Cannot connect to Global Catalog toparent domain

B

Benny Yeung

Dear All,

I need help with following,

One of two DC on parent domain crashed and Disaster recover from backup with
system state (non Authoritative) and seems working fine now( with correct
USN updated). However, the child domain DC which was using the crashed
server and logon server (%logonserver%) have error event on event viewer. We
have two DCs on the child domain and both have this error on event viewer.

---------------------------------------------------------------------------
(event ID 1655) Global Catalog

The attempt to communicate with global catalog \\dvn-hk-ad.dvngroup.com
failed with the following status:

Logon failure: unknown user name or bad password.

The operation in progress might be unable to continue. The directory
service will use the locator to try find an available global catalog server
for the next operation that requires one.

The record data is the status code.
0000: 2e 05 00 00 ....
----------------------------------------------------------------------------
-----
(Event ID 1126) Global Catalog

Unable to establish connection with global catalog.

----------------------------------------------------------------------------
-
(Event ID 1100)

Windows cannot query for the list of Group Policy objects . A message that
describes the reason for this was previously logged by this policy engine.
-----------------------------------------------------------------------
(Event ID 1100) Global Catalog

Windows cannot establish a connection to dvngroup.com with (82).
--------------------------------------------------------------------

All user on child domain cannot execute login script and access to the
server on parent domain.


The crashed parent DC FSMO role are PDC, DM and IM

I also noted that on the event viewer on the crashed server.
There are some error event on SAM after first reboot immedately after
recover from backup tape and not see it again after second reboot.



Anybody can help on this thanks
 
M

Matjaz Ladava [MVP]

Can you make another server a GC and remove GC from restored server. After
that try reassign this server as GC. Also run dcdiag /v and netdiag /v on
your server to see if there are any other errors related to RID masters and
others ?

--
Regards

Matjaz Ladava, MCSE, MCSA, MCT, MVP
Microsoft MVP - Active Directory
(e-mail address removed), (e-mail address removed)
http://ladava.com
 
B

Benny Yeung

HI Matjaz,

It seems that , the child domain DC cannot to GC with access denied problem.
May be the crashed server is PDC role and offline. I use replmon utilites
found that the Parent DC can replicated to Child domain DC without any
error.
However, the child Domain DC cannot replicate to Parent domain and error
message on replmon utility: Replication failure :unknown username or
password.

Is it related to the Keborse ticket problem and the PDC role on the
recovered server.
I found that there a topic about access denied replications Errors on
Technet

http://www.microsoft.com/technet/tr...ndows2000/maintain/opsguide/Part1/adogd12.asp

I am still unable to let the Child domain DC connect to GC server even
reboot it many times
Same error displayed on the event viewer.

Thanks for Help!!!
 
M

Matjaz Ladava [MVP]

Does this happens only with child domains or do you have any problems within
your servers domain ? Try forcing intrasite replication from that server
(from AD sites and services) ? If this is not the only server in your domain
you could run dcpromo, remove AD from that server and recreate AD on that
server. Of course you have to have at least one additional DC present in
your domain and prior to removing Ad transfer FSMO roles to that server.
What results do you get by running dcdiag on your DC ?

--
Regards

Matjaz Ladava, MCSE, MCSA, MCT, MVP
Microsoft MVP - Active Directory
(e-mail address removed), (e-mail address removed)
http://ladava.com
 
B

Benny Yeung

Thanks for your valuable information.

After verify the domain using Dcdiag utilities, I found that there are
Kerberos Error on the trust domain. And I just follow the Q328701 on
knowledge base "Replication Error Message 1326 and Event Message ID 1265
"Unknown User Name or Bad Password"

After reset the trust relationship and we can replicated the child and
parent domain now.


Thanks for helping

Best Regards

BENNY
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top