RE: AD replication issue



Hi Chris,

If you are using AD Integrated DNS, I would expect these changes to
replicate almost immediately. If you are not using AD Integrated, you should
ask yourself why not. Unless you have a well-defined answer, this should
generally be done.

I would make sure that the servers are able to ping the domain by FQDN, not
just by name. This would result in the SRV records being hit and generally
the PDCe will be returned. If this is not working, you will want to look at
the search scopes and the DNS servers that might be in there as forwarders.

Finally, you can go through the DNS manually to look for the SRV records
that should be there and to ensure that zone transfers are appropriately
configured. You might also want to run diagnostics with REPLMON, DCDIAG, and
NETDIAG to get more information.

Let us know and we'll be there to help!
--
Ryan Hanisco
MCSE, MCTS: SQL 2005, Project+
http://www.techsterity.com
Chicago, IL

Remember: Marking helpful answers helps everyone find the info they need
quickly.


"Chris Meehan" wrote:

So the situation is this....

in a remote site a new domain controller was installed and promoted. The
existing server at that location was demoted after intrasite replication took
place. For the sake of questioning the new domain controller will be called
DC2 and the old will be called DC1.

Problem is this...

On the new domain controller (DC2) at the remote site, everything looks good.

New server shows up in Domain Controllers OU, all DNS records registered
correctly, including CNAME. Old server shows as member server in the
computers OU.

On every other domain controller in the domain, It still looks as if nothing
had taken place as far as demoting and promoting. In the Domain Controllers
OU the old server (DC1) still shows.

The problem is with replication.. Inbound replication to the new DC2 server
at the remote site is working fine, however replication from the remote
domain controller inbound to servers at the hub site will not work.

I have verified all DNS test via dcdiag and tried using the repadmin /add
command to add an inbound connection object using GUIDS but get an error
stating,
"The DSA operation is unable to proceed because of a DNS lookup failure"
Error 8524.

I can ping both ways via host name, and nslookup from the server that I am
running the repadmin /add command from shows the correct ip. Kinda at a loss
here with this one and would like to try to prevent having to demote then
repromote the domain controller again. Any suggestions? thanks in advance.

Chris

.



Relevant Pages

  • Re: SBS 2003 and Replication Errors with Remote DC
    ... I did make the changes that you suggested on the DNS of my alpha server and rebooted. ... I did run the simple DNS test that you suggested by adding a host record to my SBS server. ... A simple DNS replication test is to create a host record in the SBS server and wait till it shows up in the remote server. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 and Replication Errors with Remote DC
    ... I just promoted the remote DC last week, so I still have time to solve the replication issues. ... Domain Controller Diagnosis ... Connecting to directory service on server alpha. ... Performing upstream analysis. ...
    (microsoft.public.windows.server.sbs)
  • Re: multiple errors in Active Directory
    ... They are external DNS servers and do not know about my Active Directory. ... A recent replication attempt failed when running DCDIAG. ... SHS2003 Server is the Schema owner, Domain owner, pdc, rid, ... If this computer is a domain controller for the specified domain, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Thoroughly confused SBS 2003 Server
    ... fact I first had SBS running on the box that now has the Server Enterprise ... A year ago or moe I put up the second server and made it a domain controller ... The replication generated an error: ...
    (microsoft.public.windows.server.sbs)
  • getting event 2088 after unresponsive system
    ... Active Directory could not use DNS to resolve the IP address of the source ... computer name of the source domain controller. ... Alternate server name: ... If this DNS server's Active Directory replication partners do not have the ...
    (microsoft.public.windows.server.dns)