RE: DSAccess Problems





"Uellington Santos" wrote:

> Hi everyone!
>
> Some days ago, we have made changes at AD of one of our clients and now we
> are experiencing some Exchange problems.
>
> So, our client has a larger network with 10 Domain Controllers and 2
> Exchange Servers. Eight Domain Controllers are here in Brazil and one at
> Amsterdam/Holand and the other one at Hong Kong/China (Amsterdam and Hong
> Kong have a VPN Connections over Internet to Brazil).
>
> When we have made the changes at AD all of policies were deleted because an
> incident, and we have used the RecreateDefpol.EXE to recover the Default
> Domain Police and Default Domain Controller Policy, all the other policies
> had been recreated. We had depromoting/promoting all the domain controllers
> too, except the PDC.
>
> Now, the two Exchange Servers are using the Domain Controllers from Hongk
> Kong and Amsterdam, causing troubles for users here in Brazil when they
> change their passwords. I think this occurs because the replication's time
> don't attends the users expectation. If we set the Domain Controllers
> manually, the MSExchange System Attendant and other services don't start.
>
> We activate the diagnostics (in level 5) of service DSAccess, and we get the
> following events as results:
>
> 1:
>
> Event Type: Information
> Event Source: MSExchangeDSAccess
> Event Category: Topology
> Event ID: 2080
> Date: 4/6/2005
> Time: 03:35:23 PM
> User: N/A
> Computer: SAMBMAIL
> Description:
> Process INETINFO.EXE (PID=2224). DSAccess has discovered the following
> servers with the following characteristics:
> (Server name | Roles | Reachability | Synchronized | GC capable | PDC |
> SACL right | Critical Data | Netlogon)
> In-site:
> samubu1.samarco.com.br CDG 7 7 1 0 0 1 7
> samusged.samarco.com.br CDG 7 7 1 0 0 1 7
> Out-of-site:
> sambhz2.samarco.com.br CDG 7 7 1 0 0 1 7
> SAMHKG1.samarco.com.br CDG 7 7 1 0 1 1 7
> samams1.samarco.com.br CDG 7 7 1 0 1 1 7
> sammat1.samarco.com.br CDG 7 7 1 0 0 1 7
> samger1.samarco.com.br CDG 7 7 1 0 0 1 7
> samgsged.samarco.com.br CDG 7 7 1 0 0 1 7
> SAMBHZ1.samarco.com.br CDG 7 7 1 0 0 1 7
> samvix1.samarco.com.br CDG 7 7 1 0 0 1 7
>
>
> For more information, click http://www.microsoft.com/contentredirect.asp.
>
> 2:
>
> Event Type: Information
> Event Source: MSExchangeDSAccess
> Event Category: Topology
> Event ID: 2084
> Date: 6/4/2005
> Time: 15:35:24
> User: N/A
> Computer: SAMBMAIL
> Description:
> Process INETINFO.EXE (PID=2224). No Domain Controller server is up in the
> local site 'UBU'. DSAccess will use the following out of site Domain
> Controller servers:
> SAMHKG1.samarco.com.br
> samams1.samarco.com.br
>
>
> For more information, click http://www.microsoft.com/contentredirect.asp.
>
> 3:
>
> Event Type: Information
> Event Source: MSExchangeDSAccess
> Event Category: Topology
> Event ID: 2085
> Date: 6/4/2005
> Time: 15:35:24
> User: N/A
> Computer: SAMBMAIL
> Description:
> Process INETINFO.EXE (PID=2224). No Global Catalog server is up in the local
> site 'UBU'. DSAccess will use the following out of site Global Catalog
> servers:
> SAMHKG1.samarco.com.br
> samams1.samarco.com.br
>
>
> For more information, click http://www.microsoft.com/contentredirect.asp.
>
>
> I don't understand, all sites have a domain controller and global catalog
> server, I can connect on the port 3268 through telnet, but the Exchange
> Servers still using the Domain Controllers from outside of Brazil.
>
> Follows, links to view our Domain Controllers Policy and Servers Members
> Policy, all Domain Controllers are under Defaul Domain Controllers Policy and
> all Exchange Servers are under Default Member Servers Policy.
>
> http://uellington-santos.sites.uol.com.br/Policies.zip
>
> Thanks!
>
> Sorry to the poor English.
>
> --
> Uellington Santos
> SD&O - Service Delivery & Operations
> Hewlett-Packard Brazil


Last time I got this kind of problem it related to DC and GC due to DNS
issues. Check the DC/GC status by running dcdiag, netdiag, nltest. Run
nltest /dsgetsite on Exchange server to see if the server is seeing local
site.
.



Relevant Pages

  • DSAccess Problems
    ... are experiencing some Exchange problems. ... our client has a larger network with 10 Domain Controllers and 2 ... the two Exchange Servers are using the Domain Controllers from Hongk ... links to view our Domain Controllers Policy and Servers Members ...
    (microsoft.public.exchange.admin)
  • Re: net use and LM / NTLM
    ... Kerberos authentication is used between Windows 2000 machines in a Windows ... verify that all domain controllers for users who log on to ... controllers") MUST have been upgraded to SP4. ... with earlier servers exactly as it did with Service Pack 3. ...
    (Focus-Microsoft)
  • Re: gpt.ini file
    ... -Domain controllers have the read and apply rights to the Domain Controllers ... > B382-0Z5CA836A2E2} in the sysvol folder. ... Half my servers were fine because I wasn't ... > correct group policy file but I couldn't figure out where that was. ...
    (microsoft.public.windows.server.active_directory)
  • Re: delete computer
    ... member servers are not deleted? ... Your script can check the operatingSystem attribute to make sure the ... the ability to delete domain controllers ... would belong only to domain admins; for member servers this might be ...
    (microsoft.public.scripting.vbscript)
  • Re: Account lockouts
    ... First off you can't disable lockout policy for specific accounts, it is a domain wide setting. ... Second, enable auditing on your domain controllers and member servers, specifically the logon failures auditing ...
    (microsoft.public.win2000.security)