question

RomulusAlbalonga-4079 avatar image
0 Votes"
RomulusAlbalonga-4079 asked LimitlessTechnology-2700 answered

All of the sudden one MFC member left a cluster of two

I manage a MFC of my school and I'm more a network than a system admin, so I apologize if I may not be familiar with some concepts/terminology.

Five days ago one of the two 2012 R2 servers (CLUSTER01) left the cluster. I ran a Failover Cluster Validation Report and severe errors were huighlighted, please see them here below.
(I replaced the domain name with theschool.local). Ping works, RDP doesn't, at the beginning CLUSTER01's clock was ahead by 10 seconds. I fixed it manually with PS Set-Date but that didn't help.

Errors from the report:

1) The site name of node CLUSTER01.theschool.local could not be determined because of this error: Could not get domain controller name from machine CLUSTER01.theschool.local.

nltest /dsgetdc:theschool.local
Getting DC name failed: Status = 1355 0x54b ERROR_NO_SUCH_DOMAIN

2) The distinguished name of node CLUSTER01.theschool.local could not be determined because of this error: There was an error getting information about the organization unit for node 'CLUSTER01.theschool.local' from the domain 'theschool.local'.

3) The organizational unit of node CLUSTER01.theschool.local could not be determined because of this error: Did not find an Organization Unit (OU) in the Active Directory

4) Connectivity to a writable domain controller from node CLUSTER01.theschool.local could not be determined because of this error: Could not get domain controller name from machine CLUSTER01.

5) Node(s) CLUSTER01.theschool.local cannot reach a writable domain controller. Please check connectivity of these nodes to the domain controllers.

I sought the Internet for the right remediation procedure but I could not find any related to MFC.
I would start by fixing the first point and then move on (most probably the subsequent problems will get sorted out automagically)

Is there anybody who can help, please?
We have limited resources but I'm willing to learn a lot.

Regards,

Alex

windows-server-2012
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

LimitlessTechnology-2700 avatar image
0 Votes"
LimitlessTechnology-2700 answered

Hi @RomulusAlbalonga-4079

Some points you can try to sort this issue are listed below, try each one of them to see if they are helpful to you.

Method 1: Fix Domain Name System (DNS) errors.
Method 2: Synchronize the time between computers.
Method 3: Check the Access to this computer from the network user rights.
Method 4: Verify that the domain controller's userAccountControl attribute is 532480.
Method 5: Fix the Kerberos realm (confirm that the PolAcDmN registry key and the PolPrDmN registry key match).
Method 6: Reset the machine account password, and then obtain a new Kerberos ticket.

Here is a link for a detailed description of the process that you must follow.

Cluster validation test on Active Directory configuration fails in a multi-site cluster scenario https://docs.microsoft.com/en-us/troubleshoot/windows-server/high-availability/cluster-validation-test-fails-multi-site-cluster-scenario

Domain controller is not functioning correctly https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/domain-controller-not-functioning-correctly

Hope this resolves your Query!!


--If the reply is helpful, please Upvote and Accept it as an answer–

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.