Re: Replication Problem

From: ptwilliams (ptw2001_at_hotmail.com)
Date: 01/22/05


Date: Sat, 22 Jan 2005 12:49:57 -0000

Two months is looking like the tombstone period has expired (60 days by
default). This is probably the problem.

Out of your possible solutions, I'd say number one is a no-go -it won't
work. Number two is the best solution.

The question here, is if both DCs in the site are up-to-date or not.

You could try resetting the secure channel with the DCs in the other site.

However, if 60 days have passed, the best thing to do is demote both DCs in
this site (using /forceremoval if necessary), running a metadata cleanup and
then re-promoting the DCs.

Perhaps you will learn some good lessons here:
 -- Fix replication problems ASAP.
 -- Don't configure the bridgehead servers manually. Let the ISTG do it.
This way, the KCCs can fail-over.

-- 
Paul Williams
http://www.msresource.net
http://forums.msresource.net
"Ido Ran" <ido.ran@gmail.com> wrote in message 
news:ejjLV4HAFHA.3592@TK2MSFTNGP09.phx.gbl...
Hello,
I have a Windows 2000 domain scatered over several sites. In is a single
domain in the forest. Each site has two DCs in it. We have setup the
iner-site replication topology in Sites and Services snap-in and everything
works fine.
About two mounth ago on of the servers has been shout-down, that server was
the bridge-head server in it site. The KDC has not moved the bridge-head to
the second DC in that site. Now, two mounth later I have restarted the
server.
The problem: The DC does not replicate with other DCs in the domain. The
ReplMon tool show an "Access Denied" problem.
I have searched in the MSDN and google for that problem and found a few
articles but none of them solved the problem.
I have tried the following solutions:
* Disable the KDC service, restart the server and use netdom to reset the DC
secure-channel with other DC. This did not solve the problem but it solved
the intra-site replication. So now the two DCs replicate between them-selves
but not with over DCs.
* run RepAdmin tool with /SyncAll switch and /Sync switch
Other sympthoms:
When I use "net time \\otherDC" the result is "Access Denied", when I use
"net time \\X.X.X.X" (The IP of OtherDC) the command complete successfully.
Possible Solutions:
* Backup the Active Directory database in other site and restore only the
Domain Controllers OU. I hope this will resync the computer account
passwords and the replication will restart to work
* Demote the bridge-head server in the problematic site (possible with
/force_removal), remove any leftover objects in the domain and promote the
DC again.
Please help me to understand what went wrong and how can I reinitiate the
repliation to that site.
Thank you very much,
Ido.


Relevant Pages

  • Re: PDC Is not replicating !!
    ... server on the replication DC. ... I have ACE server installed. ... > DCs replicating by disabling replication when USN rollback is ... > If you used imaging to copy your production environment into a lab ...
    (microsoft.public.win2000.active_directory)
  • Different Directory Information Trees
    ... The DCs were not able to apply group policy to themselves. ... I noticed some NTDS Replication 1955 and 1083 errors that come together. ... Weird side-effect I also noticed was that I can no longer launch the Active Directory related Management tools from my workstation unless I use the Active Directory Management MMC. ... I noticed a lot if DNS 4015 errors on the server it appears that the DNS or Active Directory is "busy". ...
    (microsoft.public.windows.server.active_directory)
  • Replication errors -BuiltinAdministrators doesnt have access ri
    ... * Connecting to directory service on server agfvads1. ... Replication Service,CN=System,DC=andrew,DC=com ... clean up this DCs ... Running partition tests on: Configuration ...
    (microsoft.public.windows.server.active_directory)
  • Re: Missing NTDS Settings object
    ... the AD database on ALL the DCs within that domain ... That's when the replication broke and the ISTG settings in the NTDS Site ... NO server for that domain appears in ANY site, ... and services on one of the domain controllers in that domain - then they show ...
    (microsoft.public.windows.server.active_directory)
  • Re: SBS 2003 and Replication Errors with Remote DC
    ... I just promoted the remote DC last week, so I still have time to solve the replication issues. ... Domain Controller Diagnosis ... Connecting to directory service on server alpha. ... Performing upstream analysis. ...
    (microsoft.public.windows.server.sbs)

Loading