I have a server 192.168.1.9 with Windows Server 2022 and a server 192.168.1.20 with Windows Server 2016 they both have the following roles:<\/p>\n
AD CS (1.9)<\/p>\n<\/li>\n
AD DS (1.9 and 1.20)<\/p>\n<\/li>\n
DHCP (1.9)<\/p>\n<\/li>\n
DNS (1.9 and 1.20)<\/p>\n<\/li>\n
File and Storage Services (1.9 and 1.20)<\/p>\n<\/li>\n
Hyper-V (1.9)<\/p>\n<\/li>\n
IIS (1.9 and 1.20)<\/p>\n<\/li>\n<\/ul>\n
As far as I can tell 1.9 gets replicated onto 1.20 (I’ve been told however that these 2 servers should be separate 1.9 is for employees to use and 1.20 is for an external company to work on, so very likely that this replication wouldn’t even be happening.)<\/p>\n
Right after installing DHCP and restarting things started to break.<\/p>\n
apps which used ldap as I get the error “Server is non functional” or just a crash whenever I try to do anything that might use Active Directory<\/p>\n If I try to open DNS I get “Access was denied would you like to add it anyway?”<\/p>\n Help, I don’t even know where to start.<\/p>\n On 192.168.1.9<\/p>\n On 192.168.1.20 (Sorry it’s in spanish)<\/p>\n DC1 is your fsmo role holder, but dc1 doesn’t know this.<\/p>\n How long has this been the case?<\/p>\n The DCs are not replicating, you have websites on the DCs along with a bunch of other unnecessary services, you have users (in this case, they will be domain admins) logging on externally. While you may not have put this together, it’s a mess.<\/p>\n I would get someone in to separate it all out and get the business back to a healthy state, I’m not sure how helpful a forum can be given the situation you find yourself in.<\/p>\n I could sit here and reply giving your small bits of advice and still get nowhere, I wouldn’t want for things to get worse, especially if you’re not familiar with this.<\/p>\n My advice is to contract someone to unpick this for you.<\/p>","upvoteCount":1,"datePublished":"2024-06-03T13:18:56.414Z","url":"https://community.spiceworks.com/t/windows-server-dc-broke-ad-ds-ldap/1081476/18","author":{"@type":"Person","name":"Rod-IT","url":"https://community.spiceworks.com/u/Rod-IT"}},"suggestedAnswer":[{"@type":"Answer","text":" Someone else set it up like that and I’ve only ever worked with linux.<\/p>\n 192.168.1.9<\/p>\n 192.168.1.20<\/p>\nldap://192.168.1.9:389<\/code> stopped working and for some reason I had to start using 192.168.1.20<\/p>\n
PS C:\\Users\\daviid> dcdiag\n\nDirectory Server Diagnosis\n\nPerforming initial setup:\n Trying to find home server...\n Home Server = MYORG-AD01\n Ldap search capability attribute search failed on server MYORG-AD01, return value = 52\n<\/code><\/pre>\n
PS C:\\Users\\daviid> dcdiag\n\nDiagnóstico del servidor de directorio\n\nRealizando instalación inicial:\n Intentando encontrar el servidor principal...\n Servidor principal = MYORG-OTHER\n * Se identificó el bosque de AD.\n Recopilación de información inicial finalizada.\n\nRealizando pruebas requeridas iniciales\n\n Probando servidor: Default-First-Site-Name\\MYORG-OTHER\n Iniciando prueba: Connectivity\n El host bb2ad125-79e5-4d8a-975a-c9e62e1827a7._msdcs.MYORGANIZATION.COM no se pudo resolver en una dirección IP. Compruebe el servidor DNS, el DHCP, el nombre de servidor, etc.\n Error al comprobar la conectividad de LDAP y RPC. Compruebe la configuración del firewall.\n ......................... MYORG-OTHER no superó la prueba Connectivity\n\nRealizando pruebas principales\n\n Probando servidor: Default-First-Site-Name\\MYORG-OTHER\n Omitiendo todas las pruebas porque el servidor MYORG-OTHER no responde a las solicitudes de servicio de directorio.\n\n\n Ejecutando pruebas de partición en: ForestDnsZones\n Iniciando prueba: CheckSDRefDom\n ......................... ForestDnsZones superó la prueba CheckSDRefDom\n Iniciando prueba: CrossRefValidation\n ......................... ForestDnsZones superó la prueba CrossRefValidation\n\n Ejecutando pruebas de partición en: DomainDnsZones\n Iniciando prueba: CheckSDRefDom\n ......................... DomainDnsZones superó la prueba CheckSDRefDom\n Iniciando prueba: CrossRefValidation\n ......................... DomainDnsZones superó la prueba CrossRefValidation\n\n Ejecutando pruebas de partición en: Schema\n Iniciando prueba: CheckSDRefDom\n ......................... Schema superó la prueba CheckSDRefDom\n Iniciando prueba: CrossRefValidation\n ......................... Schema superó la prueba CrossRefValidation\n\n Ejecutando pruebas de partición en: Configuration\n Iniciando prueba: CheckSDRefDom\n ......................... Configuration superó la prueba CheckSDRefDom\n Iniciando prueba: CrossRefValidation\n ......................... Configuration superó la prueba CrossRefValidation\n\n Ejecutando pruebas de partición en: MYORGANIZATION\n Iniciando prueba: CheckSDRefDom\n ......................... MYORGANIZATION superó la prueba CheckSDRefDom\n Iniciando prueba: CrossRefValidation\n ......................... MYORGANIZATION superó la prueba CrossRefValidation\n\n Ejecutando pruebas de empresa en: MYORGANIZATION.COM\n Iniciando prueba: LocatorCheck\n ......................... MYORGANIZATION.COM superó la prueba LocatorCheck\n Iniciando prueba: Intersite\n ......................... MYORGANIZATION.COM superó la prueba Intersite\n<\/code><\/pre>","upvoteCount":3,"answerCount":22,"datePublished":"2024-05-31T11:39:45.121Z","author":{"@type":"Person","name":"Daviid","url":"https://community.spiceworks.com/u/Daviid"},"acceptedAnswer":{"@type":"Answer","text":"
Windows IP Configuration\n\n Host Name . . . . . . . . . . . . : MYORG-AD01\n Primary Dns Suffix . . . . . . . : MYORGANIZATION.COM\n Node Type . . . . . . . . . . . . : Hybrid\n IP Routing Enabled. . . . . . . . : No\n WINS Proxy Enabled. . . . . . . . : No\n DNS Suffix Search List. . . . . . : MYORGANIZATION.COM\n\nEthernet adapter Ethernet:\n\n Media State . . . . . . . . . . . : Media disconnected\n Connection-specific DNS Suffix . :\n Description . . . . . . . . . . . : Intel(R) I210 Gigabit Network Connection\n Physical Address. . . . . . . . . : A0-36-BC-C8-1A-49\n DHCP Enabled. . . . . . . . . . . : Yes\n Autoconfiguration Enabled . . . . : Yes\n\nEthernet adapter Ethernet 2:\n\n Media State . . . . . . . . . . . : Media disconnected\n Connection-specific DNS Suffix . :\n Description . . . . . . . . . . . : Intel(R) I210 Gigabit Network Connection #2\n Physical Address. . . . . . . . . : A0-36-BC-C8-1A-4A\n DHCP Enabled. . . . . . . . . . . : Yes\n Autoconfiguration Enabled . . . . : Yes\n\nEthernet adapter Ethernet 3:\n\n Media State . . . . . . . . . . . : Media disconnected\n Connection-specific DNS Suffix . :\n Description . . . . . . . . . . . : Intel(R) I210 Gigabit Network Connection #3\n Physical Address. . . . . . . . . : A0-36-BC-C8-1A-4B\n DHCP Enabled. . . . . . . . . . . : Yes\n Autoconfiguration Enabled . . . . : Yes\n\nEthernet adapter Ethernet 4:\n\n Connection-specific DNS Suffix . :\n Description . . . . . . . . . . . : Intel(R) I210 Gigabit Network Connection #4\n Physical Address. . . . . . . . . : A0-36-BC-C8-1A-4C\n DHCP Enabled. . . . . . . . . . . : No\n Autoconfiguration Enabled . . . . : Yes\n IPv4 Address. . . . . . . . . . . : 192.168.1.8(Preferred)\n Subnet Mask . . . . . . . . . . . : 255.255.255.0\n IPv4 Address. . . . . . . . . . . : 192.168.1.9(Preferred)\n Subnet Mask . . . . . . . . . . . : 255.255.255.0\n Default Gateway . . . . . . . . . : 192.168.1.1\n DNS Servers . . . . . . . . . . . : 192.168.1.9\n 127.0.0.1\n NetBIOS over Tcpip. . . . . . . . : Enabled\n\nEthernet adapter vEthernet (WSL):\n\n Connection-specific DNS Suffix . :\n Description . . . . . . . . . . . : Hyper-V Virtual Ethernet Adapter\n Physical Address. . . . . . . . . : 00-15-5D-7C-AB-BF\n DHCP Enabled. . . . . . . . . . . : No\n Autoconfiguration Enabled . . . . : Yes\n Link-local IPv6 Address . . . . . : fe80::98f0:d53a:49a2:12d4%39(Preferred)\n IPv4 Address. . . . . . . . . . . : 172.26.176.1(Preferred)\n Subnet Mask . . . . . . . . . . . : 255.255.240.0\n Default Gateway . . . . . . . . . :\n DHCPv6 IAID . . . . . . . . . . . : 654316893\n DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-2B-6C-11-4E-A0-36-BC-C8-1A-49\n DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1\n fec0:0:0:ffff::2%1\n fec0:0:0:ffff::3%1\n NetBIOS over Tcpip. . . . . . . . : Enabled\n<\/code><\/pre>\n
Configuración IP de Windows\n\n Nombre de host. . . . . . . . . : MYORG-OTHER\n Sufijo DNS principal . . . . . : MYORGANIZATION.COM\n Tipo de nodo. . . . . . . . . . : híbrido\n Enrutamiento IP habilitado. . . : no\n Proxy WINS habilitado . . . . . : no\n Lista de búsqueda de sufijos DNS: MYORGANIZATION.COM\n\nAdaptador de Ethernet LAN:\n\n Estado de los medios. . . . . . . . . . . : medios desconectados\n Sufijo DNS específico para la conexión. . :\n Descripción . . . . . . . . . . . . . . . : Intel(R) I210 Gigabit Network Connection\n Dirección física. . . . . . . . . . . . . : 34-97-F6-5C-67-B1\n DHCP habilitado . . . . . . . . . . . . . : sí\n Configuración automática habilitada . . . : sí\n\nAdaptador de Ethernet WAN:\n\n Sufijo DNS específico para la conexión. . :\n Descripción . . . . . . . . . . . . . . . : Intel(R) I210 Gigabit Network Connection #2\n Dirección física. . . . . . . . . . . . . : 34-97-F6-5C-67-B2\n DHCP habilitado . . . . . . . . . . . . . : no\n Configuración automática habilitada . . . : sí\n Dirección IPv4. . . . . . . . . . . . . . : 192.168.1.20(Preferido)\n Máscara de subred . . . . . . . . . . . . : 255.255.255.0\n Puerta de enlace predeterminada . . . . . : 192.168.1.1\n Servidores DNS. . . . . . . . . . . . . . : 192.168.1.20\n 127.0.0.1\n NetBIOS sobre TCP/IP. . . . . . . . . . . : habilitado\n\nAdaptador de túnel isatap.{70D1EF34-40D9-454B-97F3-BF6DC6D5F7B6}:\n\n Estado de los medios. . . . . . . . . . . : medios desconectados\n Sufijo DNS específico para la conexión. . :\n Descripción . . . . . . . . . . . . . . . : Microsoft ISATAP Adapter\n Dirección física. . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0\n DHCP habilitado . . . . . . . . . . . . . : no\n Configuración automática habilitada . . . : sí\n\nAdaptador de túnel Teredo Tunneling Pseudo-Interface:\n\n Estado de los medios. . . . . . . . . . . : medios desconectados\n Sufijo DNS específico para la conexión. . :\n Descripción . . . . . . . . . . . . . . . : Microsoft Teredo Tunneling Adapter\n Dirección física. . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0\n DHCP habilitado . . . . . . . . . . . . . : no\n Configuración automática habilitada . . . : sí\n\nAdaptador de túnel isatap.{0523CB30-091E-4E3B-9B9E-7754D1308C8F}:\n\n Estado de los medios. . . . . . . . . . . : medios desconectados\n Sufijo DNS específico para la conexión. . :\n Descripción . . . . . . . . . . . . . . . : Microsoft ISATAP Adapter #3\n Dirección física. . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0\n DHCP habilitado . . . . . . . . . . . . . : no\n Configuración automática habilitada . . . : sí\n<\/code><\/pre>","upvoteCount":0,"datePublished":"2024-05-31T12:08:58.607Z","url":"https://community.spiceworks.com/t/windows-server-dc-broke-ad-ds-ldap/1081476/3","author":{"@type":"Person","name":"Daviid","url":"https://community.spiceworks.com/u/Daviid"}},{"@type":"Answer","text":"