Mutli 3 site setup connected and transferring data. DCPROMO Failing



  • clients connected to home site . i can ping, browse the servers in the home subnet  from the client network and vice versa. i am not try to add a new domain in an existing forest however dcpromo crashes so i checked the logs i have an event id 1000 and dfrs service failed to contact the domain controller to access configuration. my client servers are in the opt1 network and clients on the LAN. on the OPT1 i have a allow any to any rule. dcpromo fails right has its doing a verify netbois.. please advise? im using pfsense 2.0


  • Banned

    NetBIOS is disabled by default with OpenVPN.



  • Even if you enable netbios over TCPIP you will need to configure a WINS server.  Its not worth the fuss.  Just use IPs.
    I'm not sure at all how well dcpromo will work with this.  Never tried it.



  • @kejianshi:

    Even if you enable netbios over TCPIP you will need to configure a WINS server.  Its not worth the fuss.  Just use IPs.
    I'm not sure at all how well dcpromo will work with this.  Never tried it.

    should i join the new domain locally at the home network then carry the server to the remote location?



  • @doktornotor:

    NetBIOS is disabled by default with OpenVPN.

    can it be enabled?



  • anyone ever done anything similar to what i'm doing?



  • The new server must have its DNS server be something that knows the name of the forest/domain that you want to join. So, for example, if:

    • existing forest root server (with DNS) for net.mycompany.com is 10.20.0.1/24
    • new server is in another subnet 10.20.42.1/24, and you want it to become the first domain server for branch.net.mycompany.com
      First, manually set its DNS server to 10.20.0.1
      Then dcpromo can resolve the forest domain name you type in, and it all happens.
      Afterwards, the new server is a real DC in the new child domain. It should have a DNS referral for the parent (forest root) domain pointing to 10.20.0.1. The new server NIC properties can be changed to point to itself as its own DNS server.


  • dns was not the issue.. had to create a trust between the domains, works so i'm up and running.. thanks for the answers and advise.