询问者
域控制器报错

问题
-
域控制器日志报错,日志ID2087。日志中提到的Share01这台电脑,确认已重装系统,不存在域。
请帮忙看下怎么操作,如需要使用工具,请告之如何操作,谢谢!
Active Directory Domain Services could not resolve the following DNS host name of the source domain controller to an IP address. This error prevents additions, deletions and changes in Active Directory Domain Services from replicating between one or more domain controllers in the forest. Security groups, group policy, users and computers and their passwords will be inconsistent between domain controllers until this error is resolved, potentially affecting logon authentication and access to network resources.
Source domain controller:
share01
Failing DNS host name:
40531965-5a04-4224-8484-59411c7fe1d8._msdcs.vortice-china.local
NOTE: By default, only up to 10 DNS failures are shown for any given 12 hour period, even if more than 10 failures occur. To log all individual failure events, set the following diagnostics registry value to 1:
Registry Path:
HKLM\System\CurrentControlSet\Services\NTDS\Diagnostics\22 DS RPC Client
User Action:
1) If the source domain controller is no longer functioning or its operating system has been reinstalled with a different computer name or NTDSDSA object GUID, remove the source domain controller's metadata with ntdsutil.exe, using the steps outlined in MSKB article 216498.
2) Confirm that the source domain controller is running Active Directory Domain Services and is accessible on the network by typing "net view \\<source DC name>" or "ping <source DC name>".
3) Verify that the source domain controller is using a valid DNS server for DNS services, and that the source domain controller's host record and CNAME record are correctly registered, using the DNS Enhanced version of DCDIAG.EXE available on http://www.microsoft.com/dns
dcdiag /test:dns
4) Verify that this destination domain controller is using a valid DNS server for DNS services, by running the DNS Enhanced version of DCDIAG.EXE command on the console of the destination domain controller, as follows:
dcdiag /test:dns
5) For further analysis of DNS error failures see KB 824449:
http://support.microsoft.com/?kbid=824449
Additional Data
Error value:
11004 The requested name is valid, but no data of the requested type was found.
全部回复
-
您好
以下提供一些关于日志ID2087的解决方案,建议从以下几个方面进行考虑:
- 首先,确定源域控制器是否正常运行。如果源域控制器不起作用,请从AD DS中删除其余的元数据。
- 如果源域控制器正在运行,请根据需要继续执行诊断和解决DNS问题的过程:
- 使用Dcdiag诊断DNS问题。
- 注册DNS服务(SRV)资源记录和主机记录。
- 同步源和目标域控制器之间的复制。
- 验证NTDS设置GUID的一致性。
关于具体每个步骤该如何操作,可参考此链接:https://support.microsoft.com/en-us/help/4469661/active-directory-replication-event-id-2087-dns-lookup-failure-caused-r
Best Regards,
Fan
Please remember to mark the replies as an answers if they help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com
- 已建议为答案 flingminMicrosoft contingent staff 2019年5月29日 8:23