Re: replication failed access denied



Run diagnostics against your Active Directory domain.

If you don't have the support tools installed, install them from your server
install disk.
d:\support\tools\setup.exe

Run dcdiag, netdiag and repadmin in verbose mode.
-> DCDIAG /V /C /D /E /s:yourdcname > c:\dcdiag.log
-> repadmin.exe /showrepl dc* /verbose /all /intersite > c:\repl.txt
-> dnslint /ad /s "ip address of your dc"

**Note: Using the /E switch in dcdiag will run diagnostics against ALL dc's
in the forest. If you have significant numbers of DC's this test could
generate significant detail and take a long time. You also want to take
into account slow links to dc's will also add to the testing time.

If you download a gui script I wrote it should be simple to set and run
(DCDiag and NetDiag). It also has the option to run individual tests
without having to learn all the switch options. The details will be output
in notepad text files that pop up automagically.

The script is located on my website at
http://www.pbbergs.com/windows/downloads.htm

Just select both dcdiag and netdiag make sure verbose is set. (Leave the
default settings for dcdiag as set when selected)

When complete search for fail, error and warning messages.

Description and download for dnslint
http://support.microsoft.com/kb/321045


--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"blink" <blink@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:31539977-6B38-49F9-BFB7-E0E937480D97@xxxxxxxxxxxxxxxx
Hi all,
2003 AD Domain functional level running windows server 2003 and the Forest
Level is running at 2000.
I am trying to setup my second domain controller, went through the wizard
and I am able to logon to the domain on the second controller. I am also
always logging in as the domain admin. I am able to open and make changes
to
the AD User and Computers Console. When I run replmon from the secondary
DC
and try to sync with the PDC I keep getting the following error: There was
an
error during queuing the synchronization. The error code was:
ERROR_REPLICA_SYNC_FAILED_ACCESS IS DENIED.
I am logged in as the DC admin even set as the Enterprise Admin also. I
ran
the same procedure on the PDC and get the same error.
I will post netdiag in another post.
Thanks in advance.


.



Relevant Pages

  • Re: DCPROMO /Forceremoval task
    ... If you don't have the support tools installed, install them from your server ... Run dcdiag, netdiag and repadmin in verbose mode. ...
    (microsoft.public.windows.server.active_directory)
  • Re: KCC event ID 1567
    ... If you don't have the support tools installed, install them from your server ... Run dcdiag, netdiag and repadmin in verbose mode. ...
    (microsoft.public.win2000.active_directory)
  • Re: ACTIVE DIRECTORY NOT WORKING AFTER INSATLLING ISA SERVER 2006 SP1
    ... If you don't have the support tools installed, install them from your server install disk. ... Run dcdiag, netdiag and repadmin in verbose mode. ... If you download a gui script I wrote it should be simple to set and run (DCDiag and NetDiag). ...
    (microsoft.public.windows.server.active_directory)
  • Re: Error while trying to upgrade a Windows 2000 Server domain
    ... If you don't have the support tools installed, install them from your server install disk. ... Run dcdiag, netdiag and repadmin in verbose mode. ... The Windows 2000 DC has Windows Services for Unix v3.0 installed, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Two DCs - one seemingly not functioning properly
    ... If you don't have the tools installed, install them from your server install ... Run dcdiag, netdiag and repadmin in verbose mode. ...
    (microsoft.public.win2000.active_directory)