公有云部署Windows Server 2019 AD域控 客户端加域提示无法联系DC求助
AD域加入故障排查求助
我正在搭建用于开发场景的AD/DNS服务器,但所有客户端都无法连接到该服务器。服务端是部署在公有云环境的纯净安装版Windows Server 2019,参照相关指南完成配置,客户端为我司内部局域网的Windows 10设备。
配置过程全程顺利,但客户端始终无法接入DC,恳请各位提供排查思路。
在Windows 10客户端尝试加入域时收到报错:"无法联系域"simon.adtest"的Active Directory域控制器(AD DC)",详细信息如下:
The query was for the SRV record for _ldap._tcp.dc._msdcs.simon.adtest The following domain controllers were identified by the query: simondc2019.simon.adtest However no domain controllers could be contacted.
排查阶段已临时关闭服务端和客户端的防火墙,需说明该环境为非生产环境,常规场景下不建议关闭防火墙。
客户端执行ipconfig /all的输出如下:
Windows IP Configuration Host Name . . . . . . . . . . . . : SIMONMCALOO9364 Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No Ethernet adapter Ethernet0: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Intel(R) 82574L Gigabit Network Connection #2 Physical Address. . . . . . . . . : 00-0C-29-4A-58-02 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes IPv4 Address. . . . . . . . . . . : 192.168.1.120(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained . . . . . . . . . : 30 September 2021 12:05:31 pm Lease Expires . . . . . . . . . . : 6 November 2157 9:03:20 pm Default Gateway . . . . . . . . . : 192.168.1.1 DHCP Server . . . . . . . . . . . : 192.168.1.1 DNS Servers . . . . . . . . . . . : 45.76.xx.xx (correct address of AD/DNS server confirmed) NetBIOS over Tcpip. . . . . . . . : Enabled
客户端可正常ping通AD域名(simon.adtest)和DC服务器域名(SimonDC2019.simon.adtest):
Reply from 45.76.xx.xx: bytes=32 time=17ms TTL=116 Reply from 45.76.xx.xx: bytes=32 time=16ms TTL=116 Reply from 45.76.xx.xx: bytes=32 time=16ms TTL=116 Reply from 45.76.xx.xx: bytes=32 time=16ms TTL=116 Ping statistics for 45.76.xx.xx: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 16ms, Maximum = 17ms, Average = 16ms
nslookup正向、反向解析均正常:
Server: SimonDC2019.SIMON.adtest Address: 45.76.xx.xx Name: simon.adtest Address: 45.76.xx.xx C:\Users\simon>nslookup 45.76.xx.xx Server: SimonDC2019.SIMON.adtest Address: 45.76.xx.xx Name: SimonDC2019.SIMON.adtest Address: 45.76.xx.xx C:\Users\simon>nslookup SimonDC2019.SIMON.adtest Server: SimonDC2019.SIMON.adtest Address: 45.76.xx.xx Name: SimonDC2019.SIMON.adtest Address: 45.76.xx.xx
排查过程中分别在服务端和客户端执行dcdiag,服务端除以下项外所有测试均通过:
There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems. ......................... SIMONEVERYWHERE failed test DFSREvent
客户端dcdiag输出异常,内容如下:
Performing initial setup: * Identified AD Forest. Done gathering initial info. Doing initial required tests Testing server: Default-First-Site-Name\SIMON Starting test: Connectivity ......................... SIMON passed test Connectivity Doing primary tests Testing server: Default-First-Site-Name\SIMON Starting test: Advertising Fatal Error:DsGetDcName (SIMON) call failed, error 1722 The Locator could not find the server. ......................... SIMON failed test Advertising Starting test: FrsEvent ......................... SIMON passed test FrsEvent Starting test: DFSREvent There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems. ......................... SIMON failed test DFSREvent Starting test: SysVolCheck [SIMON] An net use or LsaPolicy operation failed with error 2, The system cannot find the file specified.. The SysVol is not ready. This can cause the DC to not advertise itself as a DC for netlogon after dcpromo. Also trouble with FRS SysVol replication can cause Group Policy problems. Check the FRS event log on this DC. ......................... SIMON failed test SysVolCheck Starting test: KccEvent ......................... SIMON passed test KccEvent Starting test: KnowsOfRoleHolders ......................... SIMON passed test KnowsOfRoleHolders Starting test: MachineAccount Could not open pipe with [SIMON]:failed with 2: The system cannot find the file specified. Could not get NetBIOSDomainName Failed can not test for HOST SPN Failed can not test for HOST SPN ......................... SIMON passed test MachineAccount Starting test: NCSecDesc ......................... SIMON passed test NCSecDesc Starting test: NetLogons [SIMON] An net use or LsaPolicy operation failed with error 2, The system cannot find the file specified.. ......................... SIMON failed test NetLogons Starting test: ObjectsReplicated ......................... SIMON passed test ObjectsReplicated Starting test: Replications ......................... SIMON passed test Replications Starting test: RidManager ......................... SIMON passed test RidManager Starting test: Services ......................... SIMON passed test Services Starting test: SystemLog ......................... SIMON passed test SystemLog Starting test: VerifyReferences ......................... SIMON passed test VerifyReferences Running partition tests on : ForestDnsZones Starting test: CheckSDRefDom ......................... ForestDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... ForestDnsZones passed test CrossRefValidation Running partition tests on : DomainDnsZones Starting test: CheckSDRefDom ......................... DomainDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... DomainDnsZones passed test CrossRefValidation Running partition tests on : Schema Starting test: CheckSDRefDom ......................... Schema passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Schema passed test CrossRefValidation Running partition tests on : Configuration Starting test: CheckSDRefDom ......................... Configuration passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Configuration passed test CrossRefValidation Running partition tests on : SIMON Starting test: CheckSDRefDom ......................... SIMON passed test CheckSDRefDom Starting test: CrossRefValidation ......................... SIMON passed test CrossRefValidation Running enterprise tests on : SIMON.adtest Starting test: LocatorCheck Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1722 A Global Catalog Server could not be located - All GC's are down. Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1722 A Primary Domain Controller could not be located. The server holding the PDC role is down. Warning: DcGetDcName(TIME_SERVER) call failed, error 1722 A Time Server could not be located. The server holding the PDC role is down. Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 1722 A Good Time Server could not be located. Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1722 A KDC could not be located - All the KDCs are down. ......................... SIMON.adtest failed test LocatorCheck Starting test: Intersite ......................... SIMON.adtest passed test Intersite
错误1722是通用RPC故障报错,我搜索了相关方案均不匹配当前场景,目前排查已陷入停滞。
故障排查解决方案
结合提供的所有日志信息,可按以下优先级逐一排查修复:
- 首先排查公有云安全组规则,仅关闭系统层面防火墙不生效,公有云实例的入站安全组默认会拦截绝大多数端口,需在安全组中放通客户端公网出口IP对以下端口的访问权限:
- TCP 53、UDP 53(DNS)
- TCP 88、UDP 88(Kerberos认证)
- TCP 135(RPC端点映射)
- TCP 139、UDP 137、UDP 138(NetBIOS)
- TCP 389、UDP 389(LDAP)
- TCP 445(SMB共享)
- TCP 464、UDP 464(Kerberos密码修改)
- TCP 49152~65535(RPC动态端口段,极易遗漏)
- 修复DC端SYSVOL共享异常:dcdiag日志明确提示SysVol未就绪、Netlogon共享不存在,这是DC无法正常提供域服务的核心原因,修复步骤:
- 登录DC服务器,运行
net share查看共享列表,确认是否存在SYSVOL和NETLOGON两个共享 - 若不存在,打开注册表编辑器定位到
HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters - 找到
SysVolReady项,将默认值0修改为1,保存后重启Netlogon服务 - 再次运行
net share确认两个共享已正常显示,重新执行dcdiag验证SysVolCheck、NetLogons、Advertising测试项是否通过
- 登录DC服务器,运行
- 检查AD站点配置:打开AD站点和服务控制台,检查Default-First-Site-Name站点关联的子网列表,需将公司的公网出口IP段添加到子网列表并关联到对应站点,否则DC会拒绝来自未知站点的客户端请求
- 客户端验证端口连通性:不要仅依赖ping测试,在客户端PowerShell中执行以下命令验证关键端口连通性,任意端口不通都会触发1722 RPC报错:
Test-NetConnection 45.76.xx.xx -Port 389 Test-NetConnection 45.76.xx.xx -Port 445 Test-NetConnection 45.76.xx.xx -Port 135 - 客户端临时配置优化:域加入前手动设置网卡的连接特定DNS后缀为
simon.adtest,勾选“在DNS中注册此连接的地址”,保存后重启网卡再尝试加入域。
内容的提问来源于stack exchange,提问作者sfkHooper
相关产品推荐
相关产品推荐

