Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , ,

Sponsored Links



problem browsing active directory resources on remote domains

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 17-04-2009
Carlettus
 
Posts: n/a
problem browsing active directory resources on remote domains

Dear All,
I have the following problem and I hope you can give me some tips to solve
it.
I administer a child domain of an Active Directory forest.
In this forest there is a root domain connected to other 10 child domains at
the same level. All the child domains are connected to the root domain with
a VPN tunnel.

The problem is that when I try to browse the AD resources from ADUC of a
specific child domain I can't and I receive the following error, please note
that I can Ping the domain controller of this child domain. This problem is
only with a specific domain, and it's working with all other 8 domains.

Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40960
Date: 4/17/2009
Time: 4:59:05 PM
User: N/A
Computer: DOMAINCONTROLLERCENTER1
Description:
The Security System detected an authentication error for the server
ldap/domaincontrollerCENTER2.xx.yyy.ORG/yy.yyy.ORG@xx.yyy.ORG. The failure
code from authentication protocol Kerberos was "There are currently no logon
servers available to service the logon request.
(0xc000005e)".

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 5e 00 00 c0 ^..À


Thank you for your help.
Carlo

Reply With Quote
  #2  
Old 17-04-2009
Isaac Oben [MCITP,MCSE]
 
Posts: n/a
Re: problem browsing active directory resources on remote domains

Hello Carlettus,

It seems like there is DNS related issue here. How is your dns configured?
Does the child domain have its own dns servers?

--
Isaac Oben [MCTIP:EA, MCSE]
"Carlettus" <bionews@community.nospam> wrote in message
news:%230L9J72vJHA.3676@TK2MSFTNGP06.phx.gbl...
> Dear All,
> I have the following problem and I hope you can give me some tips to solve
> it.
> I administer a child domain of an Active Directory forest.
> In this forest there is a root domain connected to other 10 child domains
> at the same level. All the child domains are connected to the root domain
> with a VPN tunnel.
>
> The problem is that when I try to browse the AD resources from ADUC of a
> specific child domain I can't and I receive the following error, please
> note that I can Ping the domain controller of this child domain. This
> problem is only with a specific domain, and it's working with all other 8
> domains.
>
> Event Type: Warning
> Event Source: LSASRV
> Event Category: SPNEGO (Negotiator)
> Event ID: 40960
> Date: 4/17/2009
> Time: 4:59:05 PM
> User: N/A
> Computer: DOMAINCONTROLLERCENTER1
> Description:
> The Security System detected an authentication error for the server
> ldap/domaincontrollerCENTER2.xx.yyy.ORG/yy.yyy.ORG@xx.yyy.ORG. The
> failure code from authentication protocol Kerberos was "There are
> currently no logon servers available to service the logon request.
> (0xc000005e)".
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
> Data:
> 0000: 5e 00 00 c0 ^..À
>
>
> Thank you for your help.
> Carlo
>


Reply With Quote
  #3  
Old 18-04-2009
Garry Starck - MCITP
 
Posts: n/a
RE: problem browsing active directory resources on remote domains

Hello Carlettus

Cab be DNS, but you can ping DCNAME.FQDN?? Can you telnet to port 135, 445
on the PDC emulator on the problem domain, maybe the VPN id blocking the
ports required for comms.

Cheers


--
Garry Starck
MCITP, MCTS AD, MCSE 2003 Messaging, MCDBA


"Carlettus" wrote:

> Dear All,
> I have the following problem and I hope you can give me some tips to solve
> it.
> I administer a child domain of an Active Directory forest.
> In this forest there is a root domain connected to other 10 child domains at
> the same level. All the child domains are connected to the root domain with
> a VPN tunnel.
>
> The problem is that when I try to browse the AD resources from ADUC of a
> specific child domain I can't and I receive the following error, please note
> that I can Ping the domain controller of this child domain. This problem is
> only with a specific domain, and it's working with all other 8 domains.
>
> Event Type: Warning
> Event Source: LSASRV
> Event Category: SPNEGO (Negotiator)
> Event ID: 40960
> Date: 4/17/2009
> Time: 4:59:05 PM
> User: N/A
> Computer: DOMAINCONTROLLERCENTER1
> Description:
> The Security System detected an authentication error for the server
> ldap/domaincontrollerCENTER2.xx.yyy.ORG/yy.yyy.ORG@xx.yyy.ORG. The failure
> code from authentication protocol Kerberos was "There are currently no logon
> servers available to service the logon request.
> (0xc000005e)".
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
> Data:
> 0000: 5e 00 00 c0 ^..À
>
>
> Thank you for your help.
> Carlo
>
>

Reply With Quote
  #4  
Old 18-04-2009
Meinolf Weber [MVP-DS]
 
Posts: n/a
Re: problem browsing active directory resources on remote domains

Hello Carlettus,

Make sure that the time is not ouf of sync with the PDCEmulator over 5 minutes.
Also check this one:
http://support.microsoft.com/kb/325850

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Dear All,
> I have the following problem and I hope you can give me some tips to
> solve
> it.
> I administer a child domain of an Active Directory forest.
> In this forest there is a root domain connected to other 10 child
> domains at
> the same level. All the child domains are connected to the root domain
> with
> a VPN tunnel.
> The problem is that when I try to browse the AD resources from ADUC of
> a specific child domain I can't and I receive the following error,
> please note that I can Ping the domain controller of this child
> domain. This problem is only with a specific domain, and it's working
> with all other 8 domains.
>
> Event Type: Warning
> Event Source: LSASRV
> Event Category: SPNEGO (Negotiator)
> Event ID: 40960
> Date: 4/17/2009
> Time: 4:59:05 PM
> User: N/A
> Computer: DOMAINCONTROLLERCENTER1
> Description:
> The Security System detected an authentication error for the server
> ldap/domaincontrollerCENTER2.xx.yyy.ORG/yy.yyy.ORG@xx.yyy.ORG. The
> failure
> code from authentication protocol Kerberos was "There are currently no
> logon
> servers available to service the logon request.
> (0xc000005e)".
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
> Data:
> 0000: 5e 00 00 c0 ^..À
> Thank you for your help.
> Carlo



Reply With Quote
  #5  
Old 20-04-2009
Carlettus
 
Posts: n/a
Re: problem browsing active directory resources on remote domains

Dear All,
thank you for your emails.
I can ping both DCNAME.FQDN at the remote site and got the telnet working.
I'll ask the administrator of the remote domain to check if there are any
sync issue at his side.
Thank you for your kind help

Carlo



"Garry Starck - MCITP" <vjsparx@REMOVE_CAPS_INVALIDhotmail.com> wrote in
message news:4782AA8F-7629-428B-BF59-DF9021802115@microsoft.com...
> Hello Carlettus
>
> Cab be DNS, but you can ping DCNAME.FQDN?? Can you telnet to port 135, 445
> on the PDC emulator on the problem domain, maybe the VPN id blocking the
> ports required for comms.
>
> Cheers
>
>
> --
> Garry Starck
> MCITP, MCTS AD, MCSE 2003 Messaging, MCDBA
>
>
> "Carlettus" wrote:
>
>> Dear All,
>> I have the following problem and I hope you can give me some tips to
>> solve
>> it.
>> I administer a child domain of an Active Directory forest.
>> In this forest there is a root domain connected to other 10 child domains
>> at
>> the same level. All the child domains are connected to the root domain
>> with
>> a VPN tunnel.
>>
>> The problem is that when I try to browse the AD resources from ADUC of a
>> specific child domain I can't and I receive the following error, please
>> note
>> that I can Ping the domain controller of this child domain. This problem
>> is
>> only with a specific domain, and it's working with all other 8 domains.
>>
>> Event Type: Warning
>> Event Source: LSASRV
>> Event Category: SPNEGO (Negotiator)
>> Event ID: 40960
>> Date: 4/17/2009
>> Time: 4:59:05 PM
>> User: N/A
>> Computer: DOMAINCONTROLLERCENTER1
>> Description:
>> The Security System detected an authentication error for the server
>> ldap/domaincontrollerCENTER2.xx.yyy.ORG/yy.yyy.ORG@xx.yyy.ORG. The
>> failure
>> code from authentication protocol Kerberos was "There are currently no
>> logon
>> servers available to service the logon request.
>> (0xc000005e)".
>>
>> For more information, see Help and Support Center at
>> http://go.microsoft.com/fwlink/events.asp.
>> Data:
>> 0000: 5e 00 00 c0 ^..À
>>
>>
>> Thank you for your help.
>> Carlo
>>
>>


Reply With Quote
  #6  
Old 21-04-2009
Joson Zhou
 
Posts: n/a
Re: problem browsing active directory resources on remote domains

Hi Carlo,

Thank you for posting in Newsgroup.

According to your description, I understand that you are an administrator
of a child domain of an Active Directory forest and you find that you
cannot connect to another child domain from your child domain.

Based on the failure code "There are currently no logon servers available
to service the logon request.", the possible cause could be:

" The SRV records are not correct.

I understand that you can ping the DCNAME.FQDN, but it just indicates that
the A record of the domain controller is correct.

" The required port are blocked by firewall.

Service overview and network port requirements for the Windows Server system
http://support.microsoft.com/default.aspx/kb/832017

Please run the following command on the computer where you run the ADUC
console, and let me know the result:

Nltest /dsgetdc:childdomain /force

Note: Please replace the "childdomain" with the exact name of the child
domain that you fail to connect.

Sincerely,
Joson Zhou
Microsoft Online Support
Microsoft Global Technical Support Center

Get Secure! - www.microsoft.com/security
=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.


Reply With Quote
  #7  
Old 24-04-2009
Joson Zhou
 
Posts: n/a
Re: problem browsing active directory resources on remote domains

Hi Carlo,

How are you?

I wan to check the current status of issue. Has it been resolved? Please
feel free to respond to the newsgroups if I can assist further.

Sincerely,
Joson Zhou
Microsoft Online Support
Microsoft Global Technical Support Center


Reply With Quote
  #8  
Old 27-04-2009
Carlettus
 
Posts: n/a
Dear Joson and All of you ,
thank you again for your help.
The problem was that the administrator of the other domain had blocked the
following ports on the VPN tunnel:
Port # 88
Port # 3269.
port # 636

Now, after a short discussion and action, I can browse the ad resources on
the other domain.
Thank you again I really appreciate your help.
Reply With Quote
  #9  
Old 29-04-2009
Joson Zhou
 
Posts: n/a
Re: problem browsing active directory resources on remote domains

Glad to hear that. Have a nice day.

Joson

Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "problem browsing active directory resources on remote domains"
Thread Thread Starter Forum Replies Last Post
How to use Active Directory Domains and Trusts Sergio 1 Active Directory 3 01-12-2010 06:22 AM
Active Directory Remote Authentication Sukhwinder Singh Active Directory 2 21-09-2009 05:26 PM
Prevent Domain Users From Browsing Around in Active Directory? Mygposts Active Directory 8 17-04-2009 05:22 PM
Active Directory could not replicate the directory partition - "The remote procedure call was canceled" Hans Active Directory 2 29-02-2008 02:08 PM
WSUS 3.0 Admin Console on Remote Computer without Active Directory Problem Bruce Currier Server Update Service 10 12-08-2007 02:36 AM


All times are GMT +5.5. The time now is 05:31 PM.