Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Active Directory Replication failing with remote Domain Controller

Status
Not open for further replies.

Dublin73

IS-IT--Management
Apr 26, 2005
236
US
Hi, we have a domain controller in a remote office and two in our main office. Active Directory Replication will not take place ( even when forced ) between the domain controller in our remote office and the domain controllers in our main office.

SERVER31 <Remote office DC server
SERVER20 <Main office DC server which holds the 5 FSMO roles and is our one Global Catalog Server
SERVER3 <Main office DC server

DNS zones are Active Directory Integrated on all 3 domain controllers.

We have two AD Sites, NEWYORK1 <Main Office & NEWYORK2 <Remote Office

We have only one Active Directory domain.

dcdiag ran from SERVER31....

D:\>dcdiag

Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: NEWYORK2\SERVER31
Starting test: Connectivity
......................... SERVER31 passed test Connectivity

Doing primary tests

Testing server: NEWYORK2\SERVER31
Starting test: Replications
[Replications Check,SERVER31] A recent replication attempt failed:
From SERVER3 to SERVER31
Naming Context: CN=Schema,CN=Configuration,DC=ie,DC=national,DC=com
The replication generated an error (5):
Access is denied.
The failure occurred at 2006-01-24 10:52.04.
The last success occurred at 2005-09-21 15:22.18.
2006 failures have occurred since the last success.
[Replications Check,SERVER31] A recent replication attempt failed:
From SERVER20 to SERVER31
Naming Context: CN=Schema,CN=Configuration,DC=ie,DC=national,DC=com
The replication generated an error (1722):
The RPC server is unavailable.
The failure occurred at 2006-01-24 10:52.27.
The last success occurred at 2005-10-14 10:20.20.
1644 failures have occurred since the last success.
[SERVER20] DsBind() failed with error 1722,
The RPC server is unavailable..
The source remains down. Please check the machine.
[Replications Check,SERVER31] A recent replication attempt failed:
From SERVER3 to SERVER31
Naming Context: CN=Configuration,DC=ie,DC=national,DC=com
The replication generated an error (5):
Access is denied.
The failure occurred at 2006-01-24 10:51.41.
The last success occurred at 2005-09-21 15:22.18.
2006 failures have occurred since the last success.
[Replications Check,SERVER31] A recent replication attempt failed:
From SERVER20 to SERVER31
Naming Context: CN=Configuration,DC=ie,DC=national,DC=com
The replication generated an error (1722):
The RPC server is unavailable.
The failure occurred at 2006-01-24 10:52.04.
The last success occurred at 2005-10-14 10:20.20.
1644 failures have occurred since the last success.
The source remains down. Please check the machine.
[Replications Check,SERVER31] A recent replication attempt failed:
From SERVER3 to SERVER31
Naming Context: DC=ie,DC=national,DC=com
The replication generated an error (5):
Access is denied.
The failure occurred at 2006-01-24 10:51.18.
The last success occurred at 2005-09-21 15:22.18.
2007 failures have occurred since the last success.
[Replications Check,SERVER31] A recent replication attempt failed:
From SERVER20 to SERVER31
Naming Context: DC=ie,DC=national,DC=com
The replication generated an error (1722):
The RPC server is unavailable.
The failure occurred at 2006-01-24 10:51.41.
The last success occurred at 2005-10-14 10:19.57.
1644 failures have occurred since the last success.
The source remains down. Please check the machine.
......................... SERVER31 passed test Replications
Starting test: NCSecDesc
......................... SERVER31 passed test NCSecDesc
Starting test: NetLogons
......................... SERVER31 passed test NetLogons
Starting test: Advertising
......................... SERVER31 passed test Advertising
Starting test: KnowsOfRoleHolders
Warning: SERVER20 is the Schema Owner, but is not responding to DS RPC B
ind.
[SERVER20] LDAP connection failed with error 58,
The specified server cannot perform the requested operation..
Warning: SERVER20 is the Schema Owner, but is not responding to LDAP Bin
d.
Warning: SERVER20 is the Domain Owner, but is not responding to DS RPC B
ind.
Warning: SERVER20 is the Domain Owner, but is not responding to LDAP Bin
d.
Warning: SERVER20 is the PDC Owner, but is not responding to DS RPC Bind
.
Warning: SERVER20 is the PDC Owner, but is not responding to LDAP Bind.
Warning: SERVER20 is the Rid Owner, but is not responding to DS RPC Bind
.
Warning: SERVER20 is the Rid Owner, but is not responding to LDAP Bind.
Warning: SERVER20 is the Infrastructure Update Owner, but is not respond
ing to DS RPC Bind.
Warning: SERVER20 is the Infrastructure Update Owner, but is not respond
ing to LDAP Bind.
......................... SERVER31 failed test KnowsOfRoleHolders
Starting test: RidManager
[SERVER31] DsBindWithCred() failed with error -2146893022. The target pr
incipal name is incorrect.
......................... SERVER31 failed test RidManager
Starting test: MachineAccount
......................... SERVER31 passed test MachineAccount
Starting test: Services
......................... SERVER31 passed test Services
Starting test: ObjectsReplicated
......................... SERVER31 passed test ObjectsReplicated
Starting test: frssysvol
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
......................... SERVER31 passed test frssysvol
Starting test: kccevent
An Warning Event occured. EventID: 0x8000061E
Time Generated: 01/24/2006 16:03:59
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x8000061E
Time Generated: 01/24/2006 16:03:59
(Event String could not be retrieved)
An Error Event occured. EventID: 0xC000051F
Time Generated: 01/24/2006 16:03:59
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x8000061E
Time Generated: 01/24/2006 16:03:59
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x8000061E
Time Generated: 01/24/2006 16:03:59
(Event String could not be retrieved)
An Error Event occured. EventID: 0xC000051F
Time Generated: 01/24/2006 16:03:59
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x800004F1
Time Generated: 01/24/2006 16:04:22
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x800004F1
Time Generated: 01/24/2006 16:04:45
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x800004F1
Time Generated: 01/24/2006 16:05:08
(Event String could not be retrieved)
......................... SERVER31 failed test kccevent
Starting test: systemlog
......................... SERVER31 passed test systemlog

Running enterprise tests on : ie.national.com
Starting test: Intersite
......................... ie.national.com passed test Intersite
Starting test: FsmoCheck
Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355
A Global Catalog Server could not be located - All GC's are down.
Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355
A Primary Domain Controller could not be located.
The server holding the PDC role is down.
......................... ie.national.com failed test FsmoCheck

D:\>
============================================================

Any ideas there? How can I get SERVER31 to recognize SERVER20 as the Global Catalog Server and the holder of the five FSMO roles?

Any suggestions as to where to look next are much appreciated.

thanks in advance! Dublin73
 
Hi Dublin73,

Wish I could help, but we are currently having the same problem. With the same errors. We also can not do a NetView from the affected computer, and when we try to log on to the server the local server name isn't showing on the login window. Just the domain.

We have been working on this for a week and it's causing login issues with the users. So, I also join you in pleading for assistance.
 
Thanks for that!

I did try that, but it wasn't our solution. I've since tried the following and am getting closer....

resetting the domain controller's computer account....


From there I've been using a few of the Windows 2000 support tools, netdiag, dcdiag etc... and based on the errors generated, doing lots of research on Microsoft's website.

When I run dcdiag, all tests are passing with the exception of one...

D:\>dcdiag

Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: NEWYORK2\SERVER31
Starting test: Connectivity
......................... SERVER31 passed test Connectivity

Doing primary tests

Testing server: NEWYORK2\SERVER31
Starting test: Replications
......................... SERVER31 passed test Replications
Starting test: NCSecDesc
......................... SERVER31 passed test NCSecDesc
Starting test: NetLogons
......................... SERVER31 passed test NetLogons
Starting test: Advertising
......................... SERVER31 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... SERVER31 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... SERVER31 passed test RidManager
Starting test: MachineAccount
......................... SERVER31 passed test MachineAccount
Starting test: Services
......................... SERVER31 passed test Services
Starting test: ObjectsReplicated
......................... SERVER31 passed test ObjectsReplicated
Starting test: frssysvol
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
......................... SERVER31 passed test frssysvol
Starting test: kccevent
An Warning Event occured. EventID: 0x8000061E
Time Generated: 01/26/2006 15:49:45
(Event String could not be retrieved)
An Error Event occured. EventID: 0xC000051F
Time Generated: 01/26/2006 15:49:45
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x8000061E
Time Generated: 01/26/2006 15:49:45
(Event String could not be retrieved)
An Error Event occured. EventID: 0xC000051F
Time Generated: 01/26/2006 15:49:45
(Event String could not be retrieved)
......................... SERVER31 failed test kccevent
Starting test: systemlog
......................... SERVER31 passed test systemlog

Running enterprise tests on : ie.national.com
Starting test: Intersite
......................... ie.national.com passed test Intersite
Starting test: FsmoCheck
......................... ie.national.com passed test FsmoCheck

D:\>

so on I go! Will let you know what the final solution is.
 
Is there a firewall between the sites? Are you using a site to site VPN over the internet? You may not be allowing the needed traffic over the link.

Also... Check the SRV records on both sides. Make sure the GC references in DNS are right.

PSC

Governments and corporations need people like you and me. We are samurai. The keyboard cowboys. And all those other people out there who have no idea what's going on are the cattle. Mooo! --Mr. The Plague, from the movie "Hackers
 
Finally resolved this!

Configuration at our firewall was the 1st part of the resolution and Configuring a "Site Link Bridge" in Active Directoy Sites and Services was the second.

Tools that I found incredibly useful were...

dcdiag in verbose mode. The command is "dcdiag -v" without the apostrophes.

and "netdom"

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top