Re: Replication failure



Florian Schalk <FlorianSchalk@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
> Hi,
> we have a Windows 2000 domain.
> The domain has a 'root' server and domain namend xxx. The domain is a
> single labeled domain.
> We have also am.xxx, as.xxx and eu.xxx domains.
> All DCs are patched with the regkey from KB article 300684.
> Now we have AD replication problems. And it seems that the root of the
> problems are a DNS misconfiguration.
> The DNS zone xxx. on the root server is differnt from the one on eg.
> the eu.xxx DCs.
> The zone will not be replicated to the subdomains.
> I don't know what the formely admin has done here. I think he updated
> the zone on the subdomains by hand.
> All DCs in all subdomains have the root server as first DNS server in
> their network properties. Therefore all DCs will register correct to
> the DNS zone on the root server, but it will not be replicated.
>
> Any ideas what I can do?

Under Win2k, DNS replication does not extend past the domain NC partition.
What this means, zones on the root DC/DNS replicate only to DCs in the root
domain, not to any child domains.

You can resolve this by deleting the child subdomains on the root (xxx)
zone, then create delegations named am, as, and eu in the xxx zone, make
these delegations to their respective child DNS servers. Then on all the
child DNS servers forward to the xxx DNS server and check the box "Do not
use recursion" on the child forwarder tab.
An alternate to forwarding the child DNS servers to the root DNS server is
to create a secondary of the xxx (root) zone on all child DNS servers. This
makes all DNS server in all domains capable of resolving all child domains
in addtion to the root domain.


If this were Win2k3 and all DCs were Win2k3, you would set the root domain
zone to replicate to all DNS servers in the forest. But, under Wink2 your
options are limited to my recommendations.


--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================


.



Relevant Pages

  • Re: Simple DNS For Private LAN -- SOLVED
    ... I used your examples and the "view" statement mentioned my Mathew Seaman to build a BIND 9 DNS server that is authoritative for mykitchentable.net. ... a local "master zone" visible only to my private LAN as you describe ... internal home network. ... which points to the root DNS servers. ...
    (freebsd-questions)
  • Re: speed netstat <-> nslookup
    ... the recommendation is to create a Root zone under ... will not answer for anything other than what is created on your server. ... your proxy is assumed to use a DNS server that is forwarding out. ...
    (microsoft.public.windows.server.dns)
  • Re: Forward lookup zone not automatically created for new domain i
    ... I updated the 'Preferred DNS server' on shell.company to ... Did you remove the other DNS servers? ... This looks like you already had replication errors (at least ... No forward lookup zone appeared. ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS Restart to Access Internet
    ... Secondary AD Integrated DNS server. ... Integrated zone, it can be one or the other but not both ADI and Secondary. ... Best Practice would be for both to be DCs, Global Catalogs, and have AD ... DNS servers you list here are not used by Exchange for any other purposes ...
    (microsoft.public.windows.server.dns)
  • Re: zone transfer fails
    ... > and a secondary server. ... We have been experiencing problems with zone ... Are these two DNS servers Win2000 AD domain controllers in the same domain? ...
    (microsoft.public.win2000.dns)