域重命名后的巨大失败

背后的故事

我最近升级了从03到2012年的MS服务器。该服务器需要是一个域控制器为了简单起见,我将其命名为foo.com,而不是将其命名为与在线活动不同的东西。 所以我有我的本地域命名为我的网域相同,当试图访问电子邮件帐户时,我得到各种错误。 我决定将域重命名为foo.local。

当前的问题

我最近在域中添加了新的机器,一切进展顺利。 但是,一旦我去安装Outlook 2010并添加邮箱,我开始遇到同样的问题,我以前有域控制器的名称和网域具有相同的名称。
出于病态的希望,不必再次处理这个问题, 并认为这是一个DNS问题,我从我的DNSpipe理器中删除了一些DNS条目。
现在我正在尝试再次将机器添加到foo.local域时出现错误

当我尝试添加一台机器到域,我得到这个错误:

Note: This information is intended for a network administrator. If you are not your network's administrator, notify the administrator that you received this information, which has been recorded in the file C:\Windows\debug\dcdiag.txt. DNS was successfully queried for the service location (SRV) resource record used to locate a domain controller for domain "foo.local": The query was for the SRV record for _ldap._tcp.dc._msdcs.foo.local The following domain controllers were identified by the query: fooserver01.foo.com However no domain controllers could be contacted. Common causes of this error include: - Host (A) or (AAAA) records that map the names of the domain controllers to their IP addresses are missing or contain incorrect addresses. - Domain controllers registered in DNS are not connected to the network or are not running. 

运行dcdiag /test:dns我得到这个结果:

 C:\Program Files>dcdiag /test:dns Directory Server Diagnosis Performing initial setup: Trying to find home server... Home Server = fooServer01 * Identified AD Forest. Done gathering initial info. Doing initial required tests Testing server: Default-First-Site-Name\FOOSERVER01 Starting test: Connectivity The host 01e7fc30-b4aa-4c8e-a036-c08a45b0ffb5._msdcs.foo.local could not be resolved to an IP address. Check the DNS server, DHCP, server name, etc. Got error while checking LDAP and RPC connectivity. Please check your firewall settings. ......................... FOOSERVER01 failed test Connectivity Doing primary tests Testing server: Default-First-Site-Name\FOOSERVER01 Starting test: DNS DNS Tests are running and not hung. Please wait a few minutes... ......................... FOOSERVER01 passed test DNS Running partition tests on : ForestDnsZones Running partition tests on : DomainDnsZones Running partition tests on : Schema Running partition tests on : Configuration Running partition tests on : foo Running enterprise tests on : foo.local Starting test: DNS Test results for domain controllers: DC: fooServer01.foobar.com Domain: foo.local TEST: Basic (Basc) Error: No LDAP connectivity No host records (A or AAAA) were found for this DC TEST: Records registration (RReg) Error: Record registrations cannot be found for all the network adapters Summary of DNS test results: Auth Basc Forw Del Dyn RReg Ext _________________________________________________________________ Domain: foo.local fooServer01 PASS FAIL PASS PASS PASS FAIL n/a ......................... foo.local failed test DNS 

如果我是正确的,几个小时的无望的谷歌search已经取得了,我需要恢复/修复,我遗憾地从我的DNS经理删除的DNS条目。

请让我知道,如果有任何进一步的信息将有任何帮助!

下面是fooServer01的一个ifconfig /all打印输出

 C:\Program Files>ipconfig /all Windows IP Configuration Host Name . . . . . . . . . . . . : fooServer01 Primary Dns Suffix . . . . . . . : foobar.com Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : foobar.com Ethernet adapter Ethernet: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Broadcom BCM5708C NetXtreme II GigE (NDIS VBD Client) #44 Physical Address. . . . . . . . . : 00-1E-C9-EA-86-30 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::d5ba:d38:e1e8:d716%12(Preferred) IPv4 Address. . . . . . . . . . . : 192.168.0.1(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.0.8 DHCPv6 IAID . . . . . . . . . . . : 301997769 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1B-66-05-A8-00-1E-C9-EA-86-30 DNS Servers . . . . . . . . . . . : ::1 127.0.0.1 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adapter isatap.{B0DD6412-73DF-4EEB-B3B5-53FDC632B011}: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft ISATAP Adapter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Teredo Tunneling Pseudo-Interface: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft Teredo Tunneling Adapter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes C:\Program Files> 

DNSpipe理器树

 fooServer01 |- Forward Lookup Zones | |- _msdcs.foobar.com | | |- local | | | |- foo Host(A) 192.168.0.1 static | | |- (same as parent folder) Start of Authority (SOA) [7],fooserver01.foobar.com,hostmaster.foobar.com static | | |- (same as parent folder) Name Server (NS) fooserver01.foobar.com static | | |- fooserver01 Alias (CNAME) fooserver01.foobar.com static | |- foo.local | | |- _msdcs | | | |- _dc | | | | |- _sites | | | | | |- Default-First-Name-Site | | | | | | |- _tcp | | | | | | | |- _kerberos Service Location (SRV) [0][100][89] fooserver01.foobar.com. Timestamp | | | | | | | |- _ldap Service Location (SRV) [0][100][389] fooserver01.foobar.com. Timestamp | | | | |- _tcp | | | | | |- _kerberos Service Location (SRV) [0][100][88] fooserver01.foobar.com. Timestamp | | | | | |- _ldap Service Location (SRV) [0][100][389] fooserver01.foobar.com Timestamp | | | |- domains | | | | |- {long string of letters & numbers } | | | | | |- _tcp | | | | | | |- _ldap Service Location (SRV) [0][100][389] fooserver01.foobar.com. Timestamp | | | |- gc | | | | |- _sites | | | | | |- Default-First-Site-Name | | | | | | |- _tcp | | | | | | | |- _ldap Service Location (SRV) [0][100][3268] fooserver01.foobar.com. Timestamp | | | | |- _tcp | | | | | |- _ldap Service Location (SRV) [0][100][3268] fooserver01.foobar.com. Timestamp | | | |- pdc | | | | |- _tcp | | | | | |- _ldap Service Location (SRV) [0][100][389] fooserver01.foobar.com. Timestamp | | |- _sites | | | |- Default-First-Site-Name | | | | |- _tcp | | |- _tcp | | |- _udp | | |- DomainDnsZones | | | |- _sites | | | | |- Default-First-Site-Name | | | | | |- _tcp | | | |- _tcp | | |- ForestDnsZones | | | |- _sites | | | | |- Default-First-Site-Name | | | | | |- _tcp | | | |- _tcp | | |- (same as parent folder) Start of Authority (SOA) [1611], fooserver01.foobar.com, hostmaster.foobar.com static | | |- (same as parent folder) Name Server (NS) fooserver01.foobar.com static | | |- (same as parent folder) Host (A) 192.168.0.1 Timestamp | | |- LIST OF MACHINES STARTS | | |- THERE'S ABOUT 15 OF THEM | | |- fooserver Alias (CNAME) FooServer01.foobar.com | |- _ldap.foobar.com | | |- (same as parent folder) Start of Authority (SOA) [1], fooserver01.foobar.com, hostmaster.foobar.com. static | | |- (same as parent folder) Name Server (NS) fooserver01.foobar.com. static |- Reverse Lookup Zones |- Trust Points |- Conditional Forwarders |- Global logs 

这有帮助吗? 我应该继续吗?

奇怪的是,你不是第一个这样做的人。
戴尔甚至有一个关于如何注册您的DC回到DNS的指南。

你真的应该审查一切,但是域控制器是你的基础设施的关键部分,需要一致性和可靠性。
重命名区议会是我过去不惜一切代价避免的事情,不情愿地执行了很多我希望我永远无法解决的错误/问题。
在每个操作之前进行系统状态备份,并广泛validation每个操作。 不要随意开始删除东西!

鉴于我删除了我的DNSpipe理器中的一些条目,我觉得这是一个完美的开始。 我可能会缺less条目,但我input的足够让我的工作站正确join域。 这些是我添加的条目。

  1. 将名为foob​​ar.com的新区域添加回正向查找区域
  2. 在新区域内,我添加了其他新logging和选定的服务位置(SRV)
  3. 为默认值,为服务input_ldap ,为协议input_tcp ,为优先级为0 ,权重为100 ,端口号为389 ,为提供此服务的主机提供服务的主机的ip。
  4. 然后使用服务位置(SRV)添加另一个新logging
  5. 在此对话框中,我再次将Domain设置为默认值, _gc代表服务, _tcp代表协议, 0代表优先级, 100代表权重, 3268代表端口号。

然后,我跳回到工作站进行testing,并join到域名成功。
我正在使用这个作为临时解决scheme,因为我想我将重新安装Windows Server 2012,并且一旦压力closures,就从头开始,所以把这个与一粒盐。