Problems joining a domain on another subnet

JvAsche 1 Reputation point
2021-02-20T16:26:16.247+00:00

Hello everybody,

I am experiencing the following problem:

I have a DC and another Server on different subnets. They can ping each other and the other Server gets prtquery ldap response from the DC. However when I try to join the domain, I get the following error:
DNS was successfully queried for the service location (SRV) resource record used to locate a domain controller for domain "xxxxx.eu":

The query was for the SRV record for _ldap._tcp.dc._msdcs.xxxxx.eu

The following domain controllers were identified by the query:
yyyyyy.xxxxx.eu

However no domain controllers could be contacted.

Common causes of this error include:

  • Host (A) or (AAAA) records that map the names of the domain controllers to their IP addresses are missing or contain incorrect addresses.
  • Domain controllers registered in DNS are not connected to the network or are not running.

In the diag file I get this:

02/20/2021 16:54:20:490 NetpValidateName: checking to see if 'xxxxx.eu' is valid as type 3 name
02/20/2021 16:54:35:506 NetpCheckDomainNameIsValid for xxxxx.eu returned 0x54b, last error is 0x0
02/20/2021 16:54:35:506 NetpCheckDomainNameIsValid [ Exists ] for 'xxxxx.eu' returned 0x54b

I tried the solution with single label dns as well as the NeutralizeNT4Emulator proposal but to no avail.

DNS servers are correctly set and point to the DC. Any ideas?

Many thanks in advance!

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

12 answers

Sort by: Most helpful
  1. Anonymous
    2021-02-20T17:04:22.913+00:00

    Might check the ports are flowing between networks.
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts
    https://www.microsoft.com/en-us/download/details.aspx?id=24009

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  2. JvAsche 1 Reputation point
    2021-02-20T19:01:09.067+00:00

    Hello @Anonymous ,

    thanks for the answer. Unfortunately this is not the case. I even switched both firewalls off. I checked also every port with PortQryUI, the only not listening port being 1723. I am completely baffled since querying the ldap ports from the client I get every info on the Domain...but cannot join.

    Many thanks!

    0 comments No comments

  3. Anonymous
    2021-02-20T19:03:23.447+00:00

    Please run;

    Dcdiag /v /c /d /e /s:%computername% >c:\dcdiag.log
    repadmin /showrepl >C:\repl.txt
    ipconfig /all > C:\dc1.txt
    ipconfig /all > C:\dc2.txt
    ipconfig /all > C:\problemworkstation.txt
    C:\Windows\debug\netsetup.log

    then put unzipped text files up on OneDrive and share a link.

    0 comments No comments

  4. JvAsche 1 Reputation point
    2021-02-20T19:16:17.407+00:00
    0 comments No comments

  5. Anonymous
    2021-02-20T19:27:21.01+00:00

    Multi-homing a domain controller always causes no end to grief for active directory domain DNS so I'd disable the second adapter. The multi-homed desktop could also complicate things. Also check that a route exists between 167.86.110.1 and 161.97.160.1 networks and no firewalls blocking required ports.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.