Home All Groups Group Topic Archive Search About
Author
11 Feb 2006 12:12 PM
Bonno Bloksma
Hi,



I have 5 sites. In "AD Sites and services" I have 7 subnets defined. 5 for
the 5 sites, 1 to include all internal ip numbers for all sites AND the VPN
connections and one for our DMZ.

Some servers appear in the right "site container" but some are in the wrong
container. All servers which are in the wrong container are in the same
wrong container.

One server is in my AD but does not appear in any site.

It seems something is wrong. :-(



Site Amsterdam, 172.16.192.0/20 also has the right server assigned to it.
TioAms2K3 with ip number 172.16.192.9

Site Hengelo, 172.16.128.0/20 has two servers assigned, both the right
server. Mona2K 172.16.128.31 and TioDC3 172.16.128.40

Site Eindhoven 172.16.208.0/20 was my first site. It has some servers
assigned to it which should be there but also some which don't belong.

TioDc1 172.16.208.10 and TioEin2K3 172.16.208.9 belong there

TioLdm2k3 172.16.176.9 and TioUtr2K3 172.16.32.9 do NOT belong there.

I have subnets 172.16.176.0/20 and 172.16.32.0/20 defined and assigned to
the site Leidschendam and Utrecht. If I open the properties for site
Leidschendam I can see the correct subnet (...176.0/20) in the list, the
same for Utrecht (...32.0/20). If I go to the subnets defined and look at
the properties I see the correct site assigned.



So.... why are two Windows 2003 Domain Controllers showing up in the wrong
site? I can probably move the servers to the correct site manually but
should I..... Isn't the fact that they are in the wrong site probably an
indicator something else it wrong which I need to fix?

I have 5 sites, 2 domains. In the top domain (tio.nl) are 2 DC's which are
both also dns and WINS server. In the domain below (staf.tio.nl) are 5
servers for the 5 sites. Each is domain controller and at three sites (the
ones without a dns at the top level dc) it is also the dns server.

TioLdm2k3 and TioUtr2K3, which are in the wrong site, are indeed servers
which are both dc and dns server. However so is TioAms2k3, and it is in the
correct site.



Help!!!!!


--




Groetjes,



Bonno Bloksma

Author
11 Feb 2006 5:29 PM
Paul Bergson
Inline

--


Paul Bergson  MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.


Show quoteHide quote
"Bonno Bloksma" <b.blok***@tio.nl> wrote in message
news:entY$RwLGHA.3936@TK2MSFTNGP12.phx.gbl...
> Hi,
>
>
>
> I have 5 sites. In "AD Sites and services" I have 7 subnets defined. 5 for
> the 5 sites, 1 to include all internal ip numbers for all sites AND the
> VPN
> connections and one for our DMZ.
>
> Some servers appear in the right "site container" but some are in the
> wrong
> container. All servers which are in the wrong container are in the same
> wrong container.
>
> One server is in my AD but does not appear in any site.
>
> It seems something is wrong. :-(

There is definitely some change you will need to make and if you have a DC
totally missing from your sites and services "Odds are it isn't performing
DC services."  You should run diagnostics against the domain once you have
completed the steps here.

From the link below download DCDIAG and NetDiag GUI tool it will help you
run diagnostics as explained.
http://pbbergs.dynu.com/windows/downloads.htm

I'll also say I'm being lazy I I'm trusting that you have this all figured
out subnet assignments correctly.  If this isn't the case report back and
I'll take a closer look.


>
>
>
> Site Amsterdam, 172.16.192.0/20 also has the right server assigned to it.
> TioAms2K3 with ip number 172.16.192.9

Leave Alone

>
> Site Hengelo, 172.16.128.0/20 has two servers assigned, both the right
> server. Mona2K 172.16.128.31 and TioDC3 172.16.128.40

Leave Alone

>
> Site Eindhoven 172.16.208.0/20 was my first site. It has some servers
> assigned to it which should be there but also some which don't belong.
>
> TioDc1 172.16.208.10 and TioEin2K3 172.16.208.9 belong there
>
> TioLdm2k3 172.16.176.9 and TioUtr2K3 172.16.32.9 do NOT belong there.

From Sites and Services - Drag and Drop TioLdm2k3 172.16.176.9 to the site
Leidschendam (172.16.176.0/20)

From Sites and Services - Drag and Drop TioUtr2K3 172.16.32.9  to the site
Utrecht (172.16.32.0/20 )

>
> I have subnets 172.16.176.0/20 and 172.16.32.0/20 defined and assigned to
> the site Leidschendam and Utrecht. If I open the properties for site
> Leidschendam I can see the correct subnet (...176.0/20) in the list, the
> same for Utrecht (...32.0/20). If I go to the subnets defined and look at
> the properties I see the correct site assigned.
>
>
>
> So.... why are two Windows 2003 Domain Controllers showing up in the wrong
> site? I can probably move the servers to the correct site manually but
> should I..... Isn't the fact that they are in the wrong site probably an
> indicator something else it wrong which I need to fix?

When you promote the DC it is placed in the site that corresponds to from
sites and services.  If no site exist for the subnet from which it belongs
it is placed in the site from which it receieved the source information
from.

http://support.microsoft.com/?kbid=214677

Show quoteHide quote
>
> I have 5 sites, 2 domains. In the top domain (tio.nl) are 2 DC's which are
> both also dns and WINS server. In the domain below (staf.tio.nl) are 5
> servers for the 5 sites. Each is domain controller and at three sites (the
> ones without a dns at the top level dc) it is also the dns server.
>
> TioLdm2k3 and TioUtr2K3, which are in the wrong site, are indeed servers
> which are both dc and dns server. However so is TioAms2k3, and it is in
> the
> correct site.
>
>
>
> Help!!!!!
>
>
> --
>
>
>
>
> Groetjes,
>
>
>
> Bonno Bloksma
>
>
>
>
>
>
>
>
Author
13 Feb 2006 12:19 PM
Bonno Bloksma
Hi,

Show quoteHide quote
> > I have 5 sites. In "AD Sites and services" I have 7 subnets defined. 5
for
> > the 5 sites, 1 to include all internal ip numbers for all sites AND the
> > VPN
> > connections and one for our DMZ.
> >
> > Some servers appear in the right "site container" but some are in the
> > wrong
> > container. All servers which are in the wrong container are in the same
> > wrong container.
> >
> > One server is in my AD but does not appear in any site.
> >
> > It seems something is wrong. :-(
>
> There is definitely some change you will need to make and if you have a DC
> totally missing from your sites and services "Odds are it isn't performing
> DC services."  You should run diagnostics against the domain once you have
> completed the steps here.

The one missing is just a server, not a DC. Are only DC's listed in sites
and services? Probably, now that I think of it. Oops my mistake. ;-(

> From the link below download DCDIAG and NetDiag GUI tool it will help you
> run diagnostics as explained.
> http://pbbergs.dynu.com/windows/downloads.htm

The link did not work, but I found them at the MS site.
http://support.microsoft.com/?kbid=265706

> I'll also say I'm being lazy I I'm trusting that you have this all figured
> out subnet assignments correctly.  If this isn't the case report back and
> I'll take a closer look.

Subnet's are okay, I know a lot about that stuff and checked them before
sending the message.

Just ran DCDiag on one Windows 2003 DC server and it came up with:
----------<quote>--------------------
      Starting test: Services
            RPCLOCATOR Service is stopped on [TIOEIN2K3]
            TrkWks Service is stopped on [TIOEIN2K3]
            TrkSvr Service is stopped on [TIOEIN2K3]
         ......................... TIOEIN2K3 failed test Services
----------<quote>--------------------

The RPCLocator service has startup type manual
The Distributed Link Tracking Client has startup type manual
The Distributed Link Tracking Server is disabled.

The TioEin2K3 server is the PDC as well as the RID and IM for the
staf.tio.nl domain. Would that be the cause for those stopped services to be
flagged?
At the TioAms2K3 server, a DC for the same staf domain, these same three
services are not running but the dcdiag tool does not complain.
However, my TioDC3 server is just a backup DC for the tio.nl domain server
without the PDC, RID, IM roles. The three services are not running and the
dcdiag tool IS complaining about it.

I cannot find any consistency it the behaviour of the dcdiag tool. :-( Is
that because this tool is for Windows 2000 and I'm running Windows 2003
servers?

Should I enable all those services on the servers? What is the effect of
those three services not running?

p.s. Netdiag refuses to run. Claiming: The procedure entry point
DnsGetMaxNumberoOfAddressesToRegister could not be located in the dynamic
link library DNSAPI.dll
Is this caused by the discrepancy between the tools being for Windows 2000
and my servers being Windows 2003?

--


Groetjes,

Bonno Bloksma
Author
13 Feb 2006 1:49 PM
Paul Bergson
My website uses a high port (3379) that may be why you are having trouble
accessing it.  The netdiag issue is probably because you are using the wrong
tools.  The tools should be located on your install cd at
d:\support\tools\setup.exe -or-

If you are using 2000 diagnostics some errors will report that don't really
exist, whether this is the issues with services I don't know but I don't see
any problems with the services that you have.  Yes only DC's will show up in
sites and services, this piece of ad is used for replication.  Since this
other dc isn't replicating anything it won;t be in there.


--

Paul Bergson  MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.

Show quoteHide quote
"Bonno Bloksma" <b.blok***@tio.nl> wrote in message
news:%23RPZ$eJMGHA.3936@TK2MSFTNGP10.phx.gbl...
> Hi,
>
>> > I have 5 sites. In "AD Sites and services" I have 7 subnets defined. 5
> for
>> > the 5 sites, 1 to include all internal ip numbers for all sites AND the
>> > VPN
>> > connections and one for our DMZ.
>> >
>> > Some servers appear in the right "site container" but some are in the
>> > wrong
>> > container. All servers which are in the wrong container are in the same
>> > wrong container.
>> >
>> > One server is in my AD but does not appear in any site.
>> >
>> > It seems something is wrong. :-(
>>
>> There is definitely some change you will need to make and if you have a
>> DC
>> totally missing from your sites and services "Odds are it isn't
>> performing
>> DC services."  You should run diagnostics against the domain once you
>> have
>> completed the steps here.
>
> The one missing is just a server, not a DC. Are only DC's listed in sites
> and services? Probably, now that I think of it. Oops my mistake. ;-(
>
>> From the link below download DCDIAG and NetDiag GUI tool it will help you
>> run diagnostics as explained.
>> http://pbbergs.dynu.com/windows/downloads.htm
>
> The link did not work, but I found them at the MS site.
> http://support.microsoft.com/?kbid=265706
>
>> I'll also say I'm being lazy I I'm trusting that you have this all
>> figured
>> out subnet assignments correctly.  If this isn't the case report back and
>> I'll take a closer look.
>
> Subnet's are okay, I know a lot about that stuff and checked them before
> sending the message.
>
> Just ran DCDiag on one Windows 2003 DC server and it came up with:
> ----------<quote>--------------------
>      Starting test: Services
>            RPCLOCATOR Service is stopped on [TIOEIN2K3]
>            TrkWks Service is stopped on [TIOEIN2K3]
>            TrkSvr Service is stopped on [TIOEIN2K3]
>         ......................... TIOEIN2K3 failed test Services
> ----------<quote>--------------------
>
> The RPCLocator service has startup type manual
> The Distributed Link Tracking Client has startup type manual
> The Distributed Link Tracking Server is disabled.
>
> The TioEin2K3 server is the PDC as well as the RID and IM for the
> staf.tio.nl domain. Would that be the cause for those stopped services to
> be
> flagged?
> At the TioAms2K3 server, a DC for the same staf domain, these same three
> services are not running but the dcdiag tool does not complain.
> However, my TioDC3 server is just a backup DC for the tio.nl domain server
> without the PDC, RID, IM roles. The three services are not running and the
> dcdiag tool IS complaining about it.
>
> I cannot find any consistency it the behaviour of the dcdiag tool. :-( Is
> that because this tool is for Windows 2000 and I'm running Windows 2003
> servers?
>
> Should I enable all those services on the servers? What is the effect of
> those three services not running?
>
> p.s. Netdiag refuses to run. Claiming: The procedure entry point
> DnsGetMaxNumberoOfAddressesToRegister could not be located in the dynamic
> link library DNSAPI.dll
> Is this caused by the discrepancy between the tools being for Windows 2000
> and my servers being Windows 2003?
>
> --
>
>
> Groetjes,
>
> Bonno Bloksma
>
>
>
Author
15 Feb 2006 12:34 AM
Paul Bergson
I have moved the port to a lower port, it should work for you now.

--


Paul Bergson  MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.


Show quoteHide quote
"Paul Bergson" <pbergson@allete_nospam.com> wrote in message
news:uSE7fRKMGHA.720@TK2MSFTNGP14.phx.gbl...
> My website uses a high port (3379) that may be why you are having trouble
> accessing it.  The netdiag issue is probably because you are using the
> wrong tools.  The tools should be located on your install cd at
> d:\support\tools\setup.exe -or-
>
> If you are using 2000 diagnostics some errors will report that don't
> really exist, whether this is the issues with services I don't know but I
> don't see any problems with the services that you have.  Yes only DC's
> will show up in sites and services, this piece of ad is used for
> replication.  Since this other dc isn't replicating anything it won;t be
> in there.
>
>
> --
>
> Paul Bergson  MCT, MCSE, MCSA, CNE, CNA, CCA
>
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> "Bonno Bloksma" <b.blok***@tio.nl> wrote in message
> news:%23RPZ$eJMGHA.3936@TK2MSFTNGP10.phx.gbl...
>> Hi,
>>
>>> > I have 5 sites. In "AD Sites and services" I have 7 subnets defined. 5
>> for
>>> > the 5 sites, 1 to include all internal ip numbers for all sites AND
>>> > the
>>> > VPN
>>> > connections and one for our DMZ.
>>> >
>>> > Some servers appear in the right "site container" but some are in the
>>> > wrong
>>> > container. All servers which are in the wrong container are in the
>>> > same
>>> > wrong container.
>>> >
>>> > One server is in my AD but does not appear in any site.
>>> >
>>> > It seems something is wrong. :-(
>>>
>>> There is definitely some change you will need to make and if you have a
>>> DC
>>> totally missing from your sites and services "Odds are it isn't
>>> performing
>>> DC services."  You should run diagnostics against the domain once you
>>> have
>>> completed the steps here.
>>
>> The one missing is just a server, not a DC. Are only DC's listed in sites
>> and services? Probably, now that I think of it. Oops my mistake. ;-(
>>
>>> From the link below download DCDIAG and NetDiag GUI tool it will help
>>> you
>>> run diagnostics as explained.
>>> http://pbbergs.dynu.com/windows/downloads.htm
>>
>> The link did not work, but I found them at the MS site.
>> http://support.microsoft.com/?kbid=265706
>>
>>> I'll also say I'm being lazy I I'm trusting that you have this all
>>> figured
>>> out subnet assignments correctly.  If this isn't the case report back
>>> and
>>> I'll take a closer look.
>>
>> Subnet's are okay, I know a lot about that stuff and checked them before
>> sending the message.
>>
>> Just ran DCDiag on one Windows 2003 DC server and it came up with:
>> ----------<quote>--------------------
>>      Starting test: Services
>>            RPCLOCATOR Service is stopped on [TIOEIN2K3]
>>            TrkWks Service is stopped on [TIOEIN2K3]
>>            TrkSvr Service is stopped on [TIOEIN2K3]
>>         ......................... TIOEIN2K3 failed test Services
>> ----------<quote>--------------------
>>
>> The RPCLocator service has startup type manual
>> The Distributed Link Tracking Client has startup type manual
>> The Distributed Link Tracking Server is disabled.
>>
>> The TioEin2K3 server is the PDC as well as the RID and IM for the
>> staf.tio.nl domain. Would that be the cause for those stopped services to
>> be
>> flagged?
>> At the TioAms2K3 server, a DC for the same staf domain, these same three
>> services are not running but the dcdiag tool does not complain.
>> However, my TioDC3 server is just a backup DC for the tio.nl domain
>> server
>> without the PDC, RID, IM roles. The three services are not running and
>> the
>> dcdiag tool IS complaining about it.
>>
>> I cannot find any consistency it the behaviour of the dcdiag tool. :-( Is
>> that because this tool is for Windows 2000 and I'm running Windows 2003
>> servers?
>>
>> Should I enable all those services on the servers? What is the effect of
>> those three services not running?
>>
>> p.s. Netdiag refuses to run. Claiming: The procedure entry point
>> DnsGetMaxNumberoOfAddressesToRegister could not be located in the dynamic
>> link library DNSAPI.dll
>> Is this caused by the discrepancy between the tools being for Windows
>> 2000
>> and my servers being Windows 2003?
>>
>> --
>>
>>
>> Groetjes,
>>
>> Bonno Bloksma
>>
>>
>>
>
>
Author
15 Feb 2006 12:43 PM
Bonno Bloksma
Hi,

> I have moved the port to a lower port, it should work for you now.

Thanks, got it.

--


Groetjes,

Bonno Bloksma
Author
12 Feb 2006 6:51 PM
Paul Williams [MVP]
Paul's answered your question well enough.  I'll just point out in summary
that if you move a DC after promotion you have to manually move the server
object between sites.  The reason being that you can add servers to
different sites for a number of design reasons.  Therefore, AD doesn't
automatically move server objects for you.  It only places the server object
in the best site when you promote the DC.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net
Author
13 Feb 2006 10:58 AM
Bonno Bloksma
Hi,

> Paul's answered your question well enough.

Yes, I'll try to download the tools just to see if there is something wrong.
However.....

>  I'll just point out in summary
> that if you move a DC after promotion you have to manually move the server
> object between sites.

THAT may be the cause. All servers were prepared by me at the Eindhoven
site, I just don't remember wheter I promoted them to DC while still at
Eindhoven or when I was at the "new" site. Anyway, that does explain why
they are sometimes in the Eindhoven site container.

> The reason being that you can add servers to
> different sites for a number of design reasons.  Therefore, AD doesn't
> automatically move server objects for you.  It only places the server
object
> in the best site when you promote the DC.

Ok, clear to me.

p.s. It seems the download page Paul gave me does not work. However,
Google's my friend and I've found the tools on the MS website. ;-)

--


Groetjes,

Bonno Bloksma