Win2k server , Win2k worstation - can add to domain but not logon to domain

uberdude

n00b
Joined
Jun 18, 2004
Messages
61
Just curious if anyone has run into this. A win2k server with multiple win2k workstations. All is working fine, but one workstation. This workstaion can be added and removed from the domain all day long without an issue. However, when you try to logon to the domain it error out with DOMIAN is not available.
 
when you're logged on locally, is everything in ipconfig correct? when you run an nslookup on the domain, does it return your dns servers? DNS is the root of many evils in a w2k environment, but it's odd that only the one machine would be affected.
 
check to make sure the dns server address is set to the DC on that workstation.
 
I realize I may have been a little vague in my first post. Here is the situation again and this may help you understand the problem I am having.

We have a Windows 2000 server acting as the DC. There are also 4 Windows 2000 workstations on the network. One of the nodes was having problems and was removed from the domain and also removed from the directory on the server. We logged the node in locally using the administrator account and were able to add it back to the domain fine. The computer now shows up in the directory.

The IP configuration is correct as I have cross compared the settings with that of the other nodes on the network and everything matches (i.e. DNS Servers, Default Gateway, WINS address).

I am able to log the node in as administrator under the domain name but I feel that this is not really the case as there is a cached account on the node for this login. When I try to log the node in with any other account that exists in the directory on the server, I get an error stating that I am not able to logon right now as the domain %DOMAINNAME% is not available.

The strange thing is I am able to add and remove this machine from the domain just fine and when adding it back to the domain, I am able to authenticate with the server. I am also able to map drives shared on the server as well as browse shared drives from other machines on the domain.

There is one thing I noticed that was strange:

When you pull up active directory users and computers and right click on each computer and go to properties, you can see alot of information about the machines. However, on the node that was added to the domain, some of this information is missing. All othernodes have a DNS host entry and information about the OS version etc. On the node that was added, all these fields are blank.

I checked the event viewer on the node itself and there are no error messages in relation to DNS errors. Any further help would be appericiated. Thanks
 
i would check the services on the local machine....maybe netlogon service?
 
uberdude said:
When you pull up active directory users and computers and right click on each computer and go to properties, you can see alot of information about the machines. However, on the node that was added to the domain, some of this information is missing. All othernodes have a DNS host entry and information about the OS version etc. On the node that was added, all these fields are blank.

Have you checked the security log to obtain any additional information on why the authentication is failing?

Check to make sure the workstation time is within 5 minutes of the server time.

One other thing to try is in AD users and comps. right click the problem *computer* and click on reset account.
 
well...now we are getting that error about the computer password not synced with the what the server says it should be....

however, everything i find via the web says to use NETDOM.exe, but that utitlity appears to be useless or i am typing the commands wrong....

keep getting access is denied....
 
Back
Top