RE: AD replication across firewall

From: adc (adc_at_discussions.microsoft.com)
Date: 01/10/05


Date: Mon, 10 Jan 2005 07:47:01 -0800

hi danilo,

the replmon show replication is ok, but my policies folder under sysvol is
not synchronising. suspect its due to the access denied problem in event log,
or even dns problem.

i did the restart of netlogon service on all the DCs a few times but still
same

"Danilo Bordini [MVP]" wrote:

> Adc,
>
> You can use replmon.exe or repadmin.exe (Windows Support Tools - inside CD
> Windows 2000 installation) to verify if replication is working.
> Also, you need get _gc, _pdc srv records. You can stop and start again
> netlogon service on domain controller to "force" re-recreation of srv records.
>
> Danilo Bordini
>
> "adc" wrote:
>
> > hi,
> >
> > i hv a domain spanning across 2 sites, with firewalls at the boundaries of
> > both sites.
> > initially theres 1 DC each at each site, but bcos one of the DC is actually
> > doubling up as a apps server, hence i configured another DC on that site,
> > hoping to demote the original DC to become a member server.
> >
> > currently, i am using limited rpc method for AD replication across the
> > firewall for the DCs and hv configured the new added DC as the bridge head
> > server.
> >
> > however, i saw some error in the event logs stating some group policy access
> > denied error. i also discover the sysvol folder is not replicating correctly,
> > though replmon does show that replication is ok.
> >
> > question
> >
> > 1. how do i verify the the server logon shares (sysvol and netlogon) are
> > replicating correctly? if not how do i ensure the replication is successful?
> >
> > 2. how do i ensure if the GPO are replicated correctly?
> >
> > 3. is there a way to unshare the default sysvol folder and create a blank
> > copy for it to replicate?
> >
> > 4. in the _msdcs under DNS server, which are the entries required? currently
> > the new added server does not appear in the svr record. i did a telnet of
> > port 53 acoss the site and its ok.
> >



Relevant Pages

  • Re: Added 2nd AD box, but when take 1st down to test, cant auth us
    ... Verifying that the local machine SQLSERVER, ... The File Replication Service Event log test ... This event log message will appear once per connection, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Added 2nd AD box, but when take 1st down to test, cant auth us
    ... change the dns configuration to point to 10.88.87.2 as the ... Directory Server Diagnosis ... The File Replication Service Event log test ... This event log message will appear once per connection, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Server2003 2008 error !!
    ... Remove the x.x.1.x form the NIC of the DCs and configure it as a FORWARDER or use directly the ISPs DNS server as Forwarders in the DNS server properties in the DNS management console. ... On the 2008 make sure the internal firewall is not blocking AD replication, by default the firewall is enabled ion 2008. ... The event log File Replication Service on server ... EventID: 0x000003EE ...
    (microsoft.public.windows.server.active_directory)
  • Re: SBS 2003 and Replication Errors with Remote DC
    ... I just promoted the remote DC last week, so I still have time to solve the replication issues. ... Domain Controller Diagnosis ... Connecting to directory service on server alpha. ... Performing upstream analysis. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 and Replication Errors with Remote DC
    ... alpha server as soon as you can to get things going. ... A simple DNS replication test is to create a host record in the SBS server ... Domain Controller Diagnosis ...
    (microsoft.public.windows.server.sbs)

Loading