Problem on Active Directory ( Unrget !!! )

S

SEAN

Dear ,

We have Two Server one ( A ) is Windows 2000 SP4 , Next ( B ) is Windows
2000 SP4 with Exchange 5.5 SP 4 , Two server have already do DCPROMO

Half Year ago , My Exchange Server ( B ) Is broken , And I have Install a
new Server on it and Without Doing the DCPRMON, And It seems OK ,

But one Last WED, there was a error occured at server ( A ) with event log
as follow. This error disabled active directies service. See the following
error.

Event Source: SAM
Event Category: None
Event ID: 16645

Description:
The maximum account identifier allocated to this domain controller has been
assigned. The domain controller has failed to obtain a new identifier pool.A
possible reason for this is that the domain controller has been unable to
contact the master domain controller. Account creation on this controller
will fail until a new pool has been allocated. There may be network or
connectivity problems in the domain, or the master domain controller may be
offline or missing from the domain. Verify that the master domain controller
is running and connected to the domain.

And I have Check with My Server ( A ) 's AD , it still have the the Record
on ( B ) , So, I have using " ntdsutil " to Remove it ....
And the problem Seems Fix .......

But on Last Day , My server B Can't Log into Network After Reboot , All
Services ( like Exchange ) can't Start Cause by this Problem ......

So, I log in Local Account and Do DCPROMO ,Hope can fix it ,

After Promo , it can Log into Network , Also can Start the Services .....

But it display a Error on event log

Event Type: Error
Event Source: SAM
Event Category: None
Event ID: 16650

Description:

The account-identifier allocator failed to initialize properly. The record
data contains the NT error code that caused the failure. Windows 2000 will
retry the initialization until it succeeds; until that time, account
creation will be denied on this Domain Controller. Please look for other
SAM event logs that may indicate the exact reason for the failure.

And The AD can't replicate on Two Server ....

Also When I go to Server B to open AD Sites & Services ......
When I Choose the DC ( B ) to open
It display Unable ro connect to the Domain Controller because : The target
principal name is incorrect

Do anyone Know HOw to Fix it , and Any Effect if it can't fix

Thanks A lots

Best Regards,

Sean Lai
 
D

DJ

Sounds to me like you have lost your global catalog
server. This is usually the first server on the domain and
is responsiable for many functions. If you loose one of
your 5 FMSO role holders (servers) then problems like this
will occur, but only after a long period of time like in
your situation. See Microsofts "How to seize the FMSO
roles of a domain controller" This should fix your problem.

Go here. and do what it says.

http://support.microsoft.com/?kbid=255504

Good luck.

DJ
 
S

Steven L Umbach

Run netdiag and then dcdiag on your "A" domain conrtoller looking for failed tests.
It sounds as if your RID master fsmo no longer exists or there is another problem
contacting it and the pool is empty. See links below for description of fsmo roles
and how to seize them. Also make sure your dns configuration is correct as described
in last KB link. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;EN-US;197132
http://support.microsoft.com/default.aspx?scid=kb;en-us;223787
http://support.microsoft.com/default.aspx?scid=kb;en-us;291382
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

Active Directory 1
Event ID 5513 1
Netlogon 5783 0
master browser 1
error 5783 3
Windows Server What can Active Directory Do? 6
Making Windows 2000 network Redundant 2
Cannot connect to 2000 file shares via VPN 9

Top