Re: NTDS Inbound neighbos removal

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I would rerun the following, it appears you didn't run all tests when you
ran dcdiag

Run dcdiag, netdiag and repadmin in verbose mode.
-> DCDIAG /V /C /D /E /s:yourdcname > c:\dcdiag.log
-> netdiag.exe /v > c:\netdiag.log (On each dc)
-> repadmin.exe /showrepl dc* /verbose /all /intersite > c:\repl.txt
-> ntfrsutl ds your_dc_name > c:\sysvol.log
-> dnslint /ad /s "ip address of your dc"

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"Peter" <peterpao@xxxxxxx> wrote in message
news:u4EwUmS2JHA.4744@xxxxxxxxxxxxxxxxxxxxxxx
Hi Meioof

Will the following do help on troubleshooting ? But sorry for the sack of
security reason, I need to rename and change some of the IPs and
server/domain names.

Thanks
Peter


"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news:ff16fb662487f8cba74ca4530034@xxxxxxxxxxxxxxxxxxxxxxx
Hello Peter,

Please post an unedited dcdiag /v and netdiag /v from the last remaining
server.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hi Meinolf

First of all, thanks for your help.

Yes, basically I have checked everywhere from ADUC, AD SS and DNS and
nowhere shows this record. In fact, there is only 1 DC left with this
particular domain.

Regards,
Peter
"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news:ff16fb66248788cba7487033a294@xxxxxxxxxxxxxxxxxxxxxxx

Hello Peter,

So you have none entries from the old machine in AD UC, AD sites and
services and in DNS zones including the complete folder structures
down? It is also removed from the zone properties, Name servers tab?

Also check that all DC's have replicated the change's.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Hi all

One of our DCs were having hardware problem and failed to back up
running. I have followed the KB
http://support.microsoft.com/default.aspx/kb/216498 to remove any
related data on the Active Directory and everything seems working
perfectly except event ID 1085 were logged every 15 minutes.

----------------------
Event Type: Warning
Event Source: NTDS Replication
Event Category: (5)
Event ID: 1085
Date: 5/20/2009
Time: 1:41:43 PM
User: Everyone
Computer: DC01
Description:
Replication warning: The directory replication agent (DRA) couldn't
synchronize partition DC=Ourdomain,DC=domain,DC=com with partition
on
directory server
43f472ba-fdea-4b1f-947a-4bd25cabefc7._msdcs.Ourdomain.domain.com.
The error was:
The DSA operation is unable to proceed because of a DNS lookup
failure.
Please verify that the address can be resolved with DNS, and that it
is reachable via the transport. If this error persists, the KCC
will
reconfigure the links around this server.
----------------------

When I use the repadmin utility to check, I also noticed some
records are not being removed from the bridgehead as below

----------------------

C:\WINNT\NTDS>repadmin /showreps
Site1\DC01
DSA Options : IS_GC
objectGuid : 63e6526f-9353-44f6-92d0-c0aec8709372
invocationID: 63e6526f-9353-44f6-92d0-c0aec8709372
==== INBOUND NEIGHBORS ======================================
CN=Schema,CN=Configuration,DC=Ourdomain,DC=domain,DC=com
AX
DEL:12c7c3a7-ff61-42f9-8b9c-3d53346b0e23\FAILED-SERVER
DEL:c2c10c8c-6096-4990-9416-d4403c760f0d (deleted DSA) via RPC
objectGuid: 43f472ba-fdea-4b1f-947a-4bd25cabefc7
CN=Configuration,DC=Ourdomain,DC=domain,DC=com
AX
DEL:12c7c3a7-ff61-42f9-8b9c-3d53346b0e23\FAILED-SERVER
DEL:c2c10c8c-6096-4990-9416-d4403c760f0d (deleted DSA) via RPC
objectGuid: 43f472ba-fdea-4b1f-947a-4bd25cabefc7
DC=Ourdomain,DC=domain,DC=com
AX
DEL:12c7c3a7-ff61-42f9-8b9c-3d53346b0e23\FAILED-SERVER
DEL:c2c10c8c-6096-4990-9416-d4403c760f0d (deleted DSA) via RPC
objectGuid: 43f472ba-fdea-4b1f-947a-4bd25cabefc7
==== OUTBOUND NEIGHBORS FOR CHANGE NOTIFICATIONS ============
----------------------

From the above, "DC01" is the current bridgehead server where I
noticed the error in our prmary site while "FAILED-SERVER" is the
server that I have removed by following the KB's steps.
43f472ba-fdea-4b1f-947a-4bd25cabefc7 was also manually removed from
the DNS and I could not locate it anywhere anymore. (May be I don't
know how to search all)..

Hopefully someone can help me out to resolve the problem.

Thanks









.



Relevant Pages

  • Re: SBS 2003 and Replication Errors with Remote DC
    ... alpha server as soon as you can to get things going. ... A simple DNS replication test is to create a host record in the SBS server ... Domain Controller Diagnosis ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 and Replication Errors with Remote DC
    ... I did make the changes that you suggested on the DNS of my alpha server and rebooted. ... I did run the simple DNS test that you suggested by adding a host record to my SBS server. ... A simple DNS replication test is to create a host record in the SBS server and wait till it shows up in the remote server. ...
    (microsoft.public.windows.server.sbs)
  • Re: how do i move primary DC from one machine to another
    ... Test omitted by user request: DNS ... Connecting to directory service on server WIN2003DC. ... Replication Site Latency Check ...
    (microsoft.public.windows.server.general)
  • Re: error 8254 DNS Lookup failure
    ... FYI, I repointed the DNS to one server, deleted the contents of _MSDCS ... > in the same site, Replication has been fine up until yesterday, the ... > Starting test: CrossRefValidation ...
    (microsoft.public.win2000.dns)
  • Re: WINS and DNS issue
    ... When I said the that DNS server is configured to to replicate to all other ... Ive had a look at the options under replication, ... It says to set this if you want a 2000 server to load the zone. ...
    (microsoft.public.win2000.dns)