolicy operation failed error 1203, no n
etwork provider accepted given network path..
         ......................... matrix failed test netlogons
      starting test: advertising
         warning: dsgetdcname returned information \\jacana.couthit.local, w
hen trying reach matrix.
         server not responding or not considered suitable.
         ......................... matrix failed test advertising
      starting test: knowsofroleholders
         ......................... matrix passed test knowsofroleholders
      starting test: ridmanager
         ......................... matrix passed test ridmanager
      starting test: machineaccount
         ......................... matrix passed test machineaccount
      starting test: services
         ......................... matrix passed test services
      starting test: objectsreplicated
         ......................... matrix passed test objectsreplicated
      starting test: frssysvol
         ......................... matrix passed test frssysvol
      starting test: frsevent
         there warning or error events within last 24 hours after the
         sysvol has been shared.  failing sysvol replication problems may cause
         group policy problems.
         ......................... matrix failed test frsevent
      starting test: kccevent
         ......................... matrix passed test kccevent
      starting test: systemlog
         error event occured.  eventid: 0x40000004
            time generated: 07/12/2010   17:42:28
            event string: kerberos client received a
         error event occured.  eventid: 0x0000168f
            time generated: 07/12/2010   17:42:28
            event string: dynamic deletion of dns record
         error event occured.  eventid: 0x0000168f
            time generated: 07/12/2010   17:42:28
            event string: dynamic deletion of dns record
         error event occured.  eventid: 0x0000168f
            time generated: 07/12/2010   17:42:28
            event string: dynamic deletion of dns record
         error event occured.  eventid: 0x0000168f
            time generated: 07/12/2010   17:42:28
            event string: dynamic deletion of dns record
         error event occured.  eventid: 0x0000168f
            time generated: 07/12/2010   17:42:28
            event string: dynamic deletion of dns record
         error event occured.  eventid: 0x0000168f
            time generated: 07/12/2010   17:42:28
            event string: dynamic deletion of dns record
         error event occured.  eventid: 0x0000168f
            time generated: 07/12/2010   17:42:28
            event string: dynamic deletion of dns record
         error event occured.  eventid: 0x40000004
            time generated: 07/12/2010   17:42:39
            event string: kerberos client received a
         error event occured.  eventid: 0x40000004
            time generated: 07/12/2010   17:46:10
            event string: kerberos client received a
         error event occured.  eventid: 0x40000004
            time generated: 07/12/2010   17:53:16
            event string: kerberos client received a
         error event occured.  eventid: 0x40000004
            time generated: 07/12/2010   18:22:07
            event string: kerberos client received a
         error event occured.  eventid: 0x40000004
            time generated: 07/12/2010   18:31:33
            event string: kerberos client received a
         ......................... matrix failed test systemlog
      starting test: verifyreferences
         ......................... matrix passed test verifyreferences

   running partition tests on : forestdnszones
      starting test: crossrefvalidation
         ......................... forestdnszones passed test crossrefvalidation

      starting test: checksdrefdom
         ......................... forestdnszones passed test checksdrefdom

   running partition tests on : domaindnszones
      starting test: crossrefvalidation
         ......................... domaindnszones passed test crossrefvalidation

      starting test: checksdrefdom
         ......................... domaindnszones passed test checksdrefdom

   running partition tests on : schema
      starting test: crossrefvalidation
         ......................... schema passed test crossrefvalidation
      starting test: checksdrefdom
         ......................... schema passed test checksdrefdom

   running partition tests on : configuration
      starting test: crossrefvalidation
         ......................... configuration passed test crossrefvalidation
      starting test: checksdrefdom
         ......................... configuration passed test checksdrefdom

   running partition tests on : couthit
      starting test: crossrefvalidation
         ......................... couthit passed test crossrefvalidation
      starting test: checksdrefdom
         ......................... couthit passed test checksdrefdom

   running enterprise tests on : couthit.local
      starting test: intersite
         ......................... couthit.local passed test intersite
      starting test: fsmocheck
         ......................... couthit.local passed test fsmocheck

 

i have run netdom command reset password..

could please me on issue

 

thanks

ramesh

 

 

 

 

 

hi ramehs,

thank update. based on current situation, please refer steps below , make sure secure channel reset correctly.

1. download klist.exe problem domain controllers if necessary.
 
note:
perform following steps on dc's failing pull replication (downstream dcs). dc pulling replication should chosen keep kdc running.  if dcs failing pull replication, choose 1 dc , not turn off kdc there. pdce chosen keep kdc running unless failing dc , dc is  pulling replication without issue.

2. stop kdc service:
c:\>net stop kdc
3. purge user's kerberos tickets using klist.
c:\>klist purgeall
or
c:\>klist purge
(enter 'y' confirm purging of each ticket)

4. start command prompt localsystem account using scheduler service.
c:\>at system_time /interfactive cmd.exe
(where system_time should replaced current local time plus 1 minute)

5. at scheduled time new command line window open using system account. purge system tickets window via these steps:
 
note:
window opens on console session. not appear if have ts session dc.

6. purge user's , machine's kerberos tickets using klist.
c:\>klist purgeall
or
c:\>klist purge
(enter 'y' confirm purging of each ticket)

7. reset secure channel domain controllers failing pull replication domain controller has kdc service running.
c:\>netdom resetpwd /server:pdce /userd:domain\admin_account /passwordd:*
type password associated domain user.
 
note:
domain controller chosen have kdc service running referred pdce step forward. however, machine not need pdc emulator.

8. access pdce fqdn force problem dc's request new kerberos tickets
c:\>net use \\mypdce.mydomain.com\ipc$

9. force domain controller replicate pdce using ad sites , services
 
note:
force replication pdce problem domain controllers.
attempting replicate problem domain controllers pdce fail.

10. perform following steps on pdce only.
11. open ad sites , services.
12. select pdce server, , select ntds settings.
13. delete inbound connection objects problem domain controllers
14. start kcc
c:\>repadmin /kcc

after steps, there progress? if not, please collect dcdiag logs again research.

thanks.


this posting provided "as is" no warranties, , confers no rights. please remember click "mark answer" on post helps you, , click "unmark answer" if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client