我在新的 VDS 上部署了 AD DS。我将域区域委托给服务器。问题是我无法将 PC 添加到域,因为我无法在 DNS 管理器中将域控制器私有 IP 地址更改为公共地址。当我尝试这样做时,一段时间后会改回来。
尝试将外部 IP 地址添加到网络适配器,几乎成功了。DNS 管理器中出现了公网 IP,但我猜想路由出了问题。如果我将 DNS 配置为仅监听公网 IP,则与 DNS 服务器的连接会丢失。
服务器操作系统:Windows Server 2019 Datacenter
服务器私有IP:10.128.0.10
服务器公网IP:xxx.xxx.xxx.xxx
客户端操作系统:Windows 7、10
我应该怎么做才能让 DNS 服务器指向域控制器(也是名称服务器)的公共 IP 而不是本地 IP?
更新
我取消选中了区域属性中的“将区域存储在 Active Directory 中”,最终它停止将 IP 重置为本地。现在我可以通过互联网 ping DC 和区域,但仍然无法将 PC 添加到域。现在我在加入域时收到错误:“未找到网络路径”以下是来自客户端 NETSETUP 的日志:
12/12/2020 18:57:31:135 -----------------------------------------------------------------
12/12/2020 18:57:31:135 NetpDoDomainJoin
12/12/2020 18:57:31:135 NetpMachineValidToJoin: 'USER-PC'
12/12/2020 18:57:31:135 OS Version: 6.1
12/12/2020 18:57:31:135 Build number: 7601 (7601.win7sp1_ldr_escrow.191127-1706)
12/12/2020 18:57:31:135 ServicePack: Service Pack 1
12/12/2020 18:57:31:135 SKU: Windows 7 Максимальная
12/12/2020 18:57:31:135 NetpDomainJoinLicensingCheck: ulLicenseValue=1, Status: 0x0
12/12/2020 18:57:31:135 NetpGetLsaPrimaryDomain: status: 0x0
12/12/2020 18:57:31:135 NetpMachineValidToJoin: status: 0x0
12/12/2020 18:57:31:135 NetpJoinDomain
12/12/2020 18:57:31:135 Machine: USER-PC
12/12/2020 18:57:31:135 Domain: org.a-b-c.ru
12/12/2020 18:57:31:135 MachineAccountOU: (NULL)
12/12/2020 18:57:31:135 Account: org.a-b-c.ru\Administrator
12/12/2020 18:57:31:135 Options: 0x27
12/12/2020 18:57:31:135 NetpLoadParameters: loading registry parameters...
12/12/2020 18:57:31:135 NetpLoadParameters: DNSNameResolutionRequired not found, defaulting to '1' 0x2
12/12/2020 18:57:31:135 NetpLoadParameters: DomainCompatibilityMode not found, defaulting to '0' 0x2
12/12/2020 18:57:31:135 NetpLoadParameters: status: 0x2
12/12/2020 18:57:31:135 NetpValidateName: checking to see if 'org.a-b-c.ru' is valid as type 3 name
12/12/2020 18:57:31:276 NetpCheckDomainNameIsValid [ Exists ] for 'org.a-b-c.ru' returned 0x0
12/12/2020 18:57:31:276 NetpValidateName: name 'org.a-b-c.ru' is valid for type 3
12/12/2020 18:57:31:276 NetpDsGetDcName: trying to find DC in domain 'org.a-b-c.ru', flags: 0x40001010
12/12/2020 18:57:34:041 NetpDsGetDcName: failed to find a DC having account 'USER-PC$': 0x525, last error is 0x0
12/12/2020 18:57:34:041 NetpLoadParameters: loading registry parameters...
12/12/2020 18:57:34:041 NetpLoadParameters: DNSNameResolutionRequired not found, defaulting to '1' 0x2
12/12/2020 18:57:34:041 NetpLoadParameters: DomainCompatibilityMode not found, defaulting to '0' 0x2
12/12/2020 18:57:34:041 NetpLoadParameters: status: 0x2
12/12/2020 18:57:34:073 NetpDsGetDcName: status of verifying DNS A record name resolution for 'dc2.org.a-b-c.ru': 0x0
12/12/2020 18:57:34:073 NetpDsGetDcName: found DC '\\dc2.org.a-b-c.ru' in the specified domain
12/12/2020 18:57:34:073 NetpJoinDomainOnDs: NetpDsGetDcName returned: 0x0
12/12/2020 18:57:34:088 NetUseAdd to \\dc2.org.a-b-c.ru\IPC$ returned 53
12/12/2020 18:57:34:088 NetpJoinDomain: status of connecting to dc '\\dc2.org.a-b-c.ru': 0x35
12/12/2020 18:57:34:088 NetpJoinDomainOnDs: Function exits with status of: 0x35
12/12/2020 18:57:34:088 NetpDoDomainJoin: status: 0x35
答案1
您是否尝试取消选中域控制器上的“在 DNS 中注册此连接的地址”以阻止 DNS 服务器中的自动更新过程?
编辑:
请尝试:禁用动态 DNS 更新在域控制器上:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters
DWORD: UseDynamicDns 0
然后重新启动服务器。
编辑:
您可以尝试以下建议的解决方案吗这里?