DNS: The DNS server <IP address> on <adapter name> must resolve Global Catalog resource records for the domain controller

Applies To: Windows Server 2008, Windows Server 2008 R2, Windows Server 2012

This topic is intended to address a specific issue identified by a Microsoft Baseline Configuration Analyzer or Best Practices Analyzer scan. You should apply the information in this topic only to computers that have had the DNS Microsoft Baseline Configuration Analyzer or DNS Best Practices Analyzer run against them and are experiencing the issue addressed by this topic. For more information about best practices and scans, see Best Practices Analyzer.

Operating System

Windows Server 2008, Windows Server 2008 R2, Windows Server 2012

Product/Feature

DNS

Severity

Critical

Category

Operation

Issue

Network interfaces must be configured with DNS servers that are able to resolve Global Catalog service records for the domain controller.

A DNS server configured on the network interface did not respond to a query for the _ldap._tcp.gc._msdcs.<DnsDomainName> service (SRV) record.

Impact

Active Directory Domain Services (AD DS) operations that depend on locating a Global Catalog (GC) server will fail.

Resolution

Configure the network adapter to use DNS servers that are able to resolve Global Catalog service records in the domain.

Configure network adapters to use DNS servers that host the domain zone containing the _ldap._tcp.gc._msdcs.<DnsDomainName> SRV record, or forward to other DNS servers that host this record.

To configure valid IPv4 DNS server addresses

  1. Click Start, click Control Panel, click Network and Internet, click Network and Sharing Center, click Change Adapter settings, double-click the network connection you want to change, and then click Properties.

  2. Click Internet Protocol Version 4 (TCP/IPv4), and then click Properties.

  3. Click Use the following DNS server addresses.

  4. In Preferred DNS server and Alternate DNS server, type addresses that host the domain zone containing _ldap._tcp.gc._msdcs.<DnsDomainName>.

  5. Click Advanced, and then click DNS.

  6. Click Edit or Remove to change any DNS servers that do not host the domain zone containing _ldap._tcp.gc._msdcs.<DnsDomainName>.

To configure valid IPv6 DNS server addresses

  1. Click Start, click Control Panel, click Network and Internet, click Network and Sharing Center, click Change Adapter settings, double-click the network connection you want to change, and then click Properties.

  2. Click Internet Protocol Version 6 (TCP/IPv6), and then click Properties.

  3. Click Use the following DNS server addresses.

  4. In Preferred DNS server and Alternate DNS server, type addresses that host the domain zone containing _ldap._tcp.gc._msdcs.<DnsDomainName>.

  5. Click Advanced, and then click DNS.

  6. Click Edit or Remove to change any DNS servers that do not host the domain zone containing _ldap._tcp.gc._msdcs.<DnsDomainName>.