You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

公有云部署Windows Server 2019 AD域控 客户端加域提示无法联系DC求助

AD域加入故障排查求助

我正在搭建用于开发场景的AD/DNS服务器,但所有客户端都无法连接到该服务器。服务端是部署在公有云环境的纯净安装版Windows Server 2019,参照相关指南完成配置,客户端为我司内部局域网的Windows 10设备。

配置过程全程顺利,但客户端始终无法接入DC,恳请各位提供排查思路。

在Windows 10客户端尝试加入域时收到报错:"无法联系域"simon.adtest"的Active Directory域控制器(AD DC)",详细信息如下:

The query was for the SRV record for _ldap._tcp.dc._msdcs.simon.adtest
The following domain controllers were identified by the query:
simondc2019.simon.adtest
However no domain controllers could be contacted.

排查阶段已临时关闭服务端和客户端的防火墙,需说明该环境为非生产环境,常规场景下不建议关闭防火墙。

客户端执行ipconfig /all的输出如下:

Windows IP Configuration

   Host Name . . . . . . . . . . . . : SIMONMCALOO9364
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Ethernet0:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel(R) 82574L Gigabit Network Connection #2
   Physical Address. . . . . . . . . : 00-0C-29-4A-58-02
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IPv4 Address. . . . . . . . . . . : 192.168.1.120(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained . . . . . . . . . : 30 September 2021 12:05:31 pm
   Lease Expires . . . . . . . . . . : 6 November 2157 9:03:20 pm
   Default Gateway . . . . . . . . . : 192.168.1.1
   DHCP Server . . . . . . . . . . . : 192.168.1.1
   DNS Servers . . . . . . . . . . . : 45.76.xx.xx (correct address of AD/DNS server confirmed)
   NetBIOS over Tcpip. . . . . . . . : Enabled

客户端可正常ping通AD域名(simon.adtest)和DC服务器域名(SimonDC2019.simon.adtest):

Reply from 45.76.xx.xx: bytes=32 time=17ms TTL=116
Reply from 45.76.xx.xx: bytes=32 time=16ms TTL=116
Reply from 45.76.xx.xx: bytes=32 time=16ms TTL=116
Reply from 45.76.xx.xx: bytes=32 time=16ms TTL=116

Ping statistics for 45.76.xx.xx:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 16ms, Maximum = 17ms, Average = 16ms

nslookup正向、反向解析均正常:

Server:  SimonDC2019.SIMON.adtest
Address:  45.76.xx.xx

Name:    simon.adtest
Address:  45.76.xx.xx


C:\Users\simon>nslookup 45.76.xx.xx
Server:  SimonDC2019.SIMON.adtest
Address:  45.76.xx.xx

Name:    SimonDC2019.SIMON.adtest
Address:  45.76.xx.xx


C:\Users\simon>nslookup SimonDC2019.SIMON.adtest
Server:  SimonDC2019.SIMON.adtest
Address:  45.76.xx.xx

Name:    SimonDC2019.SIMON.adtest
Address:  45.76.xx.xx

排查过程中分别在服务端和客户端执行dcdiag,服务端除以下项外所有测试均通过:

There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL
    replication problems may cause Group Policy problems.
    ......................... SIMONEVERYWHERE failed test DFSREvent

客户端dcdiag输出异常,内容如下:

Performing initial setup:
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SIMON
      Starting test: Connectivity
         ......................... SIMON passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SIMON
      Starting test: Advertising
         Fatal Error:DsGetDcName (SIMON) call failed, error 1722
         The Locator could not find the server.
         ......................... SIMON failed test Advertising
      Starting test: FrsEvent
         ......................... SIMON passed test FrsEvent
      Starting test: DFSREvent
         There are warning or error events within the last 24 hours after the SYSVOL has been shared.  Failing SYSVOL
         replication problems may cause Group Policy problems.
         ......................... SIMON failed test DFSREvent
      Starting test: SysVolCheck
         [SIMON] An net use or LsaPolicy operation failed with error 2,
         The system cannot find the file specified..
         The SysVol is not ready.  This can cause the DC to not advertise itself as a DC for netlogon after dcpromo.
         Also trouble with FRS SysVol replication can cause Group Policy problems.  Check the FRS event log on this DC.
         ......................... SIMON failed test SysVolCheck
      Starting test: KccEvent
         ......................... SIMON passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... SIMON passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         Could not open pipe with [SIMON]:failed with 2: The system cannot find the file specified.
         Could not get NetBIOSDomainName
         Failed can not test for HOST SPN
         Failed can not test for HOST SPN
         ......................... SIMON passed test MachineAccount
      Starting test: NCSecDesc
         ......................... SIMON passed test NCSecDesc
      Starting test: NetLogons
         [SIMON] An net use or LsaPolicy operation failed with error 2,
         The system cannot find the file specified..
         ......................... SIMON failed test NetLogons
      Starting test: ObjectsReplicated
         ......................... SIMON passed test ObjectsReplicated
      Starting test: Replications
         ......................... SIMON passed test Replications
      Starting test: RidManager
         ......................... SIMON passed test RidManager
      Starting test: Services
         ......................... SIMON passed test Services
      Starting test: SystemLog
         ......................... SIMON passed test SystemLog
      Starting test: VerifyReferences
         ......................... SIMON passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : SIMON
      Starting test: CheckSDRefDom
         ......................... SIMON passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... SIMON passed test CrossRefValidation

   Running enterprise tests on : SIMON.adtest
      Starting test: LocatorCheck
         Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1722
         A Global Catalog Server could not be located - All GC's are down.
         Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1722
         A Primary Domain Controller could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1722
         A Time Server could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 1722
         A Good Time Server could not be located.
         Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1722
         A KDC could not be located - All the KDCs are down.
         ......................... SIMON.adtest failed test LocatorCheck
      Starting test: Intersite
         ......................... SIMON.adtest passed test Intersite

错误1722是通用RPC故障报错,我搜索了相关方案均不匹配当前场景,目前排查已陷入停滞。


故障排查解决方案

结合提供的所有日志信息,可按以下优先级逐一排查修复:

  • 首先排查公有云安全组规则,仅关闭系统层面防火墙不生效,公有云实例的入站安全组默认会拦截绝大多数端口,需在安全组中放通客户端公网出口IP对以下端口的访问权限:
    • TCP 53、UDP 53(DNS)
    • TCP 88、UDP 88(Kerberos认证)
    • TCP 135(RPC端点映射)
    • TCP 139、UDP 137、UDP 138(NetBIOS)
    • TCP 389、UDP 389(LDAP)
    • TCP 445(SMB共享)
    • TCP 464、UDP 464(Kerberos密码修改)
    • TCP 49152~65535(RPC动态端口段,极易遗漏)
  • 修复DC端SYSVOL共享异常:dcdiag日志明确提示SysVol未就绪、Netlogon共享不存在,这是DC无法正常提供域服务的核心原因,修复步骤:
    1. 登录DC服务器,运行net share查看共享列表,确认是否存在SYSVOL和NETLOGON两个共享
    2. 若不存在,打开注册表编辑器定位到HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters
    3. 找到SysVolReady项,将默认值0修改为1,保存后重启Netlogon服务
    4. 再次运行net share确认两个共享已正常显示,重新执行dcdiag验证SysVolCheck、NetLogons、Advertising测试项是否通过
  • 检查AD站点配置:打开AD站点和服务控制台,检查Default-First-Site-Name站点关联的子网列表,需将公司的公网出口IP段添加到子网列表并关联到对应站点,否则DC会拒绝来自未知站点的客户端请求
  • 客户端验证端口连通性:不要仅依赖ping测试,在客户端PowerShell中执行以下命令验证关键端口连通性,任意端口不通都会触发1722 RPC报错:
    Test-NetConnection 45.76.xx.xx -Port 389
    Test-NetConnection 45.76.xx.xx -Port 445
    Test-NetConnection 45.76.xx.xx -Port 135
    
  • 客户端临时配置优化:域加入前手动设置网卡的连接特定DNS后缀为simon.adtest,勾选“在DNS中注册此连接的地址”,保存后重启网卡再尝试加入域。

内容的提问来源于stack exchange,提问作者sfkHooper

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.02 13:48:03