DNS Simple Query Fails on Windows 2003 and Windows 2008 DCs
Hi to all ,I have very strange problems with my DNS server .The situation is like this:We have two DCs in one Forest -DC1 and DC2 (for example) DC1 and DC2 replicates AD data with no problems,DNS zones too but when i test DNS server with Simple Query the status is fail .The Active Directory zone is domain.local (for example) but this is for about 6-7 months .Before that someone was named the create zone like this domain.subdomain.Externaldomainname.net .We decide that renaming the Domain Zone from domain.subdomain.Externaldomainname.net to domain.local ( reason Unknown) So someone of my colleagues read article like this http://techrepublic.com.com/5208-6230-0.html?forumID=102&threadID=229757&start=0and starts renaming the domain DNS zone.At this situation there was only One DC at the forest ,the seccong DC2 was added after renaming. The renaming was complete successfully according to DCDIAG tests and my colleague.Few months no one looks this servers how works.No one tests for errors ,the old Backup was replaced by new. New users and computers was added to AD and works fine.GPO works too.One day we found that the Simple Query does not works .Then immedietly starts resolving this issue.We've tryed i think anything - Reinstall DNS Servers ,delelete and recreate DNS Zones,DC Demote and DC Promote but issue persist.Here is DCDIAG output
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\DC1
Starting test: Connectivity
......................... DC1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\DC1
Starting test: Replications
......................... DC1 passed test Replications
Starting test: NCSecDesc
......................... DC1 passed test NCSecDesc
Starting test: NetLogons
......................... DC1 passed test NetLogons
Starting test: Advertising
......................... DC1 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... DC1 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... DC1 passed test RidManager
Starting test: MachineAccount
......................... DC1 passed test MachineAccount
Starting test: Services
......................... DC1 passed test Services
Starting test: ObjectsReplicated
......................... DC1 passed test ObjectsReplicated
Starting test: frssysvol
......................... DC1 passed test frssysvol
Starting test: frsevent
......................... DC1 passed test frsevent
Starting test: kccevent
......................... DC1 passed test kccevent
Starting test: systemlog
......................... DC1 passed test systemlog
Starting test: VerifyReferences
......................... DC1 passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : domain
Starting test: CrossRefValidation
......................... domain passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... domain passed test CheckSDRefDom
Running enterprise tests on : domain.local
Starting test: Intersite
......................... domain.local passed test Intersite
Starting test: FsmoCheck
......................... domain.local passed test FsmoCheck
Here is the dcdiag /test:DNS output
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\DC1
Starting test: Connectivity
......................... DC1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\DC1
DNS Tests are running and not hung. Please wait a few minutes...
Running partition tests on : ForestDnsZones
Running partition tests on : DomainDnsZones
Running partition tests on : Schema
Running partition tests on : Configuration
Running partition tests on : domain
Running enterprise tests on : domain.local
Starting test: DNS
Test results for domain controllers:
DC: DC1.domain.local
Domain: domain.local
TEST: Basic (Basc)
Warning: adapter [00000001] Intel(R) PRO/1000 MT Network Connection has invalid DNS server: 192.168.57.2 (<name unavailable>)
Warning: adapter [00000001] Intel(R) PRO/1000 MT Network Connection has invalid DNS server: 192.168.57.202 (<name unavailable>)
Error: all DNS servers are invalid
TEST: Forwarders/Root hints (Forw)
Error: Root hints list has invalid root hint server: a.root-servers.net. (198.41.0.4)
Error: Root hints list has invalid root hint server: b.root-servers.net. (192.228.79.201)
Error: Root hints list has invalid root hint server: c.root-servers.net. (192.33.4.12)
Error: Root hints list has invalid root hint server: d.root-servers.net. (128.8.10.90)
Error: Root hints list has invalid root hint server: e.root-servers.net. (192.203.230.10)
Error: Root hints list has invalid root hint server: f.root-servers.net. (192.5.5.241)
Error: Root hints list has invalid root hint server: g.root-servers.net. (192.112.36.4)
Error: Root hints list has invalid root hint server: h.root-servers.net. (128.63.2.53)
Error: Root hints list has invalid root hint server: i.root-servers.net. (192.36.148.17)
Error: Root hints list has invalid root hint server: j.root-servers.net. (192.58.128.30)
Error: Root hints list has invalid root hint server: k.root-servers.net. (193.0.14.129)
Error: Root hints list has invalid root hint server: l.root-servers.net. (199.7.83.42)
Error: Root hints list has invalid root hint server: m.root-servers.net. (202.12.27.33)
TEST: Dynamic update (Dyn)
Warning: Dynamic update is enabled on the zone but not secure domain.local.
TEST: Records registration (RReg)
Error: Record registrations cannot be found for all the network adapters
Summary of test results for DNS servers used by the above domain controllers:
DNS server: 128.63.2.53 (h.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 128.63.2.53
DNS server: 128.8.10.90 (d.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 128.8.10.90
DNS server: 192.112.36.4 (g.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.112.36.4
DNS server: 192.168.57.2 (<name unavailable>)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.168.57.2
DNS server: 192.168.57.202 (<name unavailable>)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.168.57.202
DNS server: 192.203.230.10 (e.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.203.230.10
DNS server: 192.228.79.201 (b.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.228.79.201
DNS server: 192.33.4.12 (c.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.33.4.12
DNS server: 192.36.148.17 (i.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.36.148.17
DNS server: 192.5.5.241 (f.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.5.5.241
DNS server: 192.58.128.30 (j.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 192.58.128.30
DNS server: 193.0.14.129 (k.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 193.0.14.129
DNS server: 198.41.0.4 (a.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 198.41.0.4
DNS server: 199.7.83.42 (l.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 199.7.83.42
DNS server: 202.12.27.33 (m.root-servers.net.)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 202.12.27.33
Summary of DNS test results:
Auth Basc Forw Del Dyn RReg Ext
________________________________________________________________
Domain: domain.local
DC1 PASS FAIL FAIL PASS WARN FAIL n/a
......................... domain.local failed test DNS
Now if the problem persist maybe i will try to bring up new Domain in different Forest and Migrate users from the one domain to another .I think that when we try to Deploy Exchange 2007 there will be problems with AD .Actually there is a Terminal Server in that domain that give us some errors in Terminal Licensing .Anyone with simmilar issue ? We do nat have any backup before renaming :) We was renaming another domain controller zone with no errors in different forest .edit: Nslookup Works fine
July 28th, 2009 12:24pm
Looking at the basic test. You ran this on one of the Domain Controllers, it reports invalid DNS ServersIntel(R) PRO/1000 MT Network Connection has invalid DNS server: 192.168.57.2 Is 192.168.57.2 a DNS server in your network?How about 192.168.57.202?1) Check your network adapter settings. Set the DC to use itself as a DNS server. 2) How about your DNS Server settings, do you have any forwarders set?3)Doesthe domainwork okanyway?4) Does any of the Domain Controllers reporterrors in EventLog?
Free Windows Admin Tool Kit Click here and download it now
October 18th, 2009 8:17pm
Hi Martin,Just checking to see if you have solved your issue?
October 25th, 2009 8:11pm
Yep .I was very simple error .The Simple Query actually test nslookuplocalhostserverIP (or 127.0.0.1)It seems that i do not have forwardresolve for name localhost.After creating the right Host A record LOCALHOST in my DNS zoneSimple query works fine.
Free Windows Admin Tool Kit Click here and download it now
November 19th, 2009 5:28pm