PC Review


Reply
Thread Tools Rate Thread

Win2003 DNS errors

 
 
anhfhsk
Guest
Posts: n/a
 
      2nd Feb 2004
I receive thousands of DNS errors, and i don't know what
all these are. DNS client service is disabled and i don't
want this machine to at all register itself with the uplink
DNS, but it tries to do that anyway. I only want it to act
as a DNS server for the LAN. How to do this?



---------------
Event-id 40961:
---------------
The Security System could not establish a secured
connection with the server DNS/prisoner.iana.org. No
authentication protocol was available.


---------------
Event-ID 5774:
---------------
The dynamic registration of the DNS record
'_kpasswd._tcp.bbbbb.ccc.dd. 600 IN SRV 0 100 464
aaaaa.bbbbb.ccc.dd.' failed on the following DNS server:

DNS server IP address: 999.999.999.999
Returned Response Code (RCODE): 5
Returned Status Code: 9017

For computers and users to locate this domain controller,
this record must be registered in DNS.

USER ACTION
Determine what might have caused this failure, resolve the
problem, and initiate registration of the DNS records by
the domain controller. To determine what might have caused
this failure, run DCDiag.exe. You can find this program on
the Windows Server 2003 installation CD in
Support\Tools\support.cab. To learn more about DCDiag.exe,
see Help and Support Center. To initiate registration of
the DNS records by this domain controller, run 'nltest.exe
/dsregdns' from the command prompt on the domain
controller or restart Net Logon service. Nltest.exe is
available in the Microsoft Windows Server Resource Kit CD.
Or, you can manually add this record to DNS, but it is
not recommended.

ADDITIONAL DATA
Error Value: DNS bad key.



---------------
Event-ID 5775:
---------------
The dynamic deletion of the DNS record 'bbbbb.ccc.dd. 600
IN A 192.168.0.6' failed on the following DNS server:

DNS server IP address: 999.999.999.999
Returned Response Code (RCODE): 5
Returned Status Code: 9017

USER ACTION
To prevent remote computers from connecting unnecessarily
to the domain controller, delete the record manually or
troubleshoot the failure to dynamically delete the record.
To learn more about debugging DNS, see Help and Support
Center.

ADDITIONAL DATA
Error Value: DNS bad key.

 
Reply With Quote
 
 
 
 
Kevin D. Goodknecht [MVP]
Guest
Posts: n/a
 
      2nd Feb 2004
In news:89c201c3e969$89b56430$(E-Mail Removed),
anhfhsk <(E-Mail Removed)> posted a question
Then Kevin replied below:
: I receive thousands of DNS errors, and i don't know what
: all these are. DNS client service is disabled and i don't
: want this machine to at all register itself with the uplink
: DNS, but it tries to do that anyway. I only want it to act
: as a DNS server for the LAN. How to do this?
:
:
:
: ---------------
: Event-id 40961:
: ---------------
: The Security System could not establish a secured
: connection with the server DNS/prisoner.iana.org. No
: authentication protocol was available.
:
:
: ---------------
: Event-ID 5774:
: ---------------
: The dynamic registration of the DNS record
: '_kpasswd._tcp.bbbbb.ccc.dd. 600 IN SRV 0 100 464
: aaaaa.bbbbb.ccc.dd.' failed on the following DNS server:
:
: DNS server IP address: 999.999.999.999
: Returned Response Code (RCODE): 5
: Returned Status Code: 9017
:
: For computers and users to locate this domain controller,
: this record must be registered in DNS.
:
: USER ACTION
: Determine what might have caused this failure, resolve the
: problem, and initiate registration of the DNS records by
: the domain controller. To determine what might have caused
: this failure, run DCDiag.exe. You can find this program on
: the Windows Server 2003 installation CD in
: Support\Tools\support.cab. To learn more about DCDiag.exe,
: see Help and Support Center. To initiate registration of
: the DNS records by this domain controller, run 'nltest.exe
: /dsregdns' from the command prompt on the domain
: controller or restart Net Logon service. Nltest.exe is
: available in the Microsoft Windows Server Resource Kit CD.
: Or, you can manually add this record to DNS, but it is
: not recommended.
:
: ADDITIONAL DATA
: Error Value: DNS bad key.
:
:
:
: ---------------
: Event-ID 5775:
: ---------------
: The dynamic deletion of the DNS record 'bbbbb.ccc.dd. 600
: IN A 192.168.0.6' failed on the following DNS server:
:
: DNS server IP address: 999.999.999.999
: Returned Response Code (RCODE): 5
: Returned Status Code: 9017
:
: USER ACTION
: To prevent remote computers from connecting unnecessarily
: to the domain controller, delete the record manually or
: troubleshoot the failure to dynamically delete the record.
: To learn more about debugging DNS, see Help and Support
: Center.
:
: ADDITIONAL DATA
: Error Value: DNS bad key.

All those errors are caused from using your ISP's DNS in your DC's NIC.
You are not supposed to put Your ISP's DNS in the NIC, remove it and put in
the DNS server's own IP address in the NIC. Then put your ISP's DNS in as a
forwarder, if forwarders are grayed out, delete the "." Forward Lookup Zone.
Read this starting at step 3.
300202 - HOW TO: Configure DNS for Internet Access in Windows 2000
http://support.microsoft.com/?id=300202&FR=1

--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
============================
--
When responding to posts, please "Reply to Group" via your
newsreader so that others may learn and benefit from your issue.
To respond directly to me remove the nospam. from my email.
==========================================
http://www.lonestaramerica.com/
==========================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
==========================================
Keep a back up of your OE settings and folders with
OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
==========================================


 
Reply With Quote
 
Ace Fekay [MVP]
Guest
Posts: n/a
 
      3rd Feb 2004
In news:(E-Mail Removed),
Kevin D. Goodknecht [MVP] <(E-Mail Removed)> posted their thoughts,
then I offered mine

>
> All those errors are caused from using your ISP's DNS in your DC's
> NIC.
> You are not supposed to put Your ISP's DNS in the NIC, remove it and
> put in the DNS server's own IP address in the NIC. Then put your
> ISP's DNS in as a forwarder, if forwarders are grayed out, delete the
> "." Forward Lookup Zone. Read this starting at step 3.
> 300202 - HOW TO: Configure DNS for Internet Access in Windows 2000
> http://support.microsoft.com/?id=300202&FR=1
>
> --
> Best regards,
> Kevin D4 Dad Goodknecht Sr. [MVP]
> Hope This Helps
> ============================


In addition, the 40961 error can be eliminated by creating a reverse zone.

--
Regards,
Ace

Please direct all replies to the newsgroup so all can benefit.
This posting is provided "AS IS" with no warranties.

Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory
--
=================================


 
Reply With Quote
 
anhfhsk
Guest
Posts: n/a
 
      3rd Feb 2004
> remove it and put in the DNS server's
> own IP address in the NIC.


wich means 127.0.0.1 or 10.10.10.253 ?


> put your ISP's DNS in as a forwarder


How to do this? I tried to follow the steps on linked
webpage, but when clicking "finish" it gave an error
telling it already exists.
Hoe do i add a dns server that should not try to register
this server, but only use the dns server as a sorce of dns
info? without registering the server on the dns server.

 
Reply With Quote
 
Ace Fekay [MVP]
Guest
Posts: n/a
 
      4th Feb 2004
In news:944001c3ea46$c9f9fdc0$(E-Mail Removed),
anhfhsk <(E-Mail Removed)> posted their thoughts, then I offered mine
>> remove it and put in the DNS server's
> > own IP address in the NIC.

>
> wich means 127.0.0.1 or 10.10.10.253 ?
>
>


Use the actual IP (10.10.10.253). Don't ever use the loopback address
(127.0.0.1). It won't let you anyway unless you force it thru the reg.

--
Regards,
Ace

Please direct all replies to the newsgroup so all can benefit.
This posting is provided "AS IS" with no warranties.

Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory
--
=================================


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN From Win2003 to Win2003 Server messes up routing table robdob Microsoft Windows 2000 RAS Routing 0 29th Mar 2009 06:54 PM
Browser errors after transfer of roles to Win2003 Server =?Utf-8?B?UnlhbiBMYXVyaWU=?= Microsoft Windows 2000 Networking 3 5th Feb 2007 09:23 PM
win2003 w/sharepoint giving syntax errors =?Utf-8?B?dGltYWxsYXJk?= Microsoft ASP .NET 3 13th Oct 2005 11:58 PM
Difference between Win2003 Std and Win2003 Advance Server ELTANO Microsoft Windows 2000 2 2nd Nov 2004 08:11 PM
Win2003 DNS cache lookup errors hotfix Travis Microsoft Windows 2000 DNS 5 7th May 2004 06:00 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 09:26 AM.