Big trouble with DC in China



Please help! Great wisdom is in need

We have a branch office in China - which is connected by a
firewall-to-firewall IPSec VPN. Our conection is not at all without packet
loss, by the way.

We have 2 other DCs in the states that support our main offices.

I just added a new DC/DNS/WINS server to support our branch office in China.
I have added a site with the subnet and configured links. Since then, this
server has so may errors in the event logs (KCC, DNS, FRS) that I wouldnt
know where to start. But Ill list a few anyway:

--------------------------------------------------------------------------------------
Event Type: Warning
Event Source: NTDS KCC
Event Category: Knowledge Consistency Checker
Event ID: 1925
Date: 11/10/2005
Time: 4:20:17 PM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: PORTLAND
Description:
The attempt to establish a replication link for the following writable
directory partition failed.

Directory partition:
CN=Configuration,DC=company,DC=com
Source domain controller:
CN=NTDS
Settings,CN=CHINA,CN=Servers,CN=China,CN=Sites,CN=Configuration,DC=company,DC=com
Source domain controller address:
22da5d1e-8271-4fcf-acb3-04d870397976._msdcs.dolan.corp
Intersite transport (if any):
CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=company,DC=com

This domain controller will be unable to replicate with the source domain
controller until this problem is corrected.

User Action
Verify if the source domain controller is accessible or network connectivity
is available.

Additional Data
Error value:
1727 The remote procedure call failed and did not execute.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

---------------------------------------------------------------------------
Event Type: Warning
Event Source: NTDS KCC
Event Category: Knowledge Consistency Checker
Event ID: 1925
Date: 11/10/2005
Time: 4:13:56 PM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: PORTLAND
Description:
The attempt to establish a replication link for the following writable
directory partition failed.

Directory partition:
CN=Schema,CN=Configuration,DC=company,DC=com
Source domain controller:
CN=NTDS
Settings,CN=CHINA,CN=Servers,CN=China,CN=Sites,CN=Configuration,DC=company,DC=com
Source domain controller address:
22da5d1e-8271-4fcf-acb3-04d870397976._msdcs.dolan.corp
Intersite transport (if any):
CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=company,DC=com

This domain controller will be unable to replicate with the source domain
controller until this problem is corrected.

User Action
Verify if the source domain controller is accessible or network connectivity
is available.

Additional Data
Error value:
1727 The remote procedure call failed and did not execute.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
-------------------------------------------------------------------------------------
Event Type: Warning
Event Source: DNS
Event Category: None
Event ID: 4510
Date: 11/9/2005
Time: 9:35:13 PM
User: N/A
Computer: CHINA
Description:
The DNS server was unable to connect to the domain naming FSMO
PORTLAND.company.com. No modifications to Directory Partitions are possible
until the FSMO server is available for LDAP connections. The event data
contains the error code.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: af 20 00 00 ¯ ..
Event Type: Warning
Event Source: DNS
Event Category: None
Event ID: 4510
Date: 11/9/2005
Time: 9:35:13 PM
User: N/A
Computer: CHINA
Description:
The DNS server was unable to connect to the domain naming FSMO
PORTLAND.company.com. No modifications to Directory Partitions are possible
until the FSMO server is available for LDAP connections. The event data
contains the error code.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: af 20 00 00 ¯ ..
----------------------------------------------------------------------
Event Type: Error
Event Source: DNS
Event Category: None
Event ID: 4016
Date: 11/9/2005
Time: 9:35:13 PM
User: N/A
Computer: CHINA
Description:
The DNS server timed out attempting an Active Directory service operation on
---. Check Active Directory to see that it is functioning properly. The
event data contains the error.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 55 00 00 00 U...
--------------------------------------------------------------------------------------

These errrors look so grimm that I am afraid to join our workstations over
there to the domain. Could this be due to our unreliable link and if so is
there nothing we can do to make this work? Please tell me it is possible I
could have misconfigured something along the way. This is my first time
preparing a DC overseas.
.



Relevant Pages

  • NTDS KCC Events occur after 5-7 days, DCs lose communication, Client Auto Enrollment Issues 1030
    ... Sites, one server each ... it did not fully replicate. ... following directory partition. ... There is insufficient site connectivity information in Active Directory ...
    (microsoft.public.windows.server.active_directory)
  • Add a new DC to a new branch
    ... so the connectivity and VPN tunnel is working fine. ... I installed Windows server 2003 on a new server, ... one or more domain controllers with this directory ... partition are unable to replicate the directory partition information. ...
    (microsoft.public.windows.server.active_directory)
  • No replication between DCs
    ... The domain consists of one SBS, above, box and Windows Server 2003, both ... directory partition failed. ... Source domain controller address: ...
    (microsoft.public.windows.server.sbs)
  • Re: replication issues: inbound / outbound replication disabled
    ... directory partition failed. ... Source domain controller address: ... 8457 The destination server is currently rejecting replication requests ...
    (microsoft.public.windows.server.active_directory)
  • Re: "Access Denied" message when adding member server in existing
    ... The server seems not having connectivity to the RID master. ... The File Replication Service SYSVOL ready test ... Source domain controller address: ... Running partition tests on: ForestDnsZones ...
    (microsoft.public.windows.server.active_directory)