{"id":2546,"date":"2022-08-30T15:25:46","date_gmt":"2022-08-30T15:25:46","guid":{"rendered":"https:\/\/unknownerror.org\/index.php\/2014\/01\/30\/windows-domain-controller-dns-failure-collection-of-common-programming-errors\/"},"modified":"2022-08-30T15:25:46","modified_gmt":"2022-08-30T15:25:46","slug":"windows-domain-controller-dns-failure-collection-of-common-programming-errors","status":"publish","type":"post","link":"https:\/\/unknownerror.org\/index.php\/2022\/08\/30\/windows-domain-controller-dns-failure-collection-of-common-programming-errors\/","title":{"rendered":"Windows Domain Controller\/DNS Failure-Collection of common programming errors"},"content":{"rendered":"<p>I have a previous question up about this, but I&#8217;ve come to some new information and I figured I would start a new post to stir up some new discussion.<\/p>\n<p>To start, I will give you all a short description of our network setup (from the way I understand it). We have 2 stores. We&#8217;ll call them CP, and HQ. Now HQ is a domain controller, and we have a local domain called billsgs.net. Each store basically operates on its own. They each have a firewall, and their own server running windows server 2008 R2. The only time they interact is through replication. We have specified replicated directories, which are mostly user profiles, and our database files. This is for backup for the most part.<\/p>\n<p>Now to get onto the problem&#8230; a few weeks ago (early June) we noticed the replication service on the HQ server was hogging a ton of memory, and by a ton, I mean ALL of the available memory it could get its hands on. We have 13gbs and within 10 minutes of running DFS it was about 98% memory usage. So we stopped it. We havent really been bothered by this, but if something crashes, we are pretty much screwed on the backups. We have ran some hot fixes but nothing has worked. So as of right now, DFS is not running.<\/p>\n<p>Now, a couple of weeks ago the firewalls operating system was corrupted, I have no idea how, I wasn&#8217;t there when it happened. This was at the HQ store. So we have a broken firewall and DFS isn&#8217;t working properly. We have recently reinstalled the operating system on the firewall, which is pfsense. Everything seemed to be working fine.. except we started noticing some DNS problems. We are at the point where we don&#8217;t know if this is related to DNS\/AD\/DFS issues or if this is related to firewall issues. We basically have the firewall open, so we have decided that it&#8217;s is not a problem, at least it doesn&#8217;t seem like it. So here is a few debugging things we have done&#8230;<\/p>\n<p>Here is dcdiag output&#8230;<\/p>\n<pre><code>    C:\\Users\\Administrator&gt;dcdiag\n\n    Directory Server Diagnosis\n\n    Performing initial setup:\n     Trying to find home server...\n     Home Server = BGS-HQ-VRDSVR01\n     * Identified AD Forest.\n     Done gathering initial info.\n\n    Doing initial required tests\n\n     Testing server: BGS-HQ\\BGS-HQ-VRDSVR01\n      Starting test: Connectivity\n       ......................... BGS-HQ-VRDSVR01 passed test Connectivity\n\n    Doing primary tests\n\n     Testing server: BGS-HQ\\BGS-HQ-VRDSVR01\n      Starting test: Advertising\n       ......................... BGS-HQ-VRDSVR01 passed test Advertising\n      Starting test: FrsEvent\n       There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems.\n       ......................... BGS-HQ-VRDSVR01 passed test FrsEvent\n      Starting test: DFSREvent\n       ......................... BGS-HQ-VRDSVR01 passed test DFSREvent\n      Starting test: SysVolCheck\n       ......................... BGS-HQ-VRDSVR01 passed test SysVolCheck\n      Starting test: KccEvent\n       A warning event occurred. EventID: 0x8000082C\n       Time Generated: 08\/05\/2011 15:04:12\n       Event String:\n       A warning event occurred. EventID: 0x8000082C\n       Time Generated: 08\/05\/2011 15:05:12\n       Event String:\n       ......................... BGS-HQ-VRDSVR01 passed test KccEvent\n      Starting test: KnowsOfRoleHolders\n       ......................... BGS-HQ-VRDSVR01 passed test KnowsOfRoleHolders\n      Starting test: MachineAccount\n       ......................... BGS-HQ-VRDSVR01 passed test MachineAccount\n      Starting test: NCSecDesc\n       ......................... BGS-HQ-VRDSVR01 passed test NCSecDesc\n      Starting test: NetLogons\n       ......................... BGS-HQ-VRDSVR01 passed test NetLogons\n      Starting test: ObjectsReplicated\n       ......................... BGS-HQ-VRDSVR01 passed test ObjectsReplicated\n      Starting test: Replications\n       [Replications Check,BGS-HQ-VRDSVR01] A recent replication attempt failed:\n       From BGS-CP-VRDSVR01 to BGS-HQ-VRDSVR01\n       Naming Context: DC=ForestDnsZones,DC=billsgs,DC=net\n       The replication generated an error (1908):\n       Could not find the domain controller for this domain.\n       The failure occurred at 2011-08-05 14:34:49.\n       The last success occurred at 2011-08-05 13:51:35.\n       1 failures have occurred since the last success.\n       Kerberos Error.\n       A KDC was not found to authenticate the call.\n       Check that sufficient domain controllers are available.\n       [Replications Check,BGS-HQ-VRDSVR01] A recent replication attempt failed:\n       From BGS-CP-VRDSVR01 to BGS-HQ-VRDSVR01\n       Naming Context: DC=DomainDnsZones,DC=billsgs,DC=net\n       The replication generated an error (1908):\n       Could not find the domain controller for this domain.\n       The failure occurred at 2011-08-05 14:34:48.\n       The last success occurred at 2011-08-05 13:51:35.\n       1 failures have occurred since the last success.\n       Kerberos Error.\n       A KDC was not found to authenticate the call.\n       Check that sufficient domain controllers are available.\n       [Replications Check,BGS-HQ-VRDSVR01] A recent replication attempt failed:\n       From BGS-CP-VRDSVR01 to BGS-HQ-VRDSVR01\n       Naming Context: CN=Schema,CN=Configuration,DC=billsgs,DC=net\n       The replication generated an error (1908):\n       Could not find the domain controller for this domain.\n       The failure occurred at 2011-08-05 14:34:47.\n       The last success occurred at 2011-08-05 13:51:34.\n       1 failures have occurred since the last success.\n       Kerberos Error.\n       A KDC was not found to authenticate the call.\n       Check that sufficient domain controllers are available.\n       [Replications Check,BGS-HQ-VRDSVR01] A recent replication attempt failed:\n       From BGS-CP-VRDSVR01 to BGS-HQ-VRDSVR01\n       Naming Context: CN=Configuration,DC=billsgs,DC=net\n       The replication generated an error (1908):\n       Could not find the domain controller for this domain.\n       The failure occurred at 2011-08-05 14:34:46.\n       The last success occurred at 2011-08-05 13:51:34.\n       1 failures have occurred since the last success.\n       Kerberos Error.\n       A KDC was not found to authenticate the call.\n       Check that sufficient domain controllers are available.\n       [Replications Check,BGS-HQ-VRDSVR01] A recent replication attempt failed:\n       From BGS-CP-VRDSVR01 to BGS-HQ-VRDSVR01\n       Naming Context: DC=billsgs,DC=net\n       The replication generated an error (1908):\n       Could not find the domain controller for this domain.\n       The failure occurred at 2011-08-05 14:34:46.\n       The last success occurred at 2011-08-05 13:51:34.\n       1 failures have occurred since the last success.\n       Kerberos Error.\n       A KDC was not found to authenticate the call.\n       Check that sufficient domain controllers are available.\n       ......................... BGS-HQ-VRDSVR01 failed test Replications\n      Starting test: RidManager\n       ......................... BGS-HQ-VRDSVR01 passed test RidManager\n      Starting test: Services\n       Invalid service startup type: DFSR on BGS-HQ-VRDSVR01, current value DISABLED, expected value AUTO_START\n       DFSR Service is stopped on [BGS-HQ-VRDSVR01]\n       ......................... BGS-HQ-VRDSVR01 failed test Services\n      Starting test: SystemLog\n       A warning event occurred. EventID: 0x00000458\n       Time Generated: 08\/05\/2011 14:08:10\n       Event String:\n       The Group Policy Client Side Extension Folder Redirection was unable to apply one or more settings because the changes must be processed before system startup or u\n    ser logon. The system will wait for Group Policy processing to finish completely before the next startup or logon for this user, and this may result in slow startup and boot p\n    erformance.\n       An error event occurred. EventID: 0x00000456\n       Time Generated: 08\/05\/2011 14:23:08\n       Event String:\n       The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest. Ensure the user domain name matches th\n    e name of a trusted domain that resides in the same forest as the computer account.\n       An error event occurred. EventID: 0xC0001B78\n       Time Generated: 08\/05\/2011 14:28:16\n       Event String:\n       The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the DFS Replication service, but this actio\n    n failed with the following error:\n       An error event occurred. EventID: 0xC000271A\n       Time Generated: 08\/05\/2011 14:31:28\n       Event String: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout.\n       A warning event occurred. EventID: 0x8000001D\n       Time Generated: 08\/05\/2011 14:34:09\n       Event String:\n       The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon m\n    ay not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certi\n    ficate.\n       A warning event occurred. EventID: 0x000003F6\n       Time Generated: 08\/05\/2011 14:34:13\n       Event String: Name resolution for the name billsgs.net timed out after none of the configured DNS servers responded.\n       An error event occurred. EventID: 0xC0001B58\n       Time Generated: 08\/05\/2011 14:34:48\n       Event String: The DgiVecp service failed to start due to the following error:\n       An error event occurred. EventID: 0x0000168E\n       Time Generated: 08\/05\/2011 14:34:55\n       Event String:\n       The dynamic registration of the DNS record '6282bfca-ade1-41c8-84dc-516ce19b49be._msdcs.billsgs.net. 600 IN CNAME BGS-HQ-VRDSVR01.billsgs.net.' failed on the follo\n    wing DNS server:\n       An error event occurred. EventID: 0x0000168E\n       Time Generated: 08\/05\/2011 14:34:56\n       Event String:\n       The dynamic registration of the DNS record '_kpasswd._udp.billsgs.net. 600 IN SRV 0 100 464 BGS-HQ-VRDSVR01.billsgs.net.' failed on the following DNS server:\n       A warning event occurred. EventID: 0x00002724\n       Time Generated: 08\/05\/2011 14:34:56\n       Event String: This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.\n       A warning event occurred. EventID: 0x000003F6\n       Time Generated: 08\/05\/2011 14:34:55\n       Event String: Name resolution for the name billsgs.net timed out after none of the configured DNS servers responded.\n       An error event occurred. EventID: 0xC00110F1\n       Time Generated: 08\/05\/2011 14:35:09\n       Event String: The WINS Server could not initialize security to allow the read-only operations.\n       An error event occurred. EventID: 0xC0002720\n       Time Generated: 08\/05\/2011 14:36:05\n       Event String: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID\n       A warning event occurred. EventID: 0x000727AA\n       Time Generated: 08\/05\/2011 14:38:30\n       Event String: The WinRM service failed to create the following SPNs: WSMAN\/BGS-HQ-VRDSVR01.billsgs.net; WSMAN\/BGS-HQ-VRDSVR01.\n       A warning event occurred. EventID: 0x0000043D\n       Time Generated: 08\/05\/2011 14:47:48\n       Event String:\n       Windows failed to apply the Folder Redirection settings. Folder Redirection settings might have its own log file. Please click on the \"More information\" link.\n       An error event occurred. EventID: 0x0000168E\n       Time Generated: 08\/05\/2011 15:02:25\n       Event String:\n       The dynamic registration of the DNS record '6282bfca-ade1-41c8-84dc-516ce19b49be._msdcs.billsgs.net. 600 IN CNAME BGS-HQ-VRDSVR01.billsgs.net.' failed on the follo\n    wing DNS server:\n       An error event occurred. EventID: 0x0000168E\n       Time Generated: 08\/05\/2011 15:02:26\n       Event String:\n       The dynamic registration of the DNS record '_kpasswd._udp.billsgs.net. 600 IN SRV 0 100 464 BGS-HQ-VRDSVR01.billsgs.net.' failed on the following DNS server:\n       ......................... BGS-HQ-VRDSVR01 failed test SystemLog\n      Starting test: VerifyReferences\n       ......................... BGS-HQ-VRDSVR01 passed test VerifyReferences\n\n\n     Running partition tests on : ForestDnsZones\n      Starting test: CheckSDRefDom\n       ......................... ForestDnsZones passed test CheckSDRefDom\n      Starting test: CrossRefValidation\n       ......................... ForestDnsZones passed test CrossRefValidation\n\n     Running partition tests on : DomainDnsZones\n      Starting test: CheckSDRefDom\n       ......................... DomainDnsZones passed test CheckSDRefDom\n      Starting test: CrossRefValidation\n       ......................... DomainDnsZones passed test CrossRefValidation\n\n     Running partition tests on : Schema\n      Starting test: CheckSDRefDom\n       ......................... Schema passed test CheckSDRefDom\n      Starting test: CrossRefValidation\n       ......................... Schema passed test CrossRefValidation\n\n     Running partition tests on : Configuration\n      Starting test: CheckSDRefDom\n       ......................... Configuration passed test CheckSDRefDom\n      Starting test: CrossRefValidation\n       ......................... Configuration passed test CrossRefValidation\n\n     Running partition tests on : billsgs\n      Starting test: CheckSDRefDom\n       ......................... billsgs passed test CheckSDRefDom\n      Starting test: CrossRefValidation\n       ......................... billsgs passed test CrossRefValidation\n\n     Running enterprise tests on : billsgs.net\n      Starting test: LocatorCheck\n       ......................... billsgs.net passed test LocatorCheck\n      Starting test: Intersite\n       ......................... billsgs.net passed test Intersite\n<\/code><\/pre>\n<p>Now, keep in mind this is pretty different everytime we restart the server. Sometimes we have issues related to DCOM being unable to reach our specified dns servers! Now.. here is the output of a dns test&#8230;<\/p>\n<pre><code>C:\\Users\\Administrator&gt;dcdiag \/test:DNS\n\nDirectory Server Diagnosis\n\nPerforming initial setup:\n Trying to find home server...\n Home Server = BGS-HQ-VRDSVR01\n * Identified AD Forest.\n Done gathering initial info.\n\nDoing initial required tests\n\n Testing server: BGS-HQ\\BGS-HQ-VRDSVR01\n  Starting test: Connectivity\n   ......................... BGS-HQ-VRDSVR01 passed test Connectivity\n\nDoing primary tests\n\n Testing server: BGS-HQ\\BGS-HQ-VRDSVR01\n\n  Starting test: DNS\n\n   DNS Tests are running and not hung. Please wait a few minutes...\n   ......................... BGS-HQ-VRDSVR01 passed test DNS\n\n Running partition tests on : ForestDnsZones\n\n Running partition tests on : DomainDnsZones\n\n Running partition tests on : Schema\n\n Running partition tests on : Configuration\n\n Running partition tests on : billsgs\n\n Running enterprise tests on : billsgs.net\n  Starting test: DNS\n   Test results for domain controllers:\n\n   DC: BGS-HQ-VRDSVR01.billsgs.net\n   Domain: billsgs.net\n\n\n    TEST: Basic (Basc)\n     Warning: adapter [00000007] Intel(R) PRO\/1000 MT Network Connection has invalid DNS server: 192.168.40.254 ()\n\n    TEST: Records registration (RReg)\n     Network Adapter [00000007] Intel(R) PRO\/1000 MT Network Connection:\n      Warning:\n      Missing SRV record at DNS server 192.168.40.13:\n      _ldap._tcp.billsgs.net\n\n      Warning:\n      Missing SRV record at DNS server 192.168.40.13:\n      _ldap._tcp.22017278-29d1-493a-b72d-e44b31411a70.domains._msdcs.billsgs.net\n\n      Warning:\n      Missing SRV record at DNS server 192.168.40.13:\n      _kerberos._tcp.dc._msdcs.billsgs.net\n\n      Warning:\n      Missing SRV record at DNS server 192.168.40.13:\n      _ldap._tcp.dc._msdcs.billsgs.net\n\n      Warning:\n      Missing SRV record at DNS server 192.168.40.13:\n      _kerberos._tcp.billsgs.net\n\n      Warning:\n      Missing SRV record at DNS server 192.168.40.13:\n      _kerberos._udp.billsgs.net\n\n      Warning:\n      Missing SRV record at DNS server 192.168.40.13:\n      _kpasswd._tcp.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.13:\n      _ldap._tcp.BGS-HQ._sites.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.13:\n      _kerberos._tcp.BGS-HQ._sites.dc._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.13:\n      _ldap._tcp.BGS-HQ._sites.dc._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.13:\n      _kerberos._tcp.BGS-HQ._sites.billsgs.net\n\n      Warning:\n      Missing SRV record at DNS server 192.168.40.13:\n      _ldap._tcp.gc._msdcs.billsgs.net\n\n      Warning:\n      Missing A record at DNS server 192.168.40.13:\n      gc._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.13:\n      _gc._tcp.BGS-HQ._sites.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.13:\n      _ldap._tcp.BGS-HQ._sites.gc._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.13:\n      _ldap._tcp.pdc._msdcs.billsgs.net\n\n      Warning:\n      Missing CNAME record at DNS server 192.168.40.254:\n      6282bfca-ade1-41c8-84dc-516ce19b49be._msdcs.billsgs.net\n\n      Warning:\n      Missing A record at DNS server 192.168.40.254:\n      BGS-HQ-VRDSVR01.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _ldap._tcp.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _ldap._tcp.22017278-29d1-493a-b72d-e44b31411a70.domains._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _kerberos._tcp.dc._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _ldap._tcp.dc._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _kerberos._tcp.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _kerberos._udp.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _kpasswd._tcp.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _ldap._tcp.BGS-HQ._sites.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _kerberos._tcp.BGS-HQ._sites.dc._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _ldap._tcp.BGS-HQ._sites.dc._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _kerberos._tcp.BGS-HQ._sites.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _ldap._tcp.gc._msdcs.billsgs.net\n\n      Warning:\n      Missing A record at DNS server 192.168.40.254:\n      gc._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _gc._tcp.BGS-HQ._sites.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _ldap._tcp.BGS-HQ._sites.gc._msdcs.billsgs.net\n\n      Error:\n      Missing SRV record at DNS server 192.168.40.254:\n      _ldap._tcp.pdc._msdcs.billsgs.net\n\n    Error: Record registrations cannot be found for all the network adapters\n\n   Summary of test results for DNS servers used by the above domain controllers:\n\n   DNS server: 192.168.40.254 ()\n    1 test failure on this DNS server\n    Name resolution is not functional. _ldap._tcp.billsgs.net. failed on the DNS server 192.168.40.254\n\n   Summary of DNS test results:\n\n           Auth Basc Forw Del Dyn RReg Ext\n   _________________________________________________________________\n   Domain: billsgs.net\n    BGS-HQ-VRDSVR01    PASS WARN PASS PASS PASS FAIL n\/a\n\n   ......................... billsgs.net failed test DNS\n\nC:\\Users\\Administrator&gt;\n<\/code><\/pre>\n<p>I believe this is our main issue, but I&#8217;m lost on the whole thing. I&#8217;ve given the netlogon restart trick a few tries. I&#8217;ve even ran the following sequence:<\/p>\n<pre><code>net stop netlogon\nnet stop dns\nipconfig \/flushdns\nnet start dns\nnet start netlogon\n<\/code><\/pre>\n<p>Nothing seems to work. Just recently, today, we went into &#8220;active directory users and computers&#8221;, and under &#8220;Domain Controllers&#8221;, the HQ server is not listed. It simply says unavailable.<\/p>\n<p>Also.. here is an ip config output&#8230;<\/p>\n<pre><code>Microsoft Windows [Version 6.1.7600]\nCopyright (c) 2009 Microsoft Corporation. All rights reserved.\n\nC:\\Users\\Administrator&gt;ipconfig \/all\n\nWindows IP Configuration\n\n Host Name . . . . . . . . . . . . : BGS-HQ-VRDSVR01\n Primary Dns Suffix . . . . . . . : billsgs.net\n Node Type . . . . . . . . . . . . : Hybrid\n IP Routing Enabled. . . . . . . . : No\n WINS Proxy Enabled. . . . . . . . : No\n DNS Suffix Search List. . . . . . : billsgs.net\n\nEthernet adapter Local Area Connection:\n\n Connection-specific DNS Suffix . :\n Description . . . . . . . . . . . : Intel(R) PRO\/1000 MT Network Connection\n Physical Address. . . . . . . . . : 00-0C-29-03-BA-38\n DHCP Enabled. . . . . . . . . . . : No\n Autoconfiguration Enabled . . . . : Yes\n IPv4 Address. . . . . . . . . . . : 192.168.40.13(Preferred)\n Subnet Mask . . . . . . . . . . . : 255.255.255.0\n Default Gateway . . . . . . . . . : 192.168.40.254\n DNS Servers . . . . . . . . . . . : 192.168.40.13\n          192.168.40.254\n Primary WINS Server . . . . . . . : 192.168.40.13\n Secondary WINS Server . . . . . . : 192.168.41.17\n NetBIOS over Tcpip. . . . . . . . : Enabled\n\nTunnel adapter isatap.{ADEC15A8-2603-40EB-964C-489CCBD11E08}:\n\n Media State . . . . . . . . . . . : Media disconnected\n Connection-specific DNS Suffix . :\n Description . . . . . . . . . . . : Microsoft ISATAP Adapter\n Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0\n DHCP Enabled. . . . . . . . . . . : No\n Autoconfiguration Enabled . . . . : Yes\n\nTunnel adapter Local Area Connection* 11:\n\n Media State . . . . . . . . . . . : Media disconnected\n Connection-specific DNS Suffix . :\n Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface\n Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0\n DHCP Enabled. . . . . . . . . . . : No\n Autoconfiguration Enabled . . . . : Yes\n\nC:\\Users\\Administrator&gt;\n<\/code><\/pre>\n<p>192.168.40.13 is HQ and 192.168.41.17 is CP. Also 192.168.40.254 is the HQ firewall, and 192.168.41.254 is the CP firewall.<\/p>\n<p>To tie this all together, we are basically down to the servers aren&#8217;t communicating. The DNS seems to be the main issue, like I said. Any example of this would be.. from the HQ network, If I run <strong><em>nslookup billsgs.net<\/em><\/strong> the address is 192.168.41.17 which is the CP servers address. With that said, no one can &#8220;access&#8221; the active directory from the HQ location. Meaning.. \\\\billsgs.net is inaccessible via the HQ network.<\/p>\n<ol>\n<li>\n<p>You are right AD issues are almost <em>always<\/em> DNS issues. I think the issue is with having the firewall set as a secondary DNS on your DC IP settings. Remove that from the NIC configuration and instead add the firewall as a forwarder in the DNS configuration.<\/p>\n<p>This will force all DNS resolution to start with the Windows DNS and addresses it doesn&#8217;t know about will be queried through the forwarder.<\/p>\n<p>Once you reset the DNS settings, run <code>ipconfig \/registerdns<\/code> on the DC to fix the AD registrations in DNS.<\/p>\n<p>Also, all your Windows servers and clients should point only to this DNS. If you need an alternate DNS, install DNS on another server (it does <em>not<\/em> need to be a DC to run DNS).<\/p>\n<\/li>\n<\/ol>\n<p id=\"rop\"><small>Originally posted 2014-01-30 07:19:23. <\/small><\/p>","protected":false},"excerpt":{"rendered":"<p>I have a previous question up about this, but I&#8217;ve come to some new information and I figured I would start a new post to stir up some new discussion. To start, I will give you all a short description of our network setup (from the way I understand it). We have 2 stores. We&#8217;ll [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2546","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/unknownerror.org\/index.php\/wp-json\/wp\/v2\/posts\/2546","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unknownerror.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unknownerror.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unknownerror.org\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/unknownerror.org\/index.php\/wp-json\/wp\/v2\/comments?post=2546"}],"version-history":[{"count":0,"href":"https:\/\/unknownerror.org\/index.php\/wp-json\/wp\/v2\/posts\/2546\/revisions"}],"wp:attachment":[{"href":"https:\/\/unknownerror.org\/index.php\/wp-json\/wp\/v2\/media?parent=2546"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unknownerror.org\/index.php\/wp-json\/wp\/v2\/categories?post=2546"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unknownerror.org\/index.php\/wp-json\/wp\/v2\/tags?post=2546"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}