Share via


Server Manager BPA reports numerous DNS errors

Question

Wednesday, April 27, 2016 11:06 PM

The logged errors below are from 2012 R2 Server, just a single Server in a small medical office.  It replaced a 2003 Server and AD was migrated to this machine.  The old Server is gone.  This Server appears to function normally but the fix for these BPA errors that show up in the Server Manager eludes me.  There is only 1 NIC configured and the Servers IP is specified as the primary DNS and the Router's IP is specified as the secondary DNS.  I've done it that way for years on many Servers so I can't understand what is happening here.  The Server is doing DHCP for the work stations and DHCP is turned off in the Router.   

Title:
DNS: DNS servers on NIC1 should include the loopback address, but not as the first entry.

Severity
Error

Date:
3/22/2016 4:27:28 PM

Category:
Configuration

Problem:
The network adapter NIC1 does not list the local server as a DNS server; or it is configured as the first DNS server on this adapter.

Impact:
If the loopback IP address is the first entry in the list of DNS servers, Active Directory might be unable to find its replication partners.

Resolution
Configure adapter settings to add the loopback IP address to the list of DNS servers on all active interfaces, but not as the first server in the list.

http://go.microsoft.com/fwlink/?LinkId=188760

Title:
DNS: Zone TrustAnchors secondary servers must respond to queries for the zone.

Severity
Error

Date:
3/22/2016 4:27:28 PM

Category:
Configuration

Problem:
None of the secondary servers configured for zone TrustAnchors are responding.

Impact:
Secondary servers will fail DNS queries for the zone TrustAnchors.

Resolution
Validate secondary servers for zone TrustAnchors.

http://go.microsoft.com/fwlink/?LinkId=188791

Title:
DNS: The DNS server 192.168.1.1 on NIC1 must resolve Global Catalog resource records for the domain controller

Severity
Error

Date:
3/22/2016 4:27:28 PM

Category:
Configuration

Problem:
The DNS server 192.168.1.1 on NIC1 did not successfully resolve the name _ldap._tcp.gc._msdcs.BH.local.

Impact:
Active Directory Domain Services (AD DS) operations that depend on locating a Global Catalog will fail.

Resolution
Click Start, click Network, click Network and Sharing Center, and then click Change adapter settings to configure DNS servers that can resolve the name _ldap._tcp.gc._msdcs.BH.local.

http://go.microsoft.com/fwlink/?LinkId=121970

Title:
DNS: The DNS server 192.168.1.1 on NIC1 must resolve Kerberos resource records for the domain controller

Severity
Error

Date:
3/22/2016 4:27:28 PM

Category:
Configuration

Problem:
The DNS server 192.168.1.1 on NIC1 did not successfully resolve the name _kerberos._tcp.BH.local.

Impact:
Active Directory Domain Services (AD DS) operations that depend on locating a Kerberos Key Distribution Center(KDC) will fail.

Resolution
Click Start, click Network, click Network and Sharing Center, and then click Change adapter settings to configure DNS servers that can resolve the name _kerberos._tcp.BH.local.

http://go.microsoft.com/fwlink/?LinkId=121967

Title:
DNS: The DNS server 192.168.1.1 on NIC1 must resolve LDAP resource records for the domain controller

Severity
Error

Date:
3/22/2016 4:27:28 PM

Category:
Configuration

Problem:
The DNS server 192.168.1.1 on NIC1 did not successfully resolve the name _ldap._tcp.BH.local.

Impact:
Active Directory Domain Services (AD DS) operations that depend on locating domain controllers will fail.

Resolution
Click Start, click Network, click Network and Sharing Center, and then click Change adapter settings to configure DNS servers that can resolve the name _ldap._tcp.BH.local.

http://go.microsoft.com/fwlink/?LinkId=121972

Title:
DNS: The DNS server 192.168.1.1 on the NIC1 must resolve PDC resource records for the domain controller

Severity
Error

Date:
3/22/2016 4:27:28 PM

Category:
Configuration

Problem:
The DNS server 192.168.1.1 on NIC1 did not successfully resolve the name _ldap._tcp.pdc._msdcs.BH.local.

Impact:
Active Directory Domain Services (AD DS) operations that depend on locating a Primary Domain Controller will fail.

Resolution
Click Start, click Network, click Network and Sharing Center, and then click Change adapter settings to configure DNS servers that can resolve the name _ldap._tcp.pdc._msdcs.BH.local.

http://go.microsoft.com/fwlink/?LinkId=121971

Title:
DNS: The DNS server 192.168.1.1 on NIC1 must resolve names in the forest root domain name zone

Severity
Error

Date:
3/22/2016 4:27:28 PM

Category:
Configuration

Problem:
The DNS server 192.168.1.1 on NIC1 did not successfully resolve the name for the start of authority (SOA) record of the zone hosting the computer's forest root domain name.

Impact:
Active Directory Domain Services (AD DS) operations that depend on locating domain controllers will fail.

Resolution
Click Start, click Network, click Network and Sharing Center, and then click Change adapter settings to remove all invalid or unresponsive DNS servers.

http://go.microsoft.com/fwlink/?LinkId=121974

Title:
DNS: The DNS server 192.168.1.1 on NIC1 must resolve names in the primary DNS domain zone

Severity
Error

Date:
3/22/2016 4:27:28 PM

Category:
Configuration

Problem:
The DNS server 192.168.1.1 on NIC1 did not successfully resolve the name for the start of authority (SOA) record of the zone hosting the computer's primary DNS domain name.

Impact:
Active Directory Domain Services (AD DS) operations that depend on locating domain controllers will fail.

Resolution
Click Start, click Network, click Network and Sharing Center, and then click Change adapter settings to remove or replace all invalid or unresponsive DNS servers.

http://go.microsoft.com/fwlink/?LinkId=121973

All replies (4)

Thursday, April 28, 2016 12:16 AM

You have DNS registration / resolution issue. Please configure your DC as I recommended here then run ipconfig /registerdns and restart netlogon service.

This posting is provided AS IS with no warranties or guarantees , and confers no rights.

Ahmed MALEK

My Website Link

My Linkedin Profile

My MVP Profile


Thursday, April 28, 2016 7:27 AM

Hi Mike,

1. Is the DC multihomed? It is not recommended to make DC multihomed since it may cause some odd issues.

2. On DC's NIC, it is recommended to configure DNS setting: "Preferred DNS server address" with IP address of the DC; "Alternate DNS server address" with 127.0.0.1.

3.It is better if you can post the result of ipconfig/all here.

4. Please run dcdiag in cmd to test the health of the DC.

5. As Mr X suggested, please restart netlogon service to re-registry SRV records.

Best Regards,

Anne

Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected].


Thursday, April 28, 2016 3:33 PM

Directory Server Diagnosis

Performing initial setup:

   Trying to find home server...

   Home Server = BH-2012-Server

   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

  
   Testing server: Default-First-Site-Name\BH-2012-SERVER

      Starting test: Connectivity

         ......................... BH-2012-SERVER passed test Connectivity

Doing primary tests

  
   Testing server: Default-First-Site-Name\BH-2012-SERVER

      Starting test: Advertising

         ......................... BH-2012-SERVER passed test Advertising

      Starting test: FrsEvent

         ......................... BH-2012-SERVER passed test FrsEvent

      Starting test: DFSREvent

         ......................... BH-2012-SERVER passed test DFSREvent

      Starting test: SysVolCheck

         ......................... BH-2012-SERVER passed test SysVolCheck

      Starting test: KccEvent

         ......................... BH-2012-SERVER passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... BH-2012-SERVER passed test

         KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... BH-2012-SERVER passed test MachineAccount

      Starting test: NCSecDesc

         ......................... BH-2012-SERVER passed test NCSecDesc

      Starting test: NetLogons

         ......................... BH-2012-SERVER passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... BH-2012-SERVER passed test ObjectsReplicated

      Starting test: Replications

         ......................... BH-2012-SERVER passed test Replications

      Starting test: RidManager

         ......................... BH-2012-SERVER passed test RidManager

      Starting test: Services

         ......................... BH-2012-SERVER passed test Services

      Starting test: SystemLog

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   10:30:17

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   10:30:17

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   10:30:17

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         A warning event occurred.  EventID: 0x80000109

            Time Generated: 04/28/2016   10:40:50

            Event String:

            A pointer device did not report a valid unit of angular measurement.

         A warning event occurred.  EventID: 0x80000101

            Time Generated: 04/28/2016   10:40:50

            Event String:

            A pointer device reported a bad angular physical range.

         A warning event occurred.  EventID: 0x80000102

            Time Generated: 04/28/2016   10:40:50

            Event String:

            A pointer device reported a bad angular logical range.

         A warning event occurred.  EventID: 0x80000109

            Time Generated: 04/28/2016   10:40:50

            Event String:

            A pointer device did not report a valid unit of angular measurement.

         A warning event occurred.  EventID: 0x80000101

            Time Generated: 04/28/2016   10:40:50

            Event String:

            A pointer device reported a bad angular physical range.

         A warning event occurred.  EventID: 0x80000102

            Time Generated: 04/28/2016   10:40:50

            Event String:

            A pointer device reported a bad angular logical range.

         A warning event occurred.  EventID: 0x80000109

            Time Generated: 04/28/2016   10:40:50

            Event String:

            A pointer device did not report a valid unit of angular measurement.

         A warning event occurred.  EventID: 0x80000101

            Time Generated: 04/28/2016   10:40:50

            Event String:

            A pointer device reported a bad angular physical range.

         A warning event occurred.  EventID: 0x80000102

            Time Generated: 04/28/2016   10:40:50

            Event String:

            A pointer device reported a bad angular logical range.

         An error event occurred.  EventID: 0xC0001B58

            Time Generated: 04/28/2016   10:41:59

            Event String:

            The Diagnostic Service Host service failed to start due to the following error:

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   10:45:18

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   10:45:18

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   10:45:18

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         An error event occurred.  EventID: 0x00009018

            Time Generated: 04/28/2016   10:51:41

            Event String:

            A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

         An error event occurred.  EventID: 0x00009018

            Time Generated: 04/28/2016   10:51:41

            Event String:

            A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

         An error event occurred.  EventID: 0x00009018

            Time Generated: 04/28/2016   10:53:48

            Event String:

            A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

         An error event occurred.  EventID: 0x00009018

            Time Generated: 04/28/2016   10:53:48

            Event String:

            A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 1203.

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   11:00:18

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   11:00:18

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   11:00:18

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   11:15:20

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   11:15:21

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         An error event occurred.  EventID: 0x00002716

            Time Generated: 04/28/2016   11:15:21

            Event String:

            DCOM got error "2147944122" from the computer 192.168.1.31 when attempting to activate the server:

         A warning event occurred.  EventID: 0x000003F6

            Time Generated: 04/28/2016   11:15:28

            Event String:

            Name resolution for the name 63.1.168.192.in-addr.arpa. timed out after none of the configured DNS servers responded.

         ......................... BH-2012-SERVER failed test SystemLog

      Starting test: VerifyReferences

         ......................... BH-2012-SERVER passed test VerifyReferences

  
  
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

  
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

  
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

  
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

  
   Running partition tests on : BH

      Starting test: CheckSDRefDom

         ......................... BH passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... BH passed test CrossRefValidation

  
   Running enterprise tests on : BH.local

      Starting test: LocatorCheck

         ......................... BH.local passed test LocatorCheck

      Starting test: Intersite

         ......................... BH.local passed test Intersite


Thursday, April 28, 2016 3:35 PM

Windows IP Configuration

   Host Name . . . . . . . . . . . . : BH-2012-Server
   Primary Dns Suffix  . . . . . . . : BH.local
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : BH.local

Ethernet adapter NIC1:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet
   Physical Address. . . . . . . . . : F8-BC-12-47-47-AC
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::3d77:1d7a:6269:c281%12(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.1.3(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.1
   DHCPv6 IAID . . . . . . . . . . . : 217627666
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1B-3C-74-2D-F8-BC-12-47-47-AC
   DNS Servers . . . . . . . . . . . : 192.168.1.3
                                       127.0.0.1
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{38AC1282-C278-43FF-8551-71BCCB7C54CF}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes