Can I run the rodcprep on the domain now that the ph-dc-bu is functioning not as a "read only" machine?
Main Topics
Browse All TopicsI'm having a few issues after adding a backup domain controller (2k8) to my existing 2003 domain. Honestly I dont notice any problems or any of my 75 users, internet, file and print services seem to be working okay. But I know that when there are errors on the servers it's only a matter of time when things will stop working... Here's a copy of dcdiag to get started...
I have the PHDOMAIN (Server 2003) server dns pointed to PH-DC-BU (Server 2008) and likewise... The active directory seems to be replicating, I ran into long login times immediately after restarting the PHDomain server... Can anyone help?
Directory Server Diagnosis
Performing initial setup:
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site\PHDOMAI
Starting test: Connectivity
......................... PHDOMAIN passed test Connectivity
Doing primary tests
Testing server: Default-First-Site\PHDOMAI
Starting test: Advertising
......................... PHDOMAIN passed test Advertising
Starting test: FrsEvent
......................... PHDOMAIN passed test FrsEvent
Starting test: DFSREvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... PHDOMAIN passed test DFSREvent
Starting test: SysVolCheck
......................... PHDOMAIN passed test SysVolCheck
Starting test: KccEvent
......................... PHDOMAIN passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... PHDOMAIN passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... PHDOMAIN passed test MachineAccount
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=TAPI3Directory,DC=PH,DC
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ForestDnsZones,DC=PH,DC
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=DomainDnsZones,DC=PH,DC
......................... PHDOMAIN failed test NCSecDesc
Starting test: NetLogons
......................... PHDOMAIN passed test NetLogons
Starting test: ObjectsReplicated
......................... HDOMAIN passed test ObjectsReplicated
Starting test: Replications
......................... PHDOMAIN passed test Replications
Starting test: RidManager
......................... PHDOMAIN passed test RidManager
Starting test: Services
......................... PHDOMAIN passed test Services
Starting test: SystemLog
......................... PHDOMAIN passed test SystemLog
Starting test: VerifyReferences
......................... PHDOMAIN passed test VerifyReferences
Running partition tests on : TAPI3Directory
Starting test: CheckSDRefDom
......................... TAPI3Directory passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... TAPI3Directory passed test
CrossRefValidation
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : PH
Starting test: CheckSDRefDom
......................... PH passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... PH passed test CrossRefValidation
Running enterprise tests on : PH.local
Starting test: LocatorCheck
......................... PH.local passed test LocatorCheck
Starting test: Intersite
......................... PH.local passed test Intersite
C:\Users\administrator.PH>
Directory Server Diagnosis
Performing initial setup:
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site\PH-DC-B
Starting test: Connectivity
......................... PH-DC-BU passed test Connectivity
Doing primary tests
Testing server: Default-First-Site\PH-DC-B
Starting test: Advertising
......................... PH-DC-BU passed test Advertising
Starting test: FrsEvent
The event log File Replication Service on server PH-DC-BU.PH.local
could not be queried, error 0x6ba "The RPC server is unavailable."
......................... PH-DC-BU failed test FrsEvent
Starting test: DFSREvent
The event log DFS Replication on server PH-DC-BU.PH.local could not be
queried, error 0x6ba "The RPC server is unavailable."
......................... PH-DC-BU failed test DFSREvent
Starting test: SysVolCheck
......................... PH-DC-BU passed test SysVolCheck
Starting test: KccEvent
The event log Directory Service on server PH-DC-BU.PH.local could not
be queried, error 0x6ba "The RPC server is unavailable."
......................... PH-DC-BU failed test KccEvent
Starting test: KnowsOfRoleHolders
......................... PH-DC-BU passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... PH-DC-BU passed test MachineAccount
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=DomainDnsZones,DC=PH,DC
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ForestDnsZones,DC=PH,DC
......................... PH-DC-BU failed test NCSecDesc
Starting test: NetLogons
......................... PH-DC-BU passed test NetLogons
Starting test: ObjectsReplicated
......................... PH-DC-BU passed test ObjectsReplicated
Starting test: Replications
......................... PH-DC-BU passed test Replications
Starting test: RidManager
......................... PH-DC-BU passed test RidManager
Starting test: Services
......................... PH-DC-BU passed test Services
Starting test: SystemLog
The event log System on server PH-DC-BU.PH.local could not be queried,
error 0x6ba "The RPC server is unavailable."
......................... PH-DC-BU failed test SystemLog
Starting test: VerifyReferences
......................... PH-DC-BU passed test VerifyReferences
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : PH
Starting test: CheckSDRefDom
......................... PH passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... PH passed test CrossRefValidation
Running enterprise tests on : PH.local
Starting test: LocatorCheck
......................... PH.local passed test LocatorCheck
Starting test: Intersite
......................... PH.local passed test Intersite
C:\Users\administrator.PH>
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Hello,
We are experiencing the same issues with a very similar setup (2003 DCs with 2008 DCs being added). In one of our testing environments we ran the /rodcprep before promoting the 2008 servers to DCs and are still getting the errors. The errors only appear when running the dcdiag against a remote server. We've ran repadmin and it reports successful for all DCs. When running dcdiag against the local server there are no errors.
Not trying to steal the thread, just throwing out some things we've tried in case the solution davesgonebananas mentioned does not work for bootcampwithjess.
Steve
bootcampwithjess:
We found the problem to our issue. So I hope that it solves yours as well.
We found that Windows Firewall blocks RPC traffic, even from other domain controllers. To allow your dcdiag tests to work you would need to either disable Windows Firewall, add an exception for "Remote Administration" or identify what ports are used and create an exception.
Hopefully this helps you out.
Steve
Business Accounts
Answer for Membership
by: davesgonebananasPosted on 2009-01-05 at 19:45:19ID: 23301775
This is an issue with adding a Windows2008 server to a 2003 domain without first running adprep /rodcprep - it is safe to ignore these errors unless you are planning on adding an RODC to your domain in which case you should run adprep /rodcprep on your domain.
om/en-us/l ibrary/cc7 54463.aspx
http://technet.microsoft.c