AD Replication Issue
Hello,
I am writing to you because I have an AD replication problem.
I have 2 DCs 2008r2 on VMs on HyperV hosts 2012.
It turns out that today, when trying to add a new machine to the domain, I realized that the two DCs have not been replicated for 2 months!
I tried to force the replication by running repadmin /replicate
or repadmin /syncall
but it does not work. I get an error message saying:
LDAP error 81: Server is offline.
I have followed several leads, and I finally concluded that it was a USN Rollback issue since the DSA not writing = 4
The recommended solution for this problem is to demote the problematic DC (DC1) and then repromote it.
However, DC1 holds all the FSMO roles, and when I try to transfer the roles, I am told that it cannot contact the server...
So on one hand, if I turn off DC2, people can no longer connect to the servers; the message indicates a domain trust issue.
If I turn off DC1, I end up with a DC in the FSMO role...
I'm a bit short on solutions here... :s
Do you have any advice for me?
Thank you in advance for your help :)
Configuration: Windows / Chrome 56.0.2924.87
I am writing to you because I have an AD replication problem.
I have 2 DCs 2008r2 on VMs on HyperV hosts 2012.
It turns out that today, when trying to add a new machine to the domain, I realized that the two DCs have not been replicated for 2 months!
I tried to force the replication by running repadmin /replicate
or repadmin /syncall
but it does not work. I get an error message saying:
LDAP error 81: Server is offline.
I have followed several leads, and I finally concluded that it was a USN Rollback issue since the DSA not writing = 4
The recommended solution for this problem is to demote the problematic DC (DC1) and then repromote it.
However, DC1 holds all the FSMO roles, and when I try to transfer the roles, I am told that it cannot contact the server...
So on one hand, if I turn off DC2, people can no longer connect to the servers; the message indicates a domain trust issue.
If I turn off DC1, I end up with a DC in the FSMO role...
I'm a bit short on solutions here... :s
Do you have any advice for me?
Thank you in advance for your help :)
Configuration: Windows / Chrome 56.0.2924.87
2 answers
-
Hello,
thank you for your reply,
I was able to make some progress on the subject, I managed to take all the fmso roles on DC2.
However, it's impossible to add a new PC to the domain when DC1 is not connected to the network...
it shows me "the target account name is incorrect"
Do you have any idea what might be blocking the domain join?-
ContributorIt's a DNS resolution error. What is the DNS server? Dc1 or dc2 or both?
Check the DNS on dc2. Check the DNS records.
Dc2 is indeed a global catalog...
You can look at this https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc753187(v=ws.11)?redirectedfrom=MSDN -
@bendropBoth are DNS servers,
each DC indicates its own IP as the primary DNS and that of the other as the secondary DNS.
I have verified that both DCs are global catalogs.
For now, I have disconnected DC1, and no one has reported any issues connecting to their workstation this morning.
There remains this issue of adding workstations to the domain, and then I could definitively demote DC1.
If I disconnect DC2, people can no longer log into their workstations, but the domain join works.
I can't bring myself to delete one of the two DCs under these conditions; is there a way to reconcile the two DCs? -
-
@bendropDirectory server diagnostic
Initial installation execution:
Attempting to find associated server...
Associated server: DC2 AD forest identified.
[DC1] The LDAP binding failed with error 8341,
An directory service error occurred..
Error obtained while checking if the domain controller is using
FRS or DFSR. Error: An directory service error occurred. It
may be that the VerifyReferences, FrsEvent and DfsrEvent tests fail due to this error.
Initial information gathering finished.
Executing necessary initial tests
Server test: ROSNY\DC1
Starting test: Connectivity
Error obtained while checking LDAP and RPC connectivity.
Check firewall settings.
......................... The Connectivity test
of DC1 failed
Server test: ROSNY\DC2
Starting test: Connectivity
......................... The Connectivity test
of DC2 succeeded
Executing main tests
Server test: ROSNY\DC1
Tests skipped as server DC1 is not responding to
directory service requests.
Server test: ROSNY\DC2
Starting test: Advertising
......................... The Advertising test
of DC2 succeeded
Starting test: FrsEvent
......................... The FrsEvent test
of DC2 succeeded
Starting test: DFSREvent
Errors or warnings detected in the last 24 hours
after SYSVOL share. Problems related to SYSVOL replication failure can cause Group Policy issues.
......................... The DFSREvent test
of DC2 failed
Starting test: SysVolCheck
......................... The SysVolCheck test
of DC2 succeeded
Starting test: KccEvent
......................... The KccEvent test
of DC2 succeeded
Starting test: KnowsOfRoleHolders
......................... The KnowsOfRoleHolders test
of DC2 succeeded
Starting test: MachineAccount
......................... The MachineAccount test
of DC2 succeeded
Starting test: NCSecDesc
......................... The NCSecDesc test
of DC2 succeeded
Starting test: NetLogons
......................... The NetLogons test
of DC2 succeeded
Starting test: ObjectsReplicated
......................... The ObjectsReplicated test
of DC2 succeeded
Starting test: Replications
[Replications Check,DC2] A recent replication attempt failed:
From DC1 to DC2
Naming context: DC=ForestDnsZones,DC=domain,DC=local
The replication generated an error (1256):
The remote system is unavailable. For troubleshooting network information, consult Windows Help.
The failure occurred at 2017-02-21 11:54:48.
The last success occurred at 2016-12-15 17:07:24.
6496 failures occurred since the last success.
[Replications Check,DC2] A recent replication attempt failed:
From DC1 to DC2
Naming context: DC=DomainDnsZones,DC=domain,DC=local
The replication generated an error (1256):
The remote system is unavailable. For troubleshooting network information, consult Windows Help.
The failure occurred at 2017-02-21 11:54:48.
The last success occurred at 2016-12-15 17:07:24.
10976 failures occurred since the last success.
[Replications Check,DC2] A recent replication attempt failed:
From DC1 to DC2
Naming context: CN=Schema,CN=Configuration,DC=domain,DC=local
The replication generated an error (1722):
The RPC server is unavailable.
The failure occurred at 2017-02-21 11:55:30.
The last success occurred at 2016-12-15 17:07:24.
6496 failures occurred since the last success.
The source remains stopped. Check the computer.
[Replications Check,DC2] A recent replication attempt failed:
From DC1 to DC2
Naming context: CN=Configuration,DC=domain,DC=local
The replication generated an error (1722):
The RPC server is unavailable.
The failure occurred at 2017-02-21 11:55:09.
The last success occurred at 2017-02-20 16:28:31.
79 failures occurred since the last success.
The source remains stopped. Check the computer.
[Replications Check,DC2] A recent replication attempt failed:
From DC1 to DC2
Naming context: DC=domain,DC=local
The replication generated an error (1722):
The RPC server is unavailable.
The failure occurred at 2017-02-21 11:54:48.
The last success occurred at 2016-12-15 17:08:16.
28532 failures occurred since the last success.
The source remains stopped. Check the computer.
......................... The Replications test
of DC2 failed
Starting test: RidManager
......................... The RidManager test
of DC2 succeeded
Starting test: Services
......................... The Services test
of DC2 succeeded
Starting test: SystemLog
An error event occurred. Event ID: 0x40000004
Time generated: 02/21/2017 11:09:06
Event chain:
The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server DC2$. The target name used was GC/DC2.domain.local/domain.local@domain.local. This indicates that the target server failed to decrypt the ticket provided by the client. This may occur when the server's Service Principal Name (SPN) is registered on a different account than the one used by the target service. Please ensure that the SPN is registered on, and only on, the account used by the server. This error may also occur when the target service uses a password for the target service account that differs from that held by the Kerberos Key Distribution Center for the target service account. Please ensure that the service on the server and the Kerberos Key Distribution Center are both updated to use the current password. If the server name is not fully qualified, and the target domain (domain.local) differs from the client domain (domain.local), check if there are server accounts with the same name in both domains, or use the fully qualified name to identify the server.
An error event occurred. Event ID: 0x000003EE
Time generated: 02/21/2017 11:10:14
Event chain:
Group Policy processing failed. Windows could not authenticate to the Active Directory service of a domain controller. (LDAP binding function call failed). Refer to the details tab for more information on the error code and description.
An error event occurred. Event ID: 0x40000004
Time generated: 02/21/2017 11:12:24
Event chain:
The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server DC2$. The target name used was ldap/DC2.domain.local. This indicates that the target server failed to decrypt the ticket provided by the client. This may occur when the server's Service Principal Name (SPN) is registered on a different account than the one used by the target service. Please ensure that the SPN is registered on, and only on, the account used by the server. This error may also occur when the target service uses a password for the target service account that differs from that held by the Kerberos Key Distribution Center for the target service account. Please ensure that the service on the server and the Kerberos Key Distribution Center are both updated to use the current password. If the server name is not fully qualified, and the target domain (domain.local) differs from the client domain (domain.local), check if there are server accounts with the same name in both domains, or use the fully qualified name to identify the server.
An error event occurred. Event ID: 0x40000004
Time generated: 02/21/2017 11:13:24
Event chain:
The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server DC2$. The target name used was LDAP/DC2. This indicates that the target server failed to decrypt the ticket provided by the client. This may occur when the server's Service Principal Name (SPN) is registered on a different account than the one used by the target service. Please ensure that the SPN is registered on, and only on, the account used by the server. This error may also occur when the target service uses a password for the target service account that differs from that held by the Kerberos Key Distribution Center for the target service account. Please ensure that the service on the server and the Kerberos Key Distribution Center are both updated to use the current password. If the server name is not fully qualified, and the target domain (domain.local) differs from the client domain (domain.local), check if there are server accounts with the same name in both domains, or use the fully qualified name to identify the server.
An error event occurred. Event ID: 0x000003EE
Time generated: 02/21/2017 11:15:15
Event chain:
Group Policy processing failed. Windows could not authenticate to the Active Directory service of a domain controller. (LDAP binding function call failed). Refer to the details tab for more information on the error code and description.
An error event occurred. Event ID: 0x40000004
Time generated: 02/21/2017 11:16:11
Event chain:
The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server DC2$. The target name used was DNS/DC2.domain.local. This indicates that the target server failed to decrypt the ticket provided by the client. This may occur when the server's Service Principal Name (SPN) is registered on a different account than the one used by the target service. Please ensure that the SPN is registered on, and only on, the account used by the server. This error may also occur when the target service uses a password for the target service account that differs from that held by the Kerberos Key Distribution Center for the target service account. Please ensure that the service on the server and the Kerberos Key Distribution Center are both updated to use the current password. If the server name is not fully qualified, and the target domain (domain.local) differs from the client domain (domain.local), check if there are server accounts with the same name in both domains, or use the fully qualified name to identify the server.
-
Contributor@helrighWhat does the command:
nslookup return from dc2?
-