Troubleshooting Windows Servers
Useful Links
Get the
Google AdSense
widget and many other
great free widgets
at
Widgetbox
!
Search
Inside
G
o
o
g
l
e
Display results as :
Posts
Topics
Advanced Search
Latest topics
»
Order of Group Policy Processing
Tue Dec 30, 2008 4:05 pm by
nbhatt
»
Authentication Methods in IIS
Tue Dec 30, 2008 1:06 pm by
Admin
»
Event id 4004 DNS errors and external name resolution problems
Mon Dec 29, 2008 4:19 pm by
Admin
»
Stop 0x7F or UNEXPECTED_KERNEL_MODE_TRAP
Mon Dec 29, 2008 1:43 pm by
Admin
»
Stop 0x7B or INACCESSIBLE_BOOT_DEVICE
Sat Dec 27, 2008 10:37 pm by
Anonymous
»
Stop 0x7A or KERNEL_DATA_INPAGE_ERROR
Fri Dec 26, 2008 9:42 pm by
Admin
»
Stop 0x79 or MISMATCHED_HAL
Fri Dec 26, 2008 9:36 pm by
Admin
»
Stop 0x77 or KERNEL_STACK_INPAGE_ERROR
Thu Dec 25, 2008 4:19 pm by
Admin
»
Stop 0x6B or PROCESS1_INITIALIZATION_FAILED
Thu Dec 25, 2008 4:09 pm by
Admin
Shopmotion
Navigation
Portal
Index
Memberlist
Profile
FAQ
Search
Forum
Create a free forum
Free forum support
Affiliates
Premade Website Designs
Server Unleashed
::
Networking
::
Event ID 4004 DNS errors and external name resolution problems
::
Event id 4004 DNS errors and external name resolution problems
Post a reply
Username
Subject
Dark Red
Red
Orange
Brown
Yellow
Green
Olive
Cyan
Blue
Dark Blue
Indigo
Grey
White
Black
None (use implicit)
Message body
x
YouTube
Dailymotion
x
px
Tiny
Small
Normal
Large
Huge
Dark Red
Red
Orange
Brown
Yellow
Green
Olive
Cyan
Blue
Dark Blue
Indigo
Violet
White
Black
Arial
Arial Black
Comic Sans Ms
Courier New
Georgia
Impact
Times New Roman
Trebuchet MS
Verdana
Index
Exponent
Spoiler
Hidden
Horizontal scrolling
Vertical scrolling
Random
WoW
x
Ok
Ok
Ok
x
px
Ok
YouTube
Dailymotion
Ok
Tiny
Small
Normal
Large
Huge
Dark Red
Red
Orange
Brown
Yellow
Green
Olive
Cyan
Blue
Dark Blue
Indigo
Violet
White
Black
Arial
Arial Black
Comic Sans Ms
Courier New
Georgia
Impact
Times New Roman
Trebuchet MS
Verdana
Index
Exponent
Spoiler
Hidden
Horizontal scrolling
Vertical scrolling
Random
WoW
Close Tags
Options
Options
HTML is OFF
BBCode
is ON
Smilies are ON
Disable BBCode in this post
Disable Smilies in this post
Jump to:
Select a forum
|
|--Active Directory
| |--Migration
| |--Replication Issues
| |--Group Policy processing order
| |--Troubleshooting Unshared sysvol and netlogon.
| |--Metadata Cleanup after unsuccessful demotion of server
|
|--Exchange Issues and Articles
| |--Unable to run Forestprep for Exchange 2003 due to MSDTC errors
| |--Exchange Services not starting: Unexpected error There are no more endpoints available from the endpoint mapper
|
|--NTBackup Issues
| |--Error returned while creating the volume shadow copy: 0xfffffff
|
|--Service Pack Issues
| |--Unable to install SP2 for Windows server 2003
| |--Remote Desktop Fails after intalling SP2 for Server 2003
| |--How to uninstall Service Packs for Windows from recovery console
|
|--STOP Errors
| |--Stop Errors Overview
| |--Configuring Memory Dumps
| |--Using Memory Dump Files to analyze STOP Errors
| |--Being Prepared for Stop Errors
| |--Common Stop Messages
| |--Stop 0xA or IRQL_NOT_LESS_OR_EQUAL
| |--Stop 0x1E or KMODE_EXCEPTION_NOT_HANDLED
| |--Stop 0x24 or NTFS_FILE_SYSTEM
| |--Stop 0x2E or DATA_BUS_ERROR
| |--Stop 0x31 or PHASE0_INITIALIZATION_FAILED
| |--Stop 0x32 or PHASE1_INITIALIZATION_FAILED
| |--Stop 0x3F or NO_MORE_SYSTEM_PTES
| |--Stop 0x50 or PAGE_FAULT_IN_NONPAGED_AREA
| |--Stop 0x6B or PROCESS1_INITIALIZATION_FAILED
| |--Stop 0x77 or KERNEL_STACK_INPAGE_ERROR
| |--Stop 0x79 or MISMATCHED_HAL
| |--Stop 0x7A or KERNEL_DATA_INPAGE_ERROR
| |--Stop 0x7B or INACCESSIBLE_BOOT_DEVICE
| |--Stop 0x7F or UNEXPECTED_KERNEL_MODE_TRAP
|
|--Networking
| |--No Internet after connecting through VPN
| |--Event ID 4004 DNS errors and external name resolution problems
|
|--IIS
|--AuthenticationMethods in IIS
Topic review
Author
Message
Admin
Mon Dec 29, 2008 4:19 pm
Topic: Event id 4004 DNS errors and external name resolution problems
Internal names resolve but external DNS names won’t resolve. The following error will also appear in the event log.
Event Type: Error
Source: DNS
Event ID: 4004
Description: The DNS server was unable to complete directory service enumeration of zone <domain.com>. This DNS server is configured to use information obtained from Active Directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and repeat enumeration of the zone.
More information:
The DNS Server service uses Active Directory to store DNS data, and it encountered a Lightweight Directory Access Protocol (LDAP) error while querying the directory. This error could be caused by either a high load on the domain controller or the failure of other domain controller services.
*** Resolution ***
1. DNS is listening on both the LAN and RRAS adapters. Configure DNS to listen only on the LAN adapter and then delete all records in forward lookup zone that reference the RRAS adapter address.
2. The DNS server may have a forward lookup zone called _msdcs.<forest_root_domain>
AND a subfolder under the <forest_root_domain> forward lookup zone call _msdcs. Remove the
_msdcs.<forest_root_domain>subfolder and then restart the DNS Server and Netlogon service. Also run ipconfig /flushdns and ipconfig /registerdns.
If you find a missing _msdcs delegation under <forest_root_domain> zone , create a new delegation by performing the following:
Right click on <forest_root_domain> zone, select new, then delegation, click next on the wizard, under delegated domain, type in _msdcs and click next, clck add and browse to the server's A record under forward lookup zones, domain.local, click ok and finish.
For Windows 2000 DNS, the separate zone for the _msdcs folder and delegation to it from the main forward lookup zone doesn’t exist. The _msdcs folder for Windows 2000 DNS servers will exist under the main forward lookup zone along with the _sites, _tcp and _udp SRV records. If there is a combination of the Windows 2000 and Windows 2003 DNS configuration, related to the _msdcs folder, then you must decide which is appropriate.
3. When a domain controller is demoted, the registry may still contain the Active Directory integrated zone names. This results in the server trying to load the zones. Since there is no Directory Service running, it causes the server to log the event id 4004 error.
To prevent the errors remove the old zones from the following registry location.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DNS Server\Zones
4. Make sure the Administrators and Enterprise Domain Controllers groups are added to the
“Enable Computer and User Accounts to be Trusted for Delegation" & “Access this computer from the network” right. The following steps will allow you to add these groups to the appropriate user rights assignement.
a) Open Domain Controller Security Policy.
b) In the console tree, click User Rights Assignment under:
Computer Configuration/Windows Settings/Security Settings/Local Policies/User Rights Assignment
c) In the details pane, double-click the user right that you want to assign.
d) Click Add User or Group. If the button appears dimmed, select the Define these
policy settings check box.
e) Type the name of the group to which you want to assign this right.
5. Change the zone type for each of the AD integrated zones to a standard primary zone in the DNS manager console