Sep 11 2019 04:45 AM
I have three DNS errors and a large number of warnings which I cannot resolve. There is also a problem with Windows Time which cannot resolve the time server and defaults to the CMOS clock.
There is only one ethernet adaptor:
IPConfig/all gives:
Windows IP Configuration
Host Name . . . . . . . . . . . . : XXX-Server
Primary Dns Suffix . . . . . . . : XXX.local
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : XXX.local
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) I210 Gigabit Network Connection
Physical Address. . . . . . . . . : AC-1F-6B-6A-2F-F5
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::f8db:3ccb:4fb6:a153%12(Preferred)
IPv4 Address. . . . . . . . . . . : 10.0.0.100(Preferred)
Subnet Mask . . . . . . . . . . . : 255.0.0.0
Default Gateway . . . . . . . . . : 10.0.0.1
DHCPv6 IAID . . . . . . . . . . . : 61611883
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-22-E0-CA-14-AC-1F-6B-6A-2F-F5
DNS Servers . . . . . . . . . . . : 10.0.0.100
127.0.0.1
NetBIOS over Tcpip. . . . . . . . : Enabled
Tunnel adapter isatap.{7E07F518-866F-449E-8032-3F6AAF177C0F}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
DCDiag /test:dns gives:
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = XXX-Server
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\XXX-Server
Starting test: Connectivity
......................... XXX-SERVER passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\XXX-SERVER
Starting test: DNS
DNS Tests are running and not hung. Please wait a few minutes...
......................... XXX-SERVER passed test DNS
Running partition tests on : ForestDnsZones
Running partition tests on : DomainDnsZones
Running partition tests on : Schema
Running partition tests on : Configuration
Running partition tests on : XXX
Running enterprise tests on : XXX.local
Starting test: DNS
Test results for domain controllers:
DC: XXX-Server.XXX.local
Domain: XXX.local
TEST: Dynamic update (Dyn)
Warning: Failed to delete the test record dcdiag-test-record in zone XXX.local
XXX-Server PASS PASS PASS PASS WARN PASS n/a
......................... XXX.local passed test DNS
Any help gratefully received.
Sep 11 2019 06:15 AM - edited Sep 11 2019 01:47 PM
There is only one ethernet adaptor:
If this were the PDC emulator then time would / should be sync'd to either a hardware clock or possibly an external known source.
w32tm /unregister
net stop w32time
w32tm /register
net start w32time
w32tm /config /manualpeerlist:xxx.xxx.xxx.xxx /syncfromflags:manual /reliable:yes /update
net stop w32time
net start w32time
then check
w32tm /query /source
w32tm /query /configuration
(replace xxx.xxx.xxx.xxx with desired source)
https://tf.nist.gov/tf-cgi/servers.cgi
If you're using integration services Time synchronization box checked then this overrides NT5DS and makes the source come from the hypervisor host only.
All domain members should use NT5DS domain time. Desktops and member servers will sync with any domain controller. Domain controllers sync with PDC emulator, PDCe syncs with either a hardware clock or possibly an external source.
Sep 12 2019 04:54 AM
Thanks very much @Dave Patrick for your reply. Unfortunately the time sync didn't work. I think there is a slight sequence error in the commands. So I have changed the unregister command to be after the net stop command. I have changed the time server IP to 3.uk.pool.ntp.org which pings successfully.
The serious issue as I see it are the DNS errors. I suppose I can always set the CMOS clock accurately occasionally but any further assistance in resolving the NTP issue gratefully received..
Results below:
Sep 12 2019 05:20 AM - edited Sep 12 2019 05:22 AM
No, the sequence is correct. You can ignore errors depending on the state of service. From the results above the time configuration is being overridden by a policy. However if you're moving on to other issues then please run;
Sep 12 2019 02:58 PM
Content not anonymised. Link herewith:
https://1drv.ms/u/s!AmMne01oSBYoixayALNeAxb9e8Dt?e=izuUW9
Thanks again.
Sep 12 2019 03:27 PM
Looks Ok to me. I'd suggest removing the router address as forwarder. There are quite a number of DCOM errors in system event log that may need attention. As to anything DNS I'd check the system event log for related errors since last boot.
Sep 21 2019 03:55 AM
Sep 21 2019 05:57 AM
For any errors reported I'd check the system event log for more details.
Sep 24 2019 01:56 PM