Re: Secondary domain controller can not talk to SBS server




Hi Fistcar,

Thank you for posting here.

From your post, I understand that your SBS server was backed up with
Acronis True Image, then, it was restored to a new machine. After that,
replication problem was encountered when replicating from remote-dc to
sbs-server.

Firstly, I would like to explain that to backup and restore SBS server, we
need to follow the steps in the following article. We don't recommend using
third party programs to backup and restore the SBS server.

Backing Up and Restoring Windows Small Business Server 2003
http://go.microsoft.com/fwlink/?LinkId=49916

If you would like to migrate SBS server to new hardware, please refer to
this article. Restoring the server to new hardware is not supported.

Migrating Windows Small Business Server 2003 to New Hardware
http://technet2.microsoft.com/WindowsServerSolutions/SBS/en/library/62e2094e
-ad4e-4227-b20e-97a716ed7c861033.mspx?mfr=true


Based on the current situation, we cannot simple restore the backup.
Instead, we can install the SBS into the existing domain to have the AD
information replicated back since the AD information will retain in the
additional AD controller.

Note: You may need to manually remove the information about the original
SBS server in the AD before the installation. (Also need to remove the
Exchange information from the AD). In addition, you also need to seize all
FSMO roles from the additional DC.

Using Ntdsutil.exe to transfer or seize FSMO roles to a domain controller
http://support.microsoft.com/kb/255504/en-us

How to install Small Business Server 2003 in an existing Active Directory
domain
http://support.microsoft.com/default.aspx?scid=kb;en-us;884453

How to remove Exchange Server 2003 from your computer
http://support.microsoft.com/kb/833396


Since this could be extremely complex, and our troubleshooting on SBS
public newsgroup will be time-consuming, so if you would like to call CSS
for assistance, I think it is a more effective way. To obtain the phone
numbers for specific technology request please take a look at the web site
listed below.

http://support.microsoft.com/default.aspx?scid=fh;EN-US;PHONENUMBERS

If you are outside the US please see http://support.microsoft.com for
regional support phone numbers.


Based on my research and experience, I also included some suggestions on
this issue.

Suggestion 1: Install the latest Service Pack and updates

Suggestion 2: Rerun CEICW to reset all configurations

How to configure Internet access in Windows Small Business Server 2003
http://support.microsoft.com/kb/825763/en-us

Suggestion 3: Verify Network connectivity between SBS-server and remote DC
(Ping FQDN and IP address from each other)

Suggestion 4: Run NTDSUTIL METADATA CLEANUP on the remote DC to remove
metadata of any DC that is no longer functional. Please refer KB216498:

How to remove data in Active Directory after an unsuccessful domain
controller demotion
http://support.microsoft.com/kb/216498


Suggestion 5: Add the following registry key on both DCs
==============
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters
Value Name: Allow Replication With Divergent and Corrupt Partner
Value Type: REG_DWORD
Value Data: 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters
Value Name: Replicator Allow SPN Fallback
Value Type: REG_DWORD
Value Data: 1

After that, force replication again from SBS server.


Other related KB:

Active Directory replication delayed when indexed attributes rebuilt during
schema upgrade
http://support.microsoft.com/kb/307323

Replication of the Partial Attribute Set on a Global Catalog Server Does
Not Complete
http://support.microsoft.com/kb/825782


Hope the above information helps, please feel free to let me know if you
have anything unclear.

Best regards,

Shawn Shao
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security

======================================================
PLEASE NOTE: The partner managed newsgroups are provided to assist with
break/fix issues and simple how to questions.

We also love to hear your product feedback!
Let us know what you think by posting
from the web interface: Partner Feedback
from your newsreader:
microsoft.private.directaccess.partnerfeedback.
We look forward to hearing from you!
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
======================================================

.



Relevant Pages

  • Re: AD does not start
    ... member server ... "Directory Services Restore Mode (Windows 2000 domain controllers only)" ... Master Operation roles (FSMO and the File Replication service). ...
    (microsoft.public.windows.server.active_directory)
  • Re: Disaster Recovery Site Restoring AD
    ... or where I can restore an up to date AD backup. ... We are not going to be able to setup a replication to the ... We have rebuilt a new server off our domain with similar specs. ... We restored the entire backup of the main domain controller to the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Disaster Recovery Site Restoring AD
    ... or where I can restore an up to date AD backup. ... We are not going to be able to setup a replication to the ... We have rebuilt a new server off our domain with similar specs. ... We restored the entire backup of the main domain controller to the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active Directory CRASHED!! But why??
    ... that NDS has really suffered in the past few ... > restore them from some kind of backup. ... > it will hold out until i can get in there with a new server and replicate ... But will the errors come over in the replication? ...
    (microsoft.public.win2000.active_directory)
  • Re: SBS2003 + tombstoned WIN2K DC
    ... Last replication recieved from WIN2K at 2006-10-22 ... First you'll need to demote the 2nd DC (NOT the SBS server), ... computer shows up in the SBS server. ... I'm worried that if I remove the AD from WIN2K then everything will ...
    (microsoft.public.windows.server.sbs)