父域无法访问子域Active Directory,但可Ping及访问文件求助
Hey there, let's dig into this Kerberos issue that's stopping you from accessing your child domain's Active Directory. I've worked through plenty of multi-domain AD setups on Server 2016, so let's walk through the most impactful fixes step by step:
1. Verify DNS Resolution (Critical for Kerberos)
Kerberos lives and dies on proper DNS, so start here:
- On your primary DC, run these commands to check SRV records for the child domain:
You should see the child DC's hostname and IP in the results.nslookup -type=SRV _ldap._tcp.child.xxx.com nslookup -type=SRV _kerberos._tcp.child.xxx.com - Confirm the child DC's A record exists in your primary domain's DNS (or that your primary DNS forwards requests to the child domain's DNS server). Also, make sure the child DC's DNS settings point to either itself or the primary domain's DNS (avoid external DNS unless forwarding is properly configured).
2. Purge and Test Kerberos Ticket Cache
Stale or invalid Kerberos tickets often cause this kind of error:
- Clear the Kerberos cache on the primary DC with:
klist purge - Try to request a ticket for the child domain's KDC:
klist get krbtgt/child.xxx.com@XXX.COM - If this fails, check the System and Security event logs on both DCs for Kerberos-related events (look for IDs like 4771 or 10010) — these will give you specific details about why authentication is failing.
3. Ensure Time Sync Between DCs
Kerberos won't tolerate more than a 5-minute time difference by default:
- Check the time sync status on both servers with:
w32tm /query /status - If they're out of sync, force them to sync with the domain hierarchy:
w32tm /config /syncfromflags:domhier /update net stop w32time && net start w32time
4. Validate Service Principal Names (SPNs)
Missing or incorrect SPNs break Kerberos authentication for AD services:
- On the child DC, list registered SPNs with:
setspn -L <ChildDC-Hostname> - Confirm you see entries like:
LDAP/<ChildDC-Hostname>.child.xxx.comLDAP/<ChildDC-Hostname>Kerberos/<ChildDC-Hostname>.child.xxx.comKerberos/<ChildDC-Hostname>
- If any are missing, add them with the
setspn -Acommand, e.g.:setspn -A LDAP/<ChildDC-Hostname>.child.xxx.com <ChildDC-Hostname>
5. Double-Check AD Sites and Services Configuration
Even if the DCs are in the same site, misconfigured subnets can throw off Kerberos:
- Open Active Directory Sites and Services and check the subnets linked to your site. Make sure the child DC's static IP falls within the subnet range associated with the site. If not, update the subnet or link it to the correct site.
6. Confirm Firewall Ports Are Open
File sharing and ping work, but Kerberos/LDAP ports might be blocked:
- Ensure these ports are open between the primary and child DCs:
- TCP/UDP 88 (Kerberos authentication)
- TCP 389 (LDAP)
- TCP 464 (Kerberos password change)
- TCP 3268 (Global Catalog, if used)
- Test port connectivity with:
Test-NetConnection <ChildDC-IP> -Port 88
7. Verify Domain Trust Relationship
A broken trust can cause Kerberos failures even if basic connectivity works:
- Open Active Directory Domains and Trusts on the primary DC, right-click your primary domain, go to Properties > Trusts, and confirm the trust with
child.xxx.comis bidirectional and shows a "Valid" status. - Verify the trust via command line:
netdom trust XXX.COM /domain:child.xxx.com /verify - If verification fails, reset the trust:
netdom trust XXX.COM /domain:child.xxx.com /reset
After each step, try accessing the child domain's Active Directory again (e.g., via Active Directory Users and Computers) to see if the error is resolved.
内容的提问来源于stack exchange,提问作者JukEboX

