Re: Event code confusions

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Ace Fekay [MVP] (PleaseSubstituteMyActualFirstName&LastNameHere_at_hotmail.com)
Date: 03/20/04


Date: Fri, 19 Mar 2004 19:58:51 -0500

In news:1038501c40dd1$c7eef9f0$a401280a@phx.gbl,
anonymous@discussions.microsoft.com <anonymous@discussions.microsoft.com>
posted their thoughts, then I offered mine
> Event Type: Error
> Event Source: NTDS KCC
> Event Category: (1)
> Event ID: 1311
> Date: 3/19/2004
> Time: 10:35:22 AM
> User: N/A
> Computer: DCLRAR1
> Description:
> The Directory Service consistency checker has determined
> that either (a) there is not enough physical connectivity
> published via the Active Directory Sites and Services
> Manager to create a spanning tree connecting all the sites
> containing the Partition
> CN=Configuration,DC=vestcom,DC=net, or (b) replication
> cannot be performed with one or more critical servers in
> order for changes to propagate across all sites (most
> often due to the servers being unreachable).
>
> For (a), please use the Active Directory Sites and
> Services Manager to do one of the following:
> 1. Publish sufficient site connectivity information such
> that the system can infer a route by which this Partition
> can reach this site. This option is preferred.
> 2. Add an ntdsConnection object to a Domain Controller
> that contains the Partition
> CN=Configuration,DC=vestcom,DC=net in this site from a
> Domain Controller that contains the same Partition in
> another site.
>
> For (b), please see previous events logged by the NTDS KCC
> source that identify the servers that could not be
> contacted.
>
> Are you just needing the addresses?

Things I would suggest to look for when these type of errors occur:

1. No MTU alterations in the router configs.

2. Firewalls without the proper rules.

3. Clock are not synched. Clocks must be synched within 5 minutes Zulu-
time.

4. If all the DCs are in one domain (vestcom.net), then I would make sure
that all the DNS servers have the same exact information on them. If you are
using an ISP's DNS address in any of the machines, that will definitely
cause this error as well. If so, eliminate them and only use your internal
servers.

-- 
Regards,
Ace
Please direct all replies to the newsgroup so all can benefit.
This posting is provided "AS-IS" with no warranties and confers no
rights.
Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory
-- 
=================================


Relevant Pages

  • 2 site and muliple problems
    ... The DSA operation is unable to proceed because of a DNS lookup failure. ... there is not enough physical connectivity published via the Active Directory ... all sites (most often due to the servers being unreachable). ... infer a route by which this Partition can reach this site. ...
    (microsoft.public.win2000.dns)
  • Migration of NT 4.0, DNS and NT 4.0 NTFS 7.8 GB partition
    ... I am in need of upgrading an NT 4.0 Domain. ... purchased that are to replace the current NT 4.0 servers. ... server and changed the partition size. ... Will this bypass Active Directory if I perform the upgrade for the other ...
    (microsoft.public.windows.server.migration)
  • Re: IMPACT of (Delegation Control of Group Policy) on Active Direc
    ... GPOs applied on DCs and Servers ... Health of active Directory and DCs since unSYSTEM Engineer is having ... Actually my MAIN CONCERN is that how would delegating control of Group ... Policy to SUPPORT Engineer affect health of active directory?? ...
    (microsoft.public.windows.server.active_directory)
  • RE: Need Advice (Repost)
    ... configuration there is no preference to the prod DCs over the DR DCs" Is ... if the DR servers are in a different AD site the users will be able to ... Active Directory Sites should be configured in this scenario. ... I've built two Active Directory Domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: EventID 4521 warning after SP2 upgrade
    ... I first verified that none of my DNS zones were being stored in the ... DomainDnsZones partition (other that "." ... the servers which hold this partition have had an opportunity to ... see the DomainDnsZones zone getting populated with information, ...
    (microsoft.public.windows.server.dns)