Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows Server 2003Windows 2000Windows NTSmall Business ServerVirtual ServerExchange ServerIISHost Integration ServerISA ServerSMSWSUSMOMWindows Media ServerSecurityCertification
Related Topics
SQL ServerMS WindowsMS OfficePC HardwareMore Topics ...

Windows Server Forum / Windows Server 2003 / DNS / July 2005

Tip: Looking for answers? Try searching our database.

Error 1005 & 1030

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Esteban - 28 Jul 2005 13:38 GMT
Hi,

Everything looks find in each computer of the business but when i go
into the event log, i see the same error everytime someone log in his
computer.

On the XP computers, the errors 1005 & 1030 are always there with
Source = UserEnv.

1005 = Windows can't connect to domain XYZ.(Server out of order).
      The workgroup strategy was interrupted.

1030= This error talk about group policy too.

On the 2k computers i have always the error 1000 with still UserEnv as
source.

Everything looks find on the computers except those errors and i wanted

to know what they mean and how i can fix them. All the computers have
the windows patches up to date.

Thanks for giving me a clue!
Ace Fekay [MVP] - 28 Jul 2005 16:08 GMT
> Hi,
>
[quoted text clipped - 20 lines]
>
> Thanks for giving me a clue!

This sounds like a classic DNS misconfiguration. If you can provide the
following info, we'll be able to pinpoinit it with 98% accuracy, considering
there is nothing out of the ordinary added, such as Zone Alarm, (and other
applications) etc, which can cause major issues.

1. Unedited ipconfig /all from a client and from your DC(s)
2. The actual DNS domain name of AD (found in ADUC)
3. The zonename spelling in your Forward Lookup Zones in DNS for your AD
zone
4. If updates are set to allow under the zone's properties
5. If any of the DCs have more than one NIC
6. Do you have a firewall? If so, what brand?
7. Is/are forwarder(s) configured?
8. Do the SRV records exist under your zone name?

Thank you,
Signature

Regards,
Ace

Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.

This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services
Infinite Diversities in Infinite Combinations.
=================================

Esteban - 28 Jul 2005 20:43 GMT
I went into different user computer and i only can see those error at
the login in the event viewer of one domain that is XYZ. All the other
user that aren't on XYZ and are on ABC don't get any error in the log
file.

My english is not very good so i can't understand at 100% your question
but will answer the one that are clear to me:

1. what u mean by unedited ipconfig? u want me to give you info of my
server with that i get with ipconfig?

2. I don't know what AD and ADUC is, i'm only a student here, not the
administrator, just trying to figure out where is the problem.

Is there anything i can do in a user computer so i can give you more
info?

The firewall is a Cisco PIX 515E

Thanks!
Ace Fekay [MVP] - 29 Jul 2005 04:58 GMT
> I went into different user computer and i only can see those error at
> the login in the event viewer of one domain that is XYZ. All the other
[quoted text clipped - 6 lines]
> 1. what u mean by unedited ipconfig? u want me to give you info of my
> server with that i get with ipconfig?

Yes, please. Please run at a CMD prompt:
ipconfig /all > c:\ipconfig.txt

Then open the c:\ipconfig.txt and copy and paste the data here.

> 2. I don't know what AD and ADUC is, i'm only a student here, not the
> administrator, just trying to figure out where is the problem.

Active Directory Users and Computers. If you are only a student, and not the
administrator, this needs to be brought to the administrator's attention.

> Is there anything i can do in a user computer so i can give you more
> info?

Yes, run the ipconfig /all results please.

Also please run in a CMD prompt:
gpresult > c:\gpresult.txt

Then open the c:\gpresult.txt and copy and paste the data here.

> The firewall is a Cisco PIX 515E

Are there rules on the firewall blocking domain communication traffic?

> Thanks!

You are welcome. I believe you will need to notify your administrator and
get him or her involved.

Ace
Esteban - 29 Jul 2005 14:08 GMT
well, i have one problem! When i generate those file, they're in
french, and i guess you won't understand! Is there any way to generate
an english file from another language O/S?
Ace Fekay [MVP] - 29 Jul 2005 15:28 GMT
> well, i have one problem! When i generate those file, they're in
> french, and i guess you won't understand! Is there any way to generate
> an english file from another language O/S?

I will understand it knowing what position the results are in. Don't worry,
I'll manage, and I'm sure others here may be able to read it as well.

Did you notify your administrator about these issues?

Ace
Esteban - 29 Jul 2005 18:07 GMT
GPResult:

Outil de résultat du système d'exploitation Microsoft (R) Windows (R)
XP v2.0
Copyright (C) Microsoft Corp. 1981-2001

Jeu crée le 2005-07-29 ... 08:47:41

Résultats RSOP pour NTI\lecste1 sur LECSTE1D : mode journalisation
-------------------------------------------------------------------

Type de système d'exploitation:                     Microsoft Windows
XP Professionnel
Configuration du système d'exploitation :           Station de travail
membre
Version du système d'exploitation :                 5.1.2600
Nom du domaine:     NTI
Type de domaine :   Windows 2000
Nom du site :       111Duke
Profil itinérant :
Profil local :  C:\Documents and Settings\lecste1
Connexion via une liaison lente ? : Oui

   Paramètre de l'ordinateur
   --------------------------
   CN=LECSTE1D,CN=Computers,DC=NTI,DC=NEXXLINK,DC=INT
   Heure de la dernière application de la stratégie de groupe :
2005-07-29 at 08:37:28
   Stratégie de groupe appliquée depuis :
dukedc02.NTI.NEXXLINK.INT
   Seuil de liaison lente dans la stratégie de groupe :   500 kbps

   Objets Stratégie de groupe appliqués
   -------------------------------------
       N/A

   Les objets stratégie de groupe n'ont pas été appliqués car ils
ont été refusé

------------------------------------------------------------------------------
       Stratégie de groupe locale
       Filtrage :  Non appliqué (vide)

   L'ordinateur fait partie des groupes de sécurité suivants :
   -----------------------------------------------------------
       Administrateurs
       Tout le monde
       Utilisateurs authentifiés

   PARAMÈTRES UTILISATEURS
   ------------------------
   CN=*******Name of a
user*****,OU=Operations,DC=NTI,DC=NEXXLINK,DC=INT
   Heure de la dernière application de la stratégie de groupe :
2005-07-29 at 07:19:04
   Stratégie de groupe appliquée depuis :
dukedc02.NTI.NEXXLINK.INT
   Seuil de liaison lente dans la stratégie de groupe :   500 kbps

   Objets Stratégie de groupe appliqués
   -------------------------------------
       Stratégie de groupe locale

   L'utilisateur fait partie des groupes de sécurité suivants :
   ------------------------------------------------------------
       Domain Users
       Tout le monde
       Administrateurs
       Utilisateurs
       INTERACTIF
       Utilisateurs authentifiés
       LOCAL
       NTIAppAccess2KGr
       NTIAppNavisionGr
       NTIAppOutlook2KGr
       NTIAll
       NTIAppNavision37Gr
       NTIAppWinword2KGr
       NTIAppPowerpoint2KGr
       NTIRedirectionGr
       NTIStageGr
       NTIIntegrationGr
       NexxlinkExchangevuegr
       NTIAppConfig

IPCONFIG:

Configuration IP de Windows

       Nom de l'hôte . . . . . . . . . . : LecSte1D

       Suffixe DNS principal . . . . . . : NTI.NEXXLINK.INT

       Type de noeud . . . . . . . . . . : Hybride

       Routage IP activé . . . . . . . . : Non

       Proxy WINS activé . . . . . . . . : Non

       Liste de recherche du suffixe DNS : NTI.NEXXLINK.INT

Carte Ethernet Connexion au réseau local:

       Suffixe DNS propre à la connexion :

       Description . . . . . . . . . . . : Carte réseau 3Com
EtherLink XL 10/100 PCI TX (3C905B-TX)

       Adresse physique . . . . . . . . .: 00-50-04-65-92-C1

       DHCP activé. . . . . . . . . . . :  Oui

       Configuration automatique activée . . . . : Oui

       Adresse IP. . . . . . . . . . . . : 172.18.2.217

       Masque de sous-réseau . . . . . . : 255.255.0.0

       Passerelle par défaut . . . . . . : 172.18.0.2

       Serveur DHCP. . . . . . . . . . . : 172.18.0.100

       Serveurs DNS . . . . . . . . . .  : 172.18.0.100

       Serveur WINS principal. . . . . . : 172.18.0.100

       Bail obtenu . . . . . . . . . . . : 29 juillet 2005 04:25:40

       Bail expirant . . . . . . . . . . : 30 juillet 2005 04:25:40
Ace Fekay [MVP] - 30 Jul 2005 05:50 GMT
> GPResult:
>
[quoted text clipped - 125 lines]
>
>         Bail expirant . . . . . . . . . . : 30 juillet 2005 04:25:40

Thank for posting this info.

Your ipconfig /all looks ago from what I can see. From what I can tell GPOs
appear to be working, but can't guarantee it 100% because I don't understand
French. I am trying to relate it to an English output. I believe there is a
policy being applied other than the Default Domain Policy. Also, one more
thing, there maybe a firewall (personal or entry point) or something else
blocking communications.

I believe at this point you need to contact your administrator to see if
there's errors on the DC, etc, which unfortunately you do not have access
to.

Ace
Kevin D. Goodknecht Sr. [MVP] - 30 Jul 2005 16:55 GMT
> Hi,
>
[quoted text clipped - 7 lines]
> 1005 = Windows can't connect to domain XYZ.(Server out of order).
>        The workgroup strategy was interrupted.

This error, according to eventid.net is caused because winlogon cannot
access the Global catalog and can be caused by a firewall between the
Workstation and the DC.
It can also be caused by having an incorrect LDAP IP address record, meaning
the Domain name is not resolved to an IP address on the Domain Controller
that has file sharing enabled.

> 1030= This error talk about group policy too.

A 1030 event is also caused from not being abled to acess the GPOs from the
domain name.
In looking at your ipconfig /all i9t states your AD domain name should be
NTI.NEXXLINK.INT, this means that if you resolve that name, it must resolve
to IP addresses on domain controllers that have file sharing enabled. This
allows access to the GPOs located in the domain DFS share at
\\NTI.NEXXLINK.INT\sysvol\NTI.NEXXLINK.INT\policies

Other cases I've seen to cause this:
1. TCP/IP NetBIOS helper service is stopped or disabled on the client, this
service is required to access DFS shares.
2. The DNS server used in TCP/IP properties cannot resolve the AD domain
name to the domain controller IP.
3. DC is muti-homed and the interface binding order is incorrect, the
interface that has file sharing enabled on the DC must be at the top of the
connections pane in Advanced Settings of the network properties. The DC
administrator must resolve this.

> On the 2k computers i have always the error 1000 with still UserEnv as
> source.

Once again UserEnv errors are caused be the same problems as previously
stated.

Signature

Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================

 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2010 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.