RE: Windows 2003 Replication failes from forest root to 2nd DNS tree.

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



1. An access denied error message generally is the result of
a) a broken secure channel between the DCs
b) Time Snych issues (there can be a max of 5 mins diff in system time by
defaault - kerberos). Make sure time is in synch
c) Security rights like "Access the computer from the network" does not have
"Enterprise Domain Controllers in the list"
d) "Deny access to this computer from the network"

e) if you try to access the failing DCs or vice versa ie (from failing DCs
access good DCs) by start - run - \\fdqn of the falining DCs - this should
probably fail too.

Its probably not "c" or "D" cause you can access by \\netbios name.

If the times are ok between the DCs and you resetting the secure channel
doesnt fix the issue... please run the following tool and email me the
generated reports.

[
http://www.microsoft.com/downloads/info.aspx?na=46&p=5&SrcDisplayLang=en&SrcCategoryId=&SrcFamilyId=cebf3c7c-7ca5-408f-88b7-f9c79b7306c0&genscs=&u=http%3a%2f%2fdownload.microsoft.com%2fdownload%2fb%2fb%2f1%2fbb139fcb-4aac-4fe5-a579-30b0bd915706%2fMPSRPT_DirSvc.EXE ]
.



Relevant Pages

  • RE: To disable SMB packet and secure channel signing enforcement on Windows Server 2003-based domain
    ... Secure Channel is used by domain member ... computers to pass user authentication information to DCs. ... To disable SMB packet and secure channel signing enforcement on ...
    (Focus-Microsoft)
  • Re: Kerberos errors after swapping domain controller IPs
    ... I'm not sure if Al agrees but, You can try to stop the KDC service on all ... the DCs and reset the secure channel on each DC using the netdom command. ... After resetting the secure channel password, you can reboot the server. ...
    (microsoft.public.windows.server.active_directory)
  • Re: One way replication
    ... Secure channel between the DCs ... Can you access the shares on 2003 dc from 2000 dc ... Under Default Domain Controller Security Policy - "Access this ...
    (microsoft.public.windows.server.active_directory)
  • Re: Remote site w/o VPN?
    ... DCs setup a secure channel for doing replication. ... The replication traffic is usally also compress between sites (but ... (phone on web site) ...
    (microsoft.public.win2000.active_directory)
  • Re: Two domains, One Forest....
    ... problem is that everything Microsoft insists on doing multiple network ... Placing DCs of both domain is both locations ... those machines now when there is heavy VPN traffic). ... > Correct - no leased lines T1 to internet VPN tunnel via internet. ...
    (microsoft.public.win2000.security)