"pbrill1" <(E-Mail Removed)> wrote in message
news:48F9D8D6-8184-43B8-8A5D-(E-Mail Removed)...
> Herb,
>
> Thanks for your prompt replies - I will admit that I must continue to
build
> my depth of undertanding with WINS/DNS/AD:
I am betting your problem is mostly a WINS issues.
> Followup to your responses:
> 1) Interim mode/Mixed mode: I'm still trying to determine why we are in
> mixed mode. I watched a consultant click "interim mode" when we performed
> our NT4 - W2K3 migration.
>
> 2) I ran REPLMON on our primary DC (the one with the operations masters).
> Both NT4 BDC's indicate "ERROR: Server Unreachable". If there were a way
to
> do it, I'd just demote both to member servers - but what I've read so far
> tells me that this cannot be done - within a month, we will be pulling
them
> from their remote locations and I'll remove them from AD Users/Computers.
> (Is there a way to demote them in W2K3?)
Right (you can't remove AD from NT P/B DCs.
> 3) NEON SIGNS - Herb, I may be blind to them! Obviously, my response in
#2
> above shows one major problem, but one different from my original NT4
member
> server problem.
I was making a statement, not claiming you can read the
text on those Neon Signs (it might be in a language you
don't yet know) so let's drop this. I am only saying this
is almost certainly a sign of such problems as I indicated.
> Multiple Subnets? YES, although the NT4 member server is in the same
subnet
> as our primary DC.
Where are the PDC other BDCs? Unless ALL
of the xDCs of NT4 can find a DC of the Win2000+
domain (and vice versa) then they will not be able
to find the list of Global Groups.
NetBIOS does this for older domains and external
trusts in general.
NetBIOS broadcasts do not work across routers (i.e.,
multiple subnets) and so you need WINS Server(s).
Usually people put in the WINS server(s) and neglect
to make EVERY machine, including DCs, a client of
the WINS server(s) -- and that includes THE WINS
server itself.
Or they have more than one WINS server and neglect
to make them replicate.
> It may be a question for a different posting, but we have 7 subnets, but
are
> attempting to have DC's in only 2 of these subnets.
2 subnets means at least one internal router.
Which means WINS is a practical necessity.
> The other 5 are small (1
> or 2 client) locations that we are attempting to run "DC-less" due to cost
> and administrative overhead - we do not have onsite admin at these remote
> restaurant locations to ensure security at these sites.
>
> WINS Servers? YES
> We have DNS and WINS installed on the DC's at each "major site"; each also
> has a global catalog server. Our single domain also exists within a
single
> zone (our tests have shown that broadband/T1 replication traffic has not
been
> much of an issue so far).
>
> The WINS and DNS servers ARE replicating properly. The NT4 member server
> has active DNS host records; WINS shows active File Server, Messenger, and
> Workstation records for the NT4 member server.
Are ALL of the DCs also WINS Server clients?
If so and it is replicating to all WINS servers then
we have to look elsewhere.
> Also, the NT4 member server uses a static IP address that has ONLY the
WINS
> and DNS IP address of the W2K3 DC that is in it's subnet.
I am not sure that I fully understand the sentence above, but
it is essentiall that all DCs (W2k, PDC, BDCs) are also
WINS clients.
Then if, as you say, the WINS servers all replicate they
can find each other.
I am fairly certain that your PDC is a WINS client OR
it and the Win2000 DC are on the same subnet.
Why? They found each other for the EXTERNAL TRUST
to be established.
I am reasonably confident that your two BDCs are not WINS
clients or it's not replicating.
Why? Because you said all along (your original problem)
the Groups from the trusted domain are not showing up on
SOME NT client machines (e.g., the server in question.)
> I would be very grateful for your continued advice, Herb.
>
You can even call me if you wish. Phone number is
on my website:
www.LearnQuick.Com