DCDIAG and NETDIAG point to no Issue but many Error Events



My both Domain controller having Critical Issues. I ran Netdiag and DCdiag
but I don't see any serious issue. When I ran DCDIAG /test:dns , it tell me I
have broken delegation and there are many other issues are loged into Event
Logs of Both DC1 and DC2 and all Memeber servers and Workstations.

Please guide me proper path to tackle these issues. If I have to use my 2
free support calls I will.

Here are the Netdiag and Dcdiag.



Computer Name: DC1
DNS Host Name: dc1.Domain.com
System info : Microsoft Windows Server 2003 R2 (Build 3790)
Processor : x86 Family 6 Model 15 Stepping 7, GenuineIntel
List of installed hotfixes :

Netcard queries test . . . . . . . : Passed

Per interface results:

Adapter : Team 1

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : dc1
IP Address . . . . . . . . :
Subnet Mask. . . . . . . . :
Default Gateway. . . . . . :
Primary WINS Server. . . . :
Secondary WINS Server. . . :
Dns Servers. . . . . . . . :

AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03>
r Service', <20> 'WINS' names is missing.
No remote names have been found.

WINS service test. . . . . : Passed

Global results:

Domain membership test . . . . . . : Passed

NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
1 NetBt transport currently configured.

Autonet address test . . . . . . . : Passed

IP loopback ping test. . . . . . . : Passed

Default gateway test . . . . . . . : Passed

NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation
ce', <03> 'Messenger Service', <20> 'WINS' names defined.

Winsock test . . . . . . . . . . . : Passed

DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server
and other DCs also have some of the names registered.

Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
The browser is bound to 1 NetBt transport.

DC discovery test. . . . . . . . . : Passed

DC list test . . . . . . . . . . . : Passed

Trust relationship test. . . . . . : Skipped

Kerberos test. . . . . . . . . . . : Passed

LDAP test. . . . . . . . . . . . . : Passed

Bindings test. . . . . . . . . . . : Passed

WAN configuration test . . . . . . : Skipped
No active remote access connections.

Modem diagnostics test . . . . . . : Passed


Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: Default-First-Site-Name\DC1
Starting test: Connectivity
......................... DC1 passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\DC1
Starting test: Replications
......................... DC1 passed test Replications
Starting test: NCSecDesc
......................... DC1 passed test NCSecDesc
Starting test: NetLogons
......................... DC1 passed test NetLogons
Starting test: Advertising
......................... DC1 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... DC1 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... DC1 passed test RidManager
Starting test: MachineAccount
......................... DC1 passed test MachineAccount
Starting test: Services
......................... DC1 passed test Services
Starting test: ObjectsReplicated
......................... DC1 passed test ObjectsReplicated
Starting test: frssysvol
......................... DC1 passed test frssysvol
Starting test: frsevent
......................... DC1 passed test frsevent
Starting test: kccevent
......................... DC1 passed test kccevent
Starting test: systemlog
......................... DC1 passed test systemlog
Starting test: VerifyReferences
......................... DC1 passed test VerifyReferences

Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefVa
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRef

Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefVa
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRef

Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom

Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefVal
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefD

Running partition tests on : Domain
Starting test: CrossRefValidation
......................... Domain passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Domain passed test CheckSDRefDom

Running enterprise tests on : Domain.com
Starting test: Intersite
......................... Domain.com passed test Intersite
Starting test: FsmoCheck
......................... Domain.com passed test FsmoCheck



Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: Default-First-Site-Name\DC2-FS01A
Starting test: Connectivity
......................... DC2-FS01A passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\DC2-FS01A
Starting test: Replications
......................... DC2-FS01A passed test Replications
Starting test: NCSecDesc
......................... DC2-FS01A passed test NCSecDesc
Starting test: NetLogons
......................... DC2-FS01A passed test NetLogons
Starting test: Advertising
Warning: DC2-FS01A is not advertising as a time server.
......................... Dc2-FS01A failed test Advertising
Starting test: KnowsOfRoleHolders
......................... DC2-FS01A passed test KnowsOfRoleHolders
Starting test: RidManager
..........................DC2-FS01A passed test RidManager
Starting test: MachineAccount
......................... DC2-FS01A passed test MachineAccount
Starting test: Services
......................... DC2-FS01A passed test Services
Starting test: ObjectsReplicated
......................... DC2-FS01A passed test ObjectsReplicated
Starting test: frssysvol
......................... DC2-FS01A passed test frssysvol
Starting test: frsevent
......................... DC2-FS01A passed test frsevent
Starting test: kccevent
......................... DC2-FS01A passed test kccevent
Starting test: systemlog
......................... DC2-FS01A passed test systemlog
Starting test: VerifyReferences
......................... DC2-FS01A passed test VerifyReferences

Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom

Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom

Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom

Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom

Running partition tests on : DOMAIN
Starting test: CrossRefValidation
......................... DOMAIN passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DOMAIN passed test CheckSDRefDom

Running enterprise tests on : DOMAIN.com
Starting test: Intersite
......................... DOMAIN.com passed test Intersite
Starting test: FsmoCheck
......................... DOMAIN.com passed test FsmoCheck



Computer Name: DC2-FS01A
DNS Host Name: DC2-fs01a.DOMAIN.com
System info : Windows 2000 Server (Build 3790) UPGRADED TO WINDOWS 2003
Processor : x86 Family 6 Model 8 Stepping 3, GenuineIntel

Netcard queries test . . . . . . . : Passed

Per interface results:

Adapter : Local Area Connection 4

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : DC2-fs01a.DOMAIN.com
IP Address . . . . . . . . :
Subnet Mask. . . . . . . . :
Default Gateway. . . . . . :
Primary WINS Server. . . . :
Secondary WINS Server. . . :
Dns Servers. . . . . . . . :

AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed

WINS service test. . . . . : Passed

Global results:

Domain membership test . . . . . . : Passed

NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
1 NetBt transport currently configured.


C:\>dcdiag /test:dns

Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: Default-First-Site-Name\DC2-FS01A
Starting test: Connectivity
......................... DC2-FS01A passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\DC2-FS01A

DNS Tests are running and not hung. Please wait a few minutes...

Running partition tests on : ForestDnsZones

Running partition tests on : DomainDnsZones

Running partition tests on : Schema

Running partition tests on : Configuration

Running partition tests on : domain

Running enterprise tests on : DOMAIN.com
Starting test: DNS
Test results for domain controllers:

DC: DC2-fs01a.DOMAIN.com
Domain: DOMAIN.com

TEST: Delegations (Del)
Error: DNS server: dc1.DOMAIN.com. IP: [Broken
delegated domain DOMAIN.com.DOMAIN.com.
Error: DNS server: DOMAIN-fs01a.DOMAIN.com. IP:
[Broken delegated domain DOMAIN.com.DOMAIN.com.

Summary of test results for DNS servers used by the above domain

DNS server: (dc1.DOMAIN.com.)
1 test failure on this DNS server
Delegation is broken for the domain DOMAIN.com.DOMAIN.com. on
the DNS server

DNS server: (DOMAIN-fs01a.DOMAIN.com.)
1 test failure on this DNS server
Delegation is broken for the domain DOMAIN.com.DOMAIN.com. on
the DNS server

Summary of DNS test results:

Auth Basc Forw Del Dyn RReg Ext

Domain: DOMAIN.com

I ran the Dcdiag /test:dns on DC1 following are the results.

C:\>dcdiag /test:dns

Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: Default-First-Site-Name\DC1
Starting test: Connectivity
......................... DC1 passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\DC1

DNS Tests are running and not hung. Please wait a few minutes...

Running partition tests on : ForestDnsZones

Running partition tests on : DomainDnsZones

Running partition tests on : Schema

Running partition tests on : Configuration

Running partition tests on : domain

Running enterprise tests on : domain.com
Starting test: DNS
Test results for domain controllers:

DC: dc1.domain.com
Domain: domain.com

TEST: Delegations (Del)
Error: DNS server: dc1.domain.com. IP: [Broken
delegated domain companyName(domain).com.companyName(Domain).com.]
Error: DNS server: DC2-fs01a.domain.com. IP:
[Broken delegated domain companyName(domain).com.companyName(domain).c

Summary of test results for DNS servers used by the above domain

DNS server: (dc1.domain.com.)
1 test failure on this DNS server
Delegation is broken for the domain
om. on the DNS server

DNS server: (DC2-fs01a.domain.com.)
1 test failure on this DNS server
Delegation is broken for the domain
om. on the DNS server

Summary of DNS test results:

Auth Basc Forw Del Dyn RReg Ext

Domain: domain.com

......................... Domain.com failed test DNS


What is tha mean ?

You get this message when you have a zone for mydomain.com and
_msdcs.mydomain.com, and the _msdcs delegation in mydomain.com does not have
NS records for all of the servers that have the _msdcs.mydomain.com zone.

Add the missing NS records for all server that have the full
_msdcs.mydomain.com zone.

"Meinolf Weber" wrote:

> Hello Kashif,
> Check this one:
> http://www.phwinfo.com/forum/ms-public-win-server-dns/202595-broken-deleagation.html
> Best regards
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
> > Error: DNS server:
> >



You get this message when you have a zone for mydomain.com and
_msdcs.mydomain.com, and the _msdcs delegation in mydomain.com does not have
NS records for all of the servers that have the _msdcs.mydomain.com zone.

Add the missing NS records for all server that have the full
_msdcs.mydomain.com zone.

How do I know _msdcs delegation in mydomain.com doesn't have NS records for
all the of the servers? Where is that located? How do I check it?

"Meinolf Weber" wrote:

> Hello Kashif,
> Check this one:
> http://www.phwinfo.com/forum/ms-public-win-server-dns/202595-broken-deleagation.html
> Best regards
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
> > Error: DNS server:
> >


Meinolf Weber

Hello Kashif,

Open the DNS management console and check your zones.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

> You get this message when you have a zone for mydomain.com and
> _msdcs.mydomain.com, and the _msdcs delegation in mydomain.com does
> not have NS records for all of the servers that have the
> _msdcs.mydomain.com zone.
> Add the missing NS records for all server that have the full
> _msdcs.mydomain.com zone.
> How do I know _msdcs delegation in mydomain.com doesn't have NS
> records for all the of the servers? Where is that located? How do I
> check it?
> "Meinolf Weber" wrote:
>> Hello Kashif,
>> Check this one:
>> http://www.phwinfo.com/forum/ms-public-win-server-dns/202595-broken-d
>> eleagation.html
>> Best regards
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers
>> no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> Error: DNS server:
Top Bottom