- Remove From My Forums
-
Вопрос
-
Добрый день.
Прошу помощи. Недавно появилась проблема на первом контролере домена. (у меня их два)
В логах DNS ошибка:
DNS-сервер ожидает от доменных служб Active Directory (AD DS) сигнала о том, что первичная синхронизация каталога завершена. Службу DNS-сервера невозможно запустить до завершения первичной синхронизации, так как критические данные DNS могут
быть еще не реплицированными на этот контроллер домена. Если журнал событий AD DS показывает, что имеются проблемы с разрешением DNS-имен в адреса, рассмотрите возможность добавления IP-адреса другого DNS-сервера
для этого домена в список DNS-серверов в свойствах протокола IP этого компьютера. Такое событие будет записываться в журнал каждые две минуты, пока служба AD DS не сообщит об успешном завершении первичной синхронизации.На данном сервере не проходит nslookup — 192.168.20.21
DNS request timed out.
Так же в настройках оснастки DNS не проходит простой тест и рекурсивный тест.
Запускал dcdiag /test:dns
DCDIAG пишет, что в настройках сетевого адаптера неправильный dns сервер прописан, но там как раз прописано два ip адреса dns и они правильные.
При этом если на рабочих станциях набрать nslookup — 192.168.20.21, ответ от DNS сервера есть.
Так же все тесты проходит второй контролер домена.
Так же проверял вручную репликацию между домен контролерами. Все работает без ошибок.
Очень нужна помощь.
Спасибо.
-
Изменено
1 декабря 2017 г. 8:55
-
Изменено
Ответы
-
Добрый день.
Проблема решена!
Господа Админы под знаком смерти не рекомендую Вам в своей работе использовать на серверах антивирус кАСПЕРСКОГО.
Проблема была именно в нем.
Два домен контролера, два антивируса одной версии.
Единая политика кАСПЕРСКОГО, которая как раз распространялась на эти два сервера.
На одном сервере Касперский на уровне драйвера тихо и мирно блокировал все DNS запросы.
При этом в логах у самого кАСПЕРСКОГО полная тишина.
Причем, даже если выгрузить кАСПЕРСКОГО ИЗ ПАМЯТИ, все равно на данном сервере запросы заблокированы.
Помогло удаление касперского. После удаления все запросы заработали.
Разница только в операционках и все.
Писать кАСПЕРСКОМУ бесполезно, они просто идиоты!
Всем спасибо за помощь.
-
Помечено в качестве ответа
akamsp
4 декабря 2017 г. 7:14
-
Помечено в качестве ответа
-
#1
Привет всем! На контроллере домена сыпятся eventid 4013
DNS-сервер ожидает от доменных служб Active Directory (AD DS) сигнала о том, что первичная синхронизация каталога завершена. Службу DNS-сервера невозможно запустить до завершения первичной синхронизации, так как критические данные DNS могут быть еще не реплицированными на этот контроллер домена. Если журнал событий AD DS показывает, что имеются проблемы с разрешением DNS-имен в адреса, рассмотрите возможность добавления IP-адреса другого DNS-сервера для этого домена в список DNS-серверов в свойствах протокола IP этого компьютера. Такое событие будет записываться в журнал каждые две минуты, пока служба AD DS не сообщит об успешном завершении первичной синхронизации.
Подскажите как исправить и что нужно?
Последнее редактирование модератором: 22.12.2020
-
#2
К сожалению, это — нормальное поведение: AD на хозяевах ролей FSMO в многосерверной конфигурации при недоступности остальных КД стартует долго из-за требования начальной синхронизации (http://support.microsoft.com/kb/305476). А начальная синхронизация оказывается невозможной из-за недоступости DNS.
Начальную синхронизацию можно отключить в реестре ( http://support.microsoft.com/kb/2001093 ), но это может привести к повреждению AD в случае, если в сеть будет возвращен контроллер домена, бывший хозяином роли FSMO, которые у него были принудительно захвачены (seize).
Если сейчас DNS работает и с репликацией проблем нет, то в чём тогда вопрос? Почему долго шла начальная синхронизация AD? Ответ: потому что в сети не было работоспособных DNS. Если у Вас все DNS только на контроллерах домена — то ситуация нормальная для подобной структуры. Выход: делать в сети третий DNS, который будет вторичным DNS для зон AD и будет хранить эти зоны не в AD, а в файлах. Альтернативный выход: никогда не выключать ВСЕ контроллеры домена.
несколько ответов с технета
-
#3
Привет всем! На контроллере домена сыпятся eventid 4013
Подскажите как исправить и что нужно?
посмотрите рекомендации с technet
Последнее редактирование модератором: 22.12.2020
-
#5
Попробуйте в реестре проставить параметр Repl Perform Initial Synchronizations равный 0, путь к ветке реестра тут:
Код:
[INDENT][B]HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServic esNTDSParameters[/B]
Value name: Repl Perform Initial Synchronizations
Value type: REG_DWORD
Value data: 0[/INDENT]
Проверьте есть ли у вас бэкапы схемы AD
Вот полезное видео на эту тему, очень доходчиво объясняют
Hi,
I am a newbie on this so I apologize ahead.
I have updated our Server from 2008 R2 Standard to Server 2012 Standard and the migration has passed smoothly. DNS and AD DS were both on 1 Server (2008 R2). The AD forest and Domain have been taken over without any issues. Was able to VPN into the system
with our Laptops that are on the road. There has been a total of 123 updates that needed to be done so I started that. The first attempt gave me issues and it reversed the updates. So I did it in smaller batches which worked fine. I have noticed though that
after the 3 or 4 th batch that I have installed, the VPN didn’t work any more and I got Error 812. Looked up on google and microsoft what would solve the problem and even uninstalled the Remote role and reinstalled it but the problem is still current. With
that I have then noticed that my DNS and AD DS weren’t able to communicate with each other. (Both are on 1 Server).
The following Error in Events for DNS show (ID 4013):
«The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed. The DNS server service cannot start until the initial synchronization is complete because critical
DNS data might not yet be replicated onto this domain controller. If events in the AD DS event log indicate that there is a problem with DNS name resolution, consider adding the IP address of another DNS server for this domain to the DNS server list in the
Internet Protocol properties of this computer. This event will be logged every two minutes until AD DS has signaled that the initial synchronization has successfully completed.»
I found a lot of ideas but none helped the cause. Directing the Server to point to itself with its IP (set static ip) and 127.0.0.1
The same comment is showing up in AD DS (ID 4013):
The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed. The DNS server service cannot start until the initial synchronization is complete because critical DNS
data might not yet be replicated onto this domain controller. If events in the AD DS event log indicate that there is a problem with DNS name resolution, consider adding the IP address of another DNS server for this domain to the DNS server list in the Internet
Protocol properties of this computer. This event will be logged every two minutes until AD DS has signaled that the initial synchronization has successfully completed.
I also have checked the services to be set to start automatic.
There is one solution I have not tried that microsoft has in its forum but suggests not to do it in real life process. Change settings in the regedit. Quote
«Some Microsoft and external content have recommended setting the registry valueRepl Perform Initial Synchronizations to 0 in order to bypass initial synchronization requirements in Active
Directory. The specific registry subkey and the values for that setting are as follows:
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNTDSParameters
Value name: Repl Perform Initial Synchronizations
Value type: REG_DWORD
Value data: 0
This configuration change is not recommended for use in production environments or in any environment on an ongoing basis. The use ofRepl Perform Initial Synchronizations should be used only in
critical situations to resolve temporary and specific problems. The default setting should be restored after such problems are resolved.»
Thank you in advance for your help
-
Moved by
Friday, January 5, 2018 9:40 PM
Hi,
I am a newbie on this so I apologize ahead.
I have updated our Server from 2008 R2 Standard to Server 2012 Standard and the migration has passed smoothly. DNS and AD DS were both on 1 Server (2008 R2). The AD forest and Domain have been taken over without any issues. Was able to VPN into the system
with our Laptops that are on the road. There has been a total of 123 updates that needed to be done so I started that. The first attempt gave me issues and it reversed the updates. So I did it in smaller batches which worked fine. I have noticed though that
after the 3 or 4 th batch that I have installed, the VPN didn’t work any more and I got Error 812. Looked up on google and microsoft what would solve the problem and even uninstalled the Remote role and reinstalled it but the problem is still current. With
that I have then noticed that my DNS and AD DS weren’t able to communicate with each other. (Both are on 1 Server).
The following Error in Events for DNS show (ID 4013):
«The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed. The DNS server service cannot start until the initial synchronization is complete because critical
DNS data might not yet be replicated onto this domain controller. If events in the AD DS event log indicate that there is a problem with DNS name resolution, consider adding the IP address of another DNS server for this domain to the DNS server list in the
Internet Protocol properties of this computer. This event will be logged every two minutes until AD DS has signaled that the initial synchronization has successfully completed.»
I found a lot of ideas but none helped the cause. Directing the Server to point to itself with its IP (set static ip) and 127.0.0.1
The same comment is showing up in AD DS (ID 4013):
The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed. The DNS server service cannot start until the initial synchronization is complete because critical DNS
data might not yet be replicated onto this domain controller. If events in the AD DS event log indicate that there is a problem with DNS name resolution, consider adding the IP address of another DNS server for this domain to the DNS server list in the Internet
Protocol properties of this computer. This event will be logged every two minutes until AD DS has signaled that the initial synchronization has successfully completed.
I also have checked the services to be set to start automatic.
There is one solution I have not tried that microsoft has in its forum but suggests not to do it in real life process. Change settings in the regedit. Quote
«Some Microsoft and external content have recommended setting the registry valueRepl Perform Initial Synchronizations to 0 in order to bypass initial synchronization requirements in Active
Directory. The specific registry subkey and the values for that setting are as follows:
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNTDSParameters
Value name: Repl Perform Initial Synchronizations
Value type: REG_DWORD
Value data: 0
This configuration change is not recommended for use in production environments or in any environment on an ongoing basis. The use ofRepl Perform Initial Synchronizations should be used only in
critical situations to resolve temporary and specific problems. The default setting should be restored after such problems are resolved.»
Thank you in advance for your help
-
Moved by
Friday, January 5, 2018 9:40 PM