Hi 各位大大 先謝謝大家的回答,
我有兩台 DC 在不同機器上的 VM
DC1 = FSMO, Win2008R2,VirtualBox
DC2 = Win2019, VirtualBox
8/1/2022 的時候, DC1 的硬碟壞掉, 重裝 OS, 把 7/2 的 VM ova 備份裝回去.
同時 8/1 發現 DC2 出現錯誤訊息, 重開後說 VM .vdi file missing. 所以再把 7/2 的 DC2 VM ova 裝回去.
問題:昨天發現安裝之前已經加入 domain 的 PC, 無法加入新的使用者.
退出 domain, 要再加入 domain 也不讓加入. (有跳出輸入使用者跟密碼視窗, 打入後跳出錯誤訊息)
在 DC1 跑了 dcdiag /q
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\Administrator>dcdiag /q
Warning: DsGetDcName returned information for \W2K19IP03.redwood.com,
when we were trying to reach WIN2K8R2-HM066.
SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE.
......................... WIN2K8R2-HM066 failed test Advertising
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... WIN2K8R2-HM066 failed test DFSREvent
NETLOGON Service is paused on [WIN2K8R2-HM066]
......................... WIN2K8R2-HM066 failed test Services
C:\Users\Administrator>
在 DC2 跑了 dcdiag /q
Microsoft Windows [Version 10.0.17763.2628]
(c) 2018 Microsoft Corporation. All rights reserved.
C:\Users\administrator.REDWOOD>dcdiag /q
The host bfeb3fc7-745c-4e52-91cc-25ad7263baff._msdcs.redwood.com could not be resolved to an IP address. Check
the DNS server, DHCP, server name, etc.
Got error while checking LDAP and RPC connectivity. Please check your firewall settings.
......................... W2K19IP03 failed test Connectivity
Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355
A Primary Domain Controller could not be located.
The server holding the PDC role is down.
......................... redwood.com failed test LocatorCheck
C:\Users\administrator.REDWOOD>
另外在 DC1 的 Event Viewer 的 System 有個錯誤
The dynamic registration of the DNS record '6f48b381-651e-42c2-8d1d-cfa55e8f6e81._msdcs.redwood.com. 600 IN CNAME Win2K8R2-HM066.redwood.com.' failed on the following DNS server:
DNS server IP address: 87.239.8.2
Returned Response Code (RCODE): 5
Returned Status Code: 9017
For computers and users to locate this domain controller, this record must be registered in DNS.
USER ACTION
Determine what might have caused this failure, resolve the problem, and initiate registration of the DNS records by the domain controller. To determine what might have caused this failure, run DCDiag.exe. To learn more about DCDiag.exe, see Help and Support Center. To initiate registration of the DNS records by this domain controller, run 'nltest.exe /dsregdns' from the command prompt on the domain controller or restart Net Logon service.
Or, you can manually add this record to DNS, but it is not recommended.
ADDITIONAL DATA
Error Value: DNS bad key.
謝謝大家.
Jerry
看錯誤訊息時我的解讀,請檢查防火牆,因為有時虛擬機的恢復不是百分百,很可能會造成網域或IP的跳動,很可能是Mac位址造成或者與host主機網卡的通透模式相關,是否跳到了不允許AD登入的網段內了?
看錯誤訊息也是有可能不是在相同域內,與AD無法正確或完全連線時當然是任何操作都不給過了。
我們公司只有一個網域. 每台 PC 都是設定固定 IP.
很可能是Mac位址造成或者與host主機網卡的通透模式相關,是否跳到了不允許AD登入的網段內了 => 這個我就不了解了.
請注意虛擬機的固定IP是否相同,如相同請確認Mac是否也相同,VM .vdi file missing可能造成網卡Mac跳走。
用AD主機與該VM機互通(互ping)後,雙方以Mac確認是否為相同一台機器,可以用arp -a列出。
Power Shell>>
arp -a
介面: 192.168.**.*** --- 0x6
網際網路網址 實體位址 類型
192.168.**.1 00-99-48-77-77-77 動態
192.168.**.** 00-55-01-33-88-88 動態
192.168.**.** ac-88-55-84-88-ec 動態
192.168.***.** 94-88-22-90-fc-c4 動態
如果互通沒問題,表示在相同域內,此問題即可排除,思考另一個可能。
例如 是否虛擬機的IP組態有問題?