Ken,
Slow logons are *typically* an indication that there is something going on
with DNS. A *usual* cause of this is that in the client's TCP/IP settings
the DNS Server entry is the ISP's DNS Server ( or some other external DNS ).
I would suggest that you take a look at the settings on the DHCP Server to
see what it is handing out as Option 006. All WIN2000 and WINXP clients
*MUST* *MUST* *MUST* point to an internal DNS Server that supports SRV
Records and Dynamic Updates.
Please take a look at the following two MSKB Articles that describe what a
WIN2000 and WINXP clients do at logon:
http://support.microsoft.com/?id=247811
http://support.microsoft.com/?id=314861
Another possible problem is a Global Catalog is not available at certain
times ( for God knows what reason ).
Ken, you do not give us any idea of your topology. I am assuming ( I am
almost always wrong when I do this! ) that you have one Site and not
multiple Sites. Please give us some details of your topology.
Also, I would strongly suggest that you install the Support Tools on all of
your WIN2000 Servers and run dcdaig /c /v and netdiag /v. This will give
you a good reading as to the health of your AD environment. I am not sure
why you would want to run ntdsutil? Did you dcpromo a Domain Controller and
it still shows up in the ADSS MMC? and you see it listed as a replication
partner with your currently existing DCs when you run repadmin /showreps?
The Support Tools, by the way, are located on the WIN2000 Server CD as well
as on the WIN2000 Service Pack CD in the Support | Tools folder.
HTH,
Cary