DNS Zone Errors - Active Directory Zone was not found/is not available

%3CLINGO-SUB%20id%3D%22lingo-sub-3273703%22%20slang%3D%22en-US%22%3EDNS%20Zone%20Errors%20-%20Active%20Directory%20Zone%20was%20not%20found%2Fis%20not%20available%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3273703%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20client%20that%20I%20am%20trying%20to%20clean%20up%20and%20straighten%20out%20their%20DNS.%26nbsp%3B%20Running%20the%20DCdiag%20DNS%20test%20and%20BPA%20on%20each%20server%20brings%20up%20a%20number%20of%20errors%2C%20and%20I%20am%20at%20my%20wit%E2%80%99s%20end%20trying%20to%20resolve%20them.%26nbsp%3B%20DNS%20seems%20to%20be%20functioning%20correctly%20for%20the%20time%20being%2C%20but%20I%20want%20to%20resolve%20any%20issues%20ahead%20of%20my%20next%20project.%3C%2FP%3E%3CUL%3E%3CLI%3EThe%20primary%20DNS%20Zone%20is%20called%20%E2%80%9Cdomain.com%E2%80%9D%3C%2FLI%3E%3CLI%3E%E2%80%9Cdomain.com%E2%80%9D%20is%20a%20parent%20domain%20with%202%20child%20domains%20%E2%80%93%20%E2%80%9Cchild1.domain.com%E2%80%9D%20and%20%E2%80%9Cchild2.domain.com%E2%80%9D%3C%2FLI%3E%3CLI%3EAll%20domains%20are%20contained%20in%20the%20Forest%20%E2%80%9Cdomain.com%E2%80%9D%20with%202-ways%20trusts%3C%2FLI%3E%3CLI%3EThere%20are%208%20total%20DCs%2FDNS%20servers%20%E2%80%93%203%20%E2%80%9Cdomain.com%E2%80%9D%2C%203%20%E2%80%9Cchild1.domain.com%E2%80%9D%20and%202%20%E2%80%9Cchild2.domain.com%E2%80%9D%3C%2FLI%3E%3CLI%3EDNS%20Zones%20are%20Active%20Directory%20Integrated%20(though%20I%20am%20skeptical%20for%20the%20child%20domains)%3C%2FLI%3E%3CLI%3EReplication%20is%20set%20to%20ALL%20DNS%20servers%20in%20this%20Forest%3C%2FLI%3E%3CLI%3EThere%20are%20no%20conditional%20forwarders%20configured%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20Practices%20Analyzer%20Results%3C%2FP%3E%3CUL%3E%3CLI%3EError%20DNS%3A%26nbsp%3B%20The%20DNS%20Server%20%3CIPADDRESSOFCLIENTDNS%3E%20on%20%3CPRIMARYNIC%3E%20must%20resolve%20names%20in%20the%20primary%20DNS%20domain%20zone%20(error%20occurs%20for%20each%20DNS%20Server%20configured%20on%20the%20NIC).%3C%2FPRIMARYNIC%3E%3C%2FIPADDRESSOFCLIENTDNS%3E%3C%2FLI%3E%3CLI%3EError%20DNS%3A%26nbsp%3B%20Zone%20%3CCHILD1%20or%3D%22%22%20child2%3D%22%22%3E.domain.com%20is%20an%20Active%20Directory%20integrated%20DNS%20Zone%20and%20must%20be%20available.%3C%2FCHILD1%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThere%20are%20no%20BPA%20errors%20on%20the%203%20parent%20%E2%80%9Cdomain.com%E2%80%9D%20servers%2C%20only%20the%20%E2%80%9Cchild1%E2%80%9D%20and%20%E2%80%9Cchild2%E2%80%9D%20servers.%3C%2FP%3E%3CP%3EEach%20DC%2FDNS%20server%20has%20a%20single%20NIC%2C%20single%20IP%20address.%26nbsp%3B%20The%20client%20DNS%20servers%20are%20pointed%20at%20opposing%20DC%2FDNS%20servers%20within%20the%20same%20domain%20and%20the%20loopback%20is%20configured%20as%20a%20third%20option.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDCDiag%20DNS%20Test%20Results%3C%2FP%3E%3CUL%3E%3CLI%3EThe%20SOA%20record%20for%20the%20Active%20Directory%20zone%20was%20not%20found%20(shows%20on%20all%20%E2%80%9Cchild1%E2%80%9D%20and%20%E2%80%9Cchild2%E2%80%9D%20DCs)%3C%2FLI%3E%3CLI%3EWarning%3A%20The%20Active%20Directory%20zone%20on%20this%20DC%2FDNS%20server%20was%20not%20found%20(probably%20a%20misconfiguration)%26nbsp%3B%20(shows%20on%20all%20%E2%80%9Cchild1%E2%80%9D%20and%20%E2%80%9Cchild2%E2%80%9D%20DCs)%3C%2FLI%3E%3CLI%3ERoot%20zone%20on%20this%20DC%2FDNS%20server%20was%20not%20found%20(shows%20on%20all%208%20DCs)%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20including%20a%20screen%20grab%20of%20the%20DNS%20tree%20structure.%26nbsp%3B%20I%20think%20the%20problems%20are%20related%20to%20the%20organizational%20structure%20and%2For%20delegation%2C%20but%20this%20is%20over%20my%20head%20now.%3C%2FP%3E%3CUL%3E%3CLI%3ENote%20that%20%E2%80%9Cdomain.com%E2%80%9D%20shows%20a%20%E2%80%9Czone%E2%80%9D%20folder%20icon.%26nbsp%3B%20%E2%80%9Cchild1%E2%80%9D%20and%20%E2%80%9Cchild2%E2%80%9D%20are%20nested%20inside%20%E2%80%9Cdomain.com%E2%80%9D%20and%20have%20a%20standard%20folder%20icon.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EAlso%20note%20the%20delegated%20%E2%80%9C_msdcs%E2%80%9D%20folder%20under%20%E2%80%9Cdomain.com%E2%80%9D%20%E2%80%93%20contains%203%20NS%20records%20for%20the%20%E2%80%9Cdomain.com%E2%80%9D%20DCs.%26nbsp%3B%20The%20%E2%80%9C_msdcs%E2%80%9D%20folders%20under%20the%20child%20domains%20are%20not%20delegated%20and%20contain%20no%20NS%20records%20%E2%80%93%20only%20a%20%E2%80%9Cdc%E2%80%9D%20and%20%E2%80%9Cpdc%E2%80%9D%20folder.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22Forum_DNStree.jpg%22%20style%3D%22width%3A%20272px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F360567i166846A1F49D711A%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Forum_DNStree.jpg%22%20alt%3D%22Forum_DNStree.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3273703%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3279999%22%20slang%3D%22en-US%22%3ERe%3A%20DNS%20Zone%20Errors%20-%20Active%20Directory%20Zone%20was%20not%20found%2Fis%20not%20available%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3279999%22%20slang%3D%22en-US%22%3ECould%20you%20update%20us%20with%20that%20information%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3276277%22%20slang%3D%22en-US%22%3ERe%3A%20DNS%20Zone%20Errors%20-%20Active%20Directory%20Zone%20was%20not%20found%2Fis%20not%20available%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3276277%22%20slang%3D%22en-US%22%3EI%20have%20a%20customer%20with%20a%20same%20setup%20like%20you%20have%2C%20the%20child%20domains%20do%20not%20have%20a%20NS%20record%20in%20them%20too%20and%20all%20Domain%20Controllers%20of%20every%20domain%20is%20mentioned%20as%20the%20Name%20Server%20in%20the%20parent%20domain.%20(The%20SOA%20record%20is%20also%20there)%3CBR%20%2F%3E%3CBR%20%2F%3EDo%20you%20have%20all%20Domain%20Controllers%20present%20with%20a%20Name%20Server%20(NS)%20record%20in%20the%20parent%20domain%3F%20(And%20in%20the%20Name%20Servers%20tab%20of%20the%20parent%20domain%20properties%20of%20course)%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3288342%22%20slang%3D%22en-US%22%3ERe%3A%20DNS%20Zone%20Errors%20-%20Active%20Directory%20Zone%20was%20not%20found%2Fis%20not%20available%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3288342%22%20slang%3D%22en-US%22%3E%3CP%3EDid%20you%20manage%20to%20fix%20your%20issue%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

I have a client that I am trying to clean up and straighten out their DNS.  Running the DCdiag DNS test and BPA on each server brings up a number of errors, and I am at my wit’s end trying to resolve them.  DNS seems to be functioning correctly for the time being, but I want to resolve any issues ahead of my next project.

  • The primary DNS Zone is called “domain.com”
  • “domain.com” is a parent domain with 2 child domains – “child1.domain.com” and “child2.domain.com”
  • All domains are contained in the Forest “domain.com” with 2-ways trusts
  • There are 8 total DCs/DNS servers – 3 “domain.com”, 3 “child1.domain.com” and 2 “child2.domain.com”
  • DNS Zones are Active Directory Integrated (though I am skeptical for the child domains)
  • Replication is set to ALL DNS servers in this Forest
  • There are no conditional forwarders configured

 

Best Practices Analyzer Results

  • Error DNS:  The DNS Server <IPaddressOfClientDNS> on <primaryNIC> must resolve names in the primary DNS domain zone (error occurs for each DNS Server configured on the NIC).
  • Error DNS:  Zone <child1 or child2>.domain.com is an Active Directory integrated DNS Zone and must be available.

There are no BPA errors on the 3 parent “domain.com” servers, only the “child1” and “child2” servers.

Each DC/DNS server has a single NIC, single IP address.  The client DNS servers are pointed at opposing DC/DNS servers within the same domain and the loopback is configured as a third option.

 

DCDiag DNS Test Results

  • The SOA record for the Active Directory zone was not found (shows on all “child1” and “child2” DCs)
  • Warning: The Active Directory zone on this DC/DNS server was not found (probably a misconfiguration)  (shows on all “child1” and “child2” DCs)
  • Root zone on this DC/DNS server was not found (shows on all 8 DCs)

 

I am including a screen grab of the DNS tree structure.  I think the problems are related to the organizational structure and/or delegation, but this is over my head now.

  • Note that “domain.com” shows a “zone” folder icon.  “child1” and “child2” are nested inside “domain.com” and have a standard folder icon.

Also note the delegated “_msdcs” folder under “domain.com” – contains 3 NS records for the “domain.com” DCs.  The “_msdcs” folders under the child domains are not delegated and contain no NS records – only a “dc” and “pdc” folder. 

Forum_DNStree.jpg

 

3 Replies
I have a customer with a same setup like you have, the child domains do not have a NS record in them too and all Domain Controllers of every domain is mentioned as the Name Server in the parent domain. (The SOA record is also there)

Do you have all Domain Controllers present with a Name Server (NS) record in the parent domain? (And in the Name Servers tab of the parent domain properties of course)
Could you update us with that information?

Did you manage to fix your issue ?