Re: Replication Headache - Urgent please Assist!



Since your at this point in the process I have to ask is there any
particular reason you created a child domain and not added the remote office
as a site on your existing domain?

Creating a child domain creates more admin overhead. Setting password
policies in 2 places, users traveling from one office to the
other........could get messy.

hth
DDS

"Taz1972" <Taz1972@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4936883D-FE52-42E2-9DAA-BBF7F7104C97@xxxxxxxxxxxxxxxx
Hi,

I recently added a subdomain in another site which will be on it's own
subnet with initially a few people on it and currently just one server
acting
as a DC.

I have configured everything in the following manner:

1.Manually created a delegation for the child domain on our root server
DNS
server which resides on 172.x.x.x
2.Installed DNS on the child domain server
3.Created a child zone on the child domain server
4.Enabled dynamic updates
5.Promoted the child domain server using dcpromo
6.On the TCP/IP properties of the child domain server, changed the TCP/IP
address of the DNS server to point to its own TCP/IP address.
7.Integrating DNS with the Active Directory on the child DNS server.
8.Added the parent (root) DNS server as a forwarder on the child DNS
server.
9.I also created secondary zones on each DNS server to point to each
other.
10.Configured a site connection from Wallingford to Leidschendam using IP
and linked the appropriate subdomain subnet 192.168.x.x to this site.

But when replication is attempted it gives me the error RPC Server in not
available.

I can ping the child DC by IP but not hostname, but I can do both when I
attempt to ping the other way round to the root DNS server on the root
domain
.local. It looks to be a DNS resolution issue but it's kind of strange as
zone transfers do seem to be working.


Attached is a dcdiag report which may be of some help.

<site> = new subdomain
<server>= new subdomain DC
<domain>= the root domain .local
DC= the root dns server on the root domain
DC2, 3,4 etc= other DC's in other locations.

Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: <site>\<server>
Starting test: Connectivity
......................... <server> passed test Connectivity

Doing primary tests

Testing server: <site>\<server>
Starting test: Replications
[Replications Check,<server>] A recent replication attempt failed:
From MAIL to FJBVDC1
Naming Context: DC=ForestDnsZones,DC=<domain>,DC=local
The replication generated an error (1256):
The remote system is not available. For information about
network tr
oubleshooting, see Windows Help.
The failure occurred at 2008-12-23 10:46:38.
The last success occurred at 2008-12-22 15:45:44.
7 failures have occurred since the last success.
[Replications Check,<server>] A recent replication attempt failed:
From MAIL to <server>
Naming Context:
CN=Schema,CN=Configuration,DC=fugro-jason,DC=local
The replication generated an error (8524):
The DSA operation is unable to proceed because of a DNS lookup
failu
re.
The failure occurred at 2008-12-23 07:47:34.
The last success occurred at 2008-12-22 15:45:43.
6 failures have occurred since the last success.
The guid-based DNS name
1e5fb0dc-5d86-4467-9d43-055d890145f2._msdcs.
fugro-jason.local
is not registered on one or more DNS servers.
[Replications Check,<server>] A recent replication attempt failed:
From DC to <server>
Naming Context: CN=Configuration,DC=<domain>,DC=local
The replication generated an error (8524):
The DSA operation is unable to proceed because of a DNS lookup
failu
re.
The failure occurred at 2008-12-23 10:46:38.
The last success occurred at 2008-12-22 15:56:47.
10 failures have occurred since the last success.
The guid-based DNS name
1e5fb0dc-5d86-4467-9d43-055d890145f2._msdcs.
fugro-jason.local
is not registered on one or more DNS servers.
REPLICATION-RECEIVED LATENCY WARNING
<server>: Current time is 2008-12-23 16:00:19.
DC=ForestDnsZones,DC=fugro-jason,DC=local
Last replication recieved from <server> at 2008-12-22
15:20:01.

Last replication recieved from DC at 2008-12-22 15:45:44.
Last replication recieved from DC2 at 2008-12-22 15:29:38.
Last replication recieved from DC3 at 2008-12-22 15:19:50.
Last replication recieved from DC4 at 2008-12-22 15:44:37.
CN=Schema,CN=Configuration,DC=<domain>,DC=local
Last replication recieved from DC01 at 2008-12-22 15:20:01.

Last replication recieved from DC at 2008-12-22 15:45:43.
Last replication recieved from DC2 at 2008-12-22 15:45:44.
Last replication recieved from DC3 at 2008-12-22 15:44:36.
Last replication recieved from DC4 at 2008-12-22 15:29:37.
Last replication recieved from DC5 at 2008-12-22 15:19:50.
Last replication recieved from DC6 at 2008-12-22 15:44:36.
CN=Configuration,DC=<domain>,DC=local
Last replication recieved from DC01 at 2008-12-22 15:19:57.

Last replication recieved from DC at 2008-12-22 15:56:47.
Last replication recieved from DC2 at 2008-12-22 15:58:25.
Last replication recieved from DC3 at 2008-12-22 15:44:32.
Last replication recieved from DC4 at 2008-12-22 15:29:32.
Last replication recieved from DC5 at 2008-12-22 15:20:23.
Last replication recieved from DC6 at 2008-12-22 15:44:34.
......................... <server> passed test Replications
Starting test: NCSecDesc
......................... <server> passed test NCSecDesc
Starting test: NetLogons
* You must make sure there are no existing net use connections,
you can use "net use /d \\<server>\ipc$" or "net use /d
\\<machine-name>\<share-name>"
......................... <server> failed test NetLogons
Starting test: Advertising
......................... <server> passed test Advertising
Starting test: KnowsOfRoleHolders
......................... <server> passed test KnowsOfRoleHolders
Starting test: RidManager
......................... <server> passed test RidManager
Starting test: MachineAccount
Could not open pipe with [<server>]:failed with 1219: Multiple
connectio
ns to a server or shared resource by the same user, using more than one
user
nam
e, are not allowed. Disconnect all previous connections to the server or
shared
resource and try again.
Could not get NetBIOSDomainName
Failed can not test for HOST SPN
Failed can not test for HOST SPN
* Missing SPN :(null)
* Missing SPN :(null)
......................... <server> failed test MachineAccount
Starting test: Services
Could not open Remote ipc to [<server>]:failed with 1219: Multiple
conne
ctions to a server or shared resource by the same user, using more than
one
user
name, are not allowed. Disconnect all previous connections to the server
or
sha
red resource and try again.
......................... <server> failed test Services
Starting test: ObjectsReplicated
......................... <server> passed test ObjectsReplicated
Starting test: frssysvol
* You must make sure there are no existing net use connections,
you can use "net use /d \\<server>\ipc$" or "net use /d
\\<machine-name>\<share-name>"
......................... <server> failed test frssysvol
Starting test: frsevent
......................... <server> failed test frsevent
Starting test: kccevent
Failed to enumerate event log records, error Multiple connections
to a
server or shared resource by the same user, using more than one user name,
are n
ot allowed. Disconnect all previous connections to the server or shared
resource
and try again.
......................... <server> failed test kccevent
Starting test: systemlog
Failed to enumerate event log records, error Multiple connections
to a
server or shared resource by the same user, using more than one user name,
are n
ot allowed. Disconnect all previous connections to the server or shared
resource
and try again.
......................... <server> failed test systemlog
Starting test: VerifyReferences
......................... <server> passed test VerifyReferences

Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation

Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom

Running partition tests on : <site>
Starting test: CrossRefValidation
......................... <site> passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... <site> passed test CheckSDRefDom

Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation

Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom

Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom

Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom

Running enterprise tests on : <domain.local>
Starting test: Intersite
......................... <domain.local> passed test Intersite
Starting test: FsmoCheck
......................... <domain.local> passed test FsmoCheck

Any pointers you can provide in order to solve this issue will be greatly
appreciated.

Thanks in advance,
Taz



.



Relevant Pages

  • Re: Unable to Raise Domain Functional Level
    ... that directory replication is healthy on multiple test passes. ... Should I check the remaining child domain and root domain to ... The server that DCDiag complains about is CNR-PR-DOMA00 ... are indicating the servers are receiving their DNS settings via DHCP. ...
    (microsoft.public.windows.server.migration)
  • Re: DC of the Parent Domain cant Ping the hostname of the DC Chil
    ... I didn't know we still have to setup WINS between Parent - Child domains. ... name not a dns name, so pinging a FQDN that works tells me that your dns is ... sake of argument" also acting as File Server in head office with all ... The Parent, host1, knows about the child domain and its DC in the DNS ...
    (microsoft.public.windows.server.active_directory)
  • Re: Error: cant find _ldap._tcp.dc._msdc.
    ... domain over a VPN? ... The DNS server name as listed in the DNS manager is cda.cdaxxxx.org.uk ... VPN connection to the top of the connections list. ...
    (microsoft.public.windows.server.dns)
  • RE: Changing from DCHP to static IP address
    ... You configure your Internet connections ... Best of Luck with your server. ... On your OUTSIDE (Internet) adapter, you should have the following configured: ... You also need to add the ISP's DNS addresses ...
    (microsoft.public.windows.server.sbs)
  • Re: Userreplikation
    ... PASS - All the DNS entries for DC are registered on DNS server ... List of NetBt transports currently bound to the Redir ... No active remote access connections. ...
    (microsoft.public.de.german.win2000.active_directory)

Loading