我得到DNS事件日志中的这两个错误(问题结束时的错误)。 我已经确认我有重复区域。 我想知道哪些删除。 DomainDNSZone包含了我们所有的DNSlogging,但是它没有_msdcs区域…它在ForestDNSZone中,并且没有被使用。
3个问题。 我了解在ForestDNSZone中拥有DNS的优势。
所以…
为什么DNS使用DomainDNSZone,这是可以接受的考虑_msdcs …是在ForestDNSZone?
如果是这样,我应该从ForestDNSZone中删除DC = 1.168.192.in-addr.arpa和DC = supernova.local? 或者我应该试图让那些被使用的? 那些步骤是什么? 我明白如何删除。 这很简单,但如果我必须移动区域一些信息将在那里appreaciated。
只是为了确认。 从我的理解。 我可以删除ForestDNSZone中的两个副本,并将_msdcs.supernova.local保留为那里所需的值。 这将解决我看到的错误。
只是当我查看ForestDNSZone中的文件夹时,他们分别只有2个和1个条目。 与其他人相比显然没有被使用。 我很确定我了解完成这个步骤。 但如果你想提供这些信息,奖励积分!
Event Type: Warning Event Source: DNS Event Category: None Event ID: 4515 Date: 1/4/2011 Time: 2:14:18 PM User: N/A Computer: STANLEY Description: The zone 1.168.192.in-addr.arpa was previously loaded from the directory partition DomainDnsZones.supernova.local but another copy of the zone has been found in directory partition ForestDnsZones.supernova.local. The DNS Server will ignore this new copy of the zone. Please resolve this conflict as soon as possible. If an administrator has moved this zone from one directory partition to another this may be a harmless transient condition. In this case, no action is necessary. The deletion of the original copy of the zone should soon replicate to this server. If there are two copies of this zone in two different directory partitions but this is not a transient caused by a zone move operation then one of these copies should be deleted as soon as possible to resolve this conflict. To change the replication scope of an application directory partition containing DNS zones and for more details on storing DNS zones in the application directory partitions, please see Help and Support. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Data: 0000: 89 25 00 00 %..
和
Event Type: Warning Event Source: DNS Event Category: None Event ID: 4515 Date: 1/4/2011 Time: 2:14:18 PM User: N/A Computer: STANLEY Description: The zone supernova.local was previously loaded from the directory partition DomainDnsZones.supernova.local but another copy of the zone has been found in directory partition ForestDnsZones.supernova.local. The DNS Server will ignore this new copy of the zone. Please resolve this conflict as soon as possible. If an administrator has moved this zone from one directory partition to another this may be a harmless transient condition. In this case, no action is necessary. The deletion of the original copy of the zone should soon replicate to this server. If there are two copies of this zone in two different directory partitions but this is not a transient caused by a zone move operation then one of these copies should be deleted as soon as possible to resolve this conflict. To change the replication scope of an application directory partition containing DNS zones and for more details on storing DNS zones in the application directory partitions, please see Help and Support. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Data: 0000: 89 25 00 00 %..
更新:build议改善这个问题,所以我可以得到一个回应,将不胜感激。
更新2:
我们的AD由3个DC组成
服务器在192.168.1.100是我们的Exchange和一个DC(不幸)这也是我们的文件服务器。 操作系统:Server 2003 R2
服务器Stanley.DOMAIN.LOCAL是我们的GC并拥有shcemas,但我会尽快将它们移动到DNS服务器。 OS Server 2003 R2
DNS服务器192.168.1.103是我们新的2008 R2 Box。 它现在托pipe的DNS和DHCP,以及是一个GC,一旦我转移架构,将成为PDC。
我想先解决这个DNS问题。
我尝试从所有其他服务器上删除DNS,并且只能在新的2008 R2盒子上运行。 我还没有看到我们的2008 R2服务器(Stanley)DNS日志自11日以来产生事件错误。 斯坦利曾经是DNS,但现在closures了。 这可能是为什么我从那以后没有看到错误? 这是净诊断。 它在交换服务器上运行,因为它仍然是2003 R2。 NETDIAG:
.................................... Computer Name: SERVERNAME DNS Host Name: SERVERNAME.DOMAINNAME.local System info : Microsoft Windows Server 2003 R2 (Build 3790) Processor : x86 Family 6 Model 15 Stepping 6, GenuineIntel List of installed hotfixes : KB2079403 KB2115168 KB2160329 KB2183461-IE8 KB2229593 KB2286198 KB923561 KB924667-v2 KB925398_WMP64 KB925876 KB925902-v2 KB926122 KB926139-v2 KB927891 KB929123 KB930178 KB932168 KB933854 KB936357 KB938127 KB941569 KB942830 KB942831 KB943055 KB943460 KB943729 KB944338-v2 KB944653 KB945553 KB946026 KB948496 KB950760 KB950762 KB950974 KB951066 KB951748 KB952004 KB952069 KB952954 KB953298 KB954155 KB954550-v5 KB955069 KB955759 KB956572 KB956744 KB956802 KB956803 KB956844 KB958469 KB958644 KB958869 KB959426 KB960225 KB960803 KB960859 KB961063 KB961118 KB961501 KB967715 KB967723 KB968389 KB968816 KB969059 KB969883 KB969947 KB970238 KB970430 KB970483 KB971032 KB971468 KB971513 KB971657 KB971737 KB971961 KB971961-IE8 KB972270 KB973037 KB973354 KB973507 KB973540 KB973687 KB973815 KB973825 KB973869 KB973904 KB973917-v2 KB974112 KB974318 KB974392 KB974571 KB975025 KB975254 KB975467 KB975560 KB975562 KB975713 KB976323 KB976662-IE8 KB977165-v2 KB977290 KB977816 KB977914 KB978037 KB978251 KB978262 KB978338 KB978542 KB978601 KB978695 KB978706 KB979306 KB979309 KB979482 KB979559 KB979683 KB979907 KB980182 KB980182-IE8 KB980195 KB980218 KB980232 KB980302-IE8 KB980436 KB981332-IE8 KB982214 KB982381-IE8 KB982666 Q147222 Netcard queries test . . . . . . . : Passed Per interface results: Adapter : Local Area Connection 2 Netcard queries test . . . : Passed Host Name. . . . . . . . . : SERVERNAME IP Address . . . . . . . . : 192.168.1.100 Subnet Mask. . . . . . . . : 255.255.255.0 Default Gateway. . . . . . : 192.168.1.1 Dns Servers. . . . . . . . : 192.168.1.103 AutoConfiguration results. . . . . . : Passed Default gateway test . . . : Passed NetBT name test. . . . . . : Passed WINS service test. . . . . : Skipped There are no WINS servers configured for this interface. Global results: Domain membership test . . . . . . : Passed NetBT transports test. . . . . . . : Passed List of NetBt transports currently configured: NetBT_Tcpip_{9052E7E6-EBB2-43F2-857A-8CF43C9718B3} 1 NetBt transport currently configured. Autonet address test . . . . . . . : Passed IP loopback ping test. . . . . . . : Passed Default gateway test . . . . . . . : Passed NetBT name test. . . . . . . . . . : Passed Winsock test . . . . . . . . . . . : Passed DNS test . . . . . . . . . . . . . : Passed PASS - All the DNS entries for DC are registered on DNS server '192.168.1.103' and other DCs also have some of the names registered. Redir and Browser test . . . . . . : Passed List of NetBt transports currently bound to the Redir NetBT_Tcpip_{9052E7E6-EBB2-43F2-857A-8CF43C9718B3} The redir is bound to 1 NetBt transport. List of NetBt transports currently bound to the browser NetBT_Tcpip_{9052E7E6-EBB2-43F2-857A-8CF43C9718B3} The browser is bound to 1 NetBt transport. DC discovery test. . . . . . . . . : Passed DC list test . . . . . . . . . . . : Passed Trust relationship test. . . . . . : Passed Secure channel for domain 'SUPERNOVA' is to '\\stanley.DOMAINNAME.local'. Kerberos test. . . . . . . . . . . : Passed LDAP test. . . . . . . . . . . . . : Passed Bindings test. . . . . . . . . . . : Passed WAN configuration test . . . . . . : Skipped No active remote access connections. Modem diagnostics test . . . . . . : Passed IP Security test . . . . . . . . . : Skipped Note: run "netsh ipsec dynamic show /?" for more detailed information The command completed successfullylution.
我也只是在韦尔上运行一个DC Diag。 这是2008 R2盒子这个testing失败了。 虽然只是看了这一点,并认识到,如果我没有做adprep / rodcprep。 考虑到我不打算在RODC MS上说这可以被忽略。
Starting test: NCSecDesc Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have Replicating Directory Changes In Filtered Set access rights for the naming context: DC=ForestDnsZones,DC=DOMAINAME,DC=local Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have Replicating Directory Changes In Filtered Set access rights for the naming context: DC=DomainDnsZones,DC=DOMAINAME,DC=local ......................... WEIR failed test NCSecDesc
有时会在更改2003 DNSpipe理单元中的复制范围时发生这种情况。 我想解决的是:
在一台服务器上重新启动DNS服务器服务。
检查DNS日志 – EventID 4515的所有事件应该消失。 如果不确定“AD集成”处于closures状态,请重新启动该服务,直到它启动而没有任何4515警告。
启用AD集成。 请记住设置复制范围并启用安全更新。
强制AD复制到所有运行DNS的DC。
**注意如果其他DNS服务器上的其他区域未复制到您在步骤1中select的服务器,请停止正在处理的计算机上的DNS服务器服务,然后重复步骤1至5以获取承载剩余冲突区域的DNS服务器。
这个域是从Windows 2000升级到2003的域,但可能没有正确完成? 有关如何执行此类升级的非常详细的说明,包括如何清理_msdcs子域可以在这里find:
http://support.microsoft.com/kb/817470
为了帮助改善这个问题,我可能会提供以下内容:
1)AD / DNS基础结构的描述。 2)命名服务(如netdiag)的诊断日志,以确认(1)中的所有内容按照预期的名称/资源分辨率工作。