Помогите разобраться, не могу поднять дочерний домен.
Делаю примерно
так: На главном контроллере (lebid.local - 192.168.1.2):
1. Разрешаю динамические обновление для зоны lebid.local
2. Создаю делегирование для zluky.lebid.local
3. Разрешаю передачу зон для _msdcs.lebid.local.
На дочернем домене (zluky.lebid.local - 192.168.1.3):
1. Поднимаю DNS сервер.
2. Создаю основную зону zluky.lebid.local
3. Копирую дополнительную зону _msdcs.lebid.local с главного контроллера.
4. Запускаю dcpromo, говорит ошибка DNS, говорю что настрою позже.
5. После окончания, меняю адрес сервера DNS c 127.0.0.1 - основной на 192.168.1.3, дополнительный - 192.168.1.2
6. Перезагружаюсь.
После перезагрузки в записях DNS сервера главного контроллера появляется CNAME запись server2.zluky.lebid.local. В сетевом окружении вижу 2 домена, по шарам ходить могу.
Но репликация не работает. В событиях вижу такие ошибки:
[more=NTDS General - 1126]
Active Directory не удается подключиться к глобальному каталогу.
Дополнительные данные
Значение ошибки:
1355 Указанный домен не существует или к нему невозможно подключиться. [/more]
[more=DNS - 4015]
DNS-серверу обнаружил критическую ошибку Active Directory. Убедитесь, что Active Directory работает правильно. Расширенная информация об ошибке: "000021A2: SvcErr: DSID-030A09F3, problem 5001 (BUSY), data 0". Данные события содержат сведения об ошибке.[/more]
[more=NTDS General - 1655]
Попытки обращения Active Directory к следующему глобальному каталогу завершились неудачно.
Глобальный каталог:
\\server1.lebid.local
Продолжение выполнения текущей операции невозможно. Active Directory воспользуется локатором контроллеров домена для поиска доступного сервера глобального каталога.
Дополнительные данные
Значение ошибки:
1908 Не удается найти контроллер этого домена. [/more]
[more=dcdiag]
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\SERVER2
Starting test: Connectivity
......................... SERVER2 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\SERVER2
Starting test: Replications
[Replications Check,SERVER2] A recent replication attempt failed:
From SERVER1 to SERVER2
Naming Context: CN=Schema,CN=Configuration,DC=lebid,DC=local
The replication generated an error (1908):
Не удается найти контроллер этого домена.
The failure occurred at 2008-10-15 23:07:36.
The last success occurred at 2008-10-15 22:59:10.
2 failures have occurred since the last success.
Kerberos Error.
A KDC was not found to authenticate the call.
Check that sufficient domain controllers are available.
......................... SERVER2 passed test Replications
Starting test: NCSecDesc
......................... SERVER2 passed test NCSecDesc
Starting test: NetLogons
......................... SERVER2 passed test NetLogons
Starting test: Advertising
......................... SERVER2 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... SERVER2 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... SERVER2 passed test RidManager
Starting test: MachineAccount
......................... SERVER2 passed test MachineAccount
Starting test: Services
......................... SERVER2 passed test Services
Starting test: ObjectsReplicated
......................... SERVER2 passed test ObjectsReplicated
Starting test: frssysvol
......................... SERVER2 passed test frssysvol
Starting test: frsevent
......................... SERVER2 passed test frsevent
Starting test: kccevent
......................... SERVER2 passed test kccevent
Starting test: systemlog
......................... SERVER2 passed test systemlog
Starting test: VerifyReferences
......................... SERVER2 passed test VerifyReferences
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Running partition tests on : zluky
Starting test: CrossRefValidation
......................... zluky passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... zluky passed test CheckSDRefDom
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running enterprise tests on : lebid.local
Starting test: Intersite
......................... lebid.local passed test Intersite
Starting test: FsmoCheck
......................... lebid.local passed test FsmoCheck[/more]
[more=netdiag]
Computer Name: SERVER2
DNS Host Name: server2.zluky.lebid.local
System info : Microsoft Windows Server 2003 (Build 3790)
Processor : x86 Family 15 Model 2 Stepping 8, GenuineIntel
List of installed hotfixes :
Q147222
Netcard queries test . . . . . . . : Passed
GetStats failed for '╧Ё ьющ ярЁрыыхы№э√щ яюЁЄ'. [ERROR_NOT_SUPPORTED]
[WARNING] The net card '╠шэшяюЁЄ WAN (PPTP)' may not be working because it h
as not received any packets.
[WARNING] The net card '╠шэшяюЁЄ WAN (PPPoE)' may not be working because it
has not received any packets.
[WARNING] The net card '╠шэшяюЁЄ WAN (IP)' may not be working because it has
not received any packets.
GetStats failed for '╠шэшяюЁЄ WAN (L2TP)'. [ERROR_NOT_SUPPORTED]
Per interface results:
Adapter : ╧юфъы■ўхэшх яю ыюъры№эющ ёхЄш
Netcard queries test . . . : Passed
Host Name. . . . . . . . . : server2
IP Address . . . . . . . . : 192.168.1.3
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . :
Dns Servers. . . . . . . . : 192.168.1.2
192.168.1.3
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Skipped
[WARNING] No gateways defined for this adapter.
NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenge
r Service', <20> 'WINS' names is missing.
No remote names have been found.
WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{AA3FC25E-14D4-4C0C-BFA9-4A13F5B18928}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Failed
[FATAL] NO GATEWAYS ARE REACHABLE.
You have no connectivity to other network segments.
If you configured the IP protocol manually then
you need to add at least one valid gateway.
NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server '192.168.1.2'
.
PASS - All the DNS entries for DC are registered on DNS server '192.168.1.3'
.
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{AA3FC25E-14D4-4C0C-BFA9-4A13F5B18928}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{AA3FC25E-14D4-4C0C-BFA9-4A13F5B18928}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Skipped
Kerberos test. . . . . . . . . . . : Passed
LDAP test. . . . . . . . . . . . . : Passed
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Skipped
Note: run "netsh ipsec dynamic show /?" for more detailed information
The command completed successfully[/more]