Advertisement

10.06.2008 at 02:52PM PDT, ID: 23792104
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

7.0

Unable to replicate Active Directory between two sites

Asked by NWJustice in Active Directory, Windows 2003 Server, Windows 2000 Server

Tags: , , ,

I have a Windows 2000 Native Domain with 14 sites.  Each of my 13 remote sites is physically connected to my central site (Seattle) with a site-to-site VPN tunnel.  There is no tunnel between remote sites.  In Seattle, I have 2 DCs - both on Win2k.  We'll call them SeaDC1 and SeaDC2.  SeaDC1 is the PDC and Infrastructure Master. SeaDC2 is the Schema Master, Domain Naming Master, and RID Master.  Both are Global Catalog Servers.  Each remote site has a Win2003 DC - none of these are a GC Server.

In AD Sites and Services, I have one InterSite Transport Link set up for each remote site - each Transport Link contains two sites:  one of the remote sites and Seattle.  Unfortunately, I discovered today that for one of my remote sites (Aberdeen), the corresponding Transport Link didn't contain Seattle, but instead contained another remote site that Aberdeen does not have physical connectivity with.  Thus Aberdeen's DC (ABDSERVER) has been isolated for some time.  I believe it has been since 8/21.  When I discovered this, I saw that I was getting very frequent 1566, 1311, 1865, and 1925 error messages from NTDC KCC, as well as error message 4 from Kerberos, all on ABDSERVER.

I added the Seattle site to Aberdeen's Transport Link (and removed the other remote site), so the Transport Link now contains both Aberdeen and Seattle.  Then, in AD Sites and Services, I added a connection to SeaDC1 under Aberdeen-ABDSERVER-NTDS Settings.  I removed the connection to the other remote server.  All of the steps in this paragraph I performed on both ABDSERVER and SeaDC1.

Then I right-clicked on the new SeaDC1 connection I had created and chose Replicate Now.  I got the following error message: "The following error occurred during the attempt to synchronize naming context [domain name] from domain controller SeaDC1 to domain controller ABDSERVER: The naming context is in the process of being removed or is not replicated from the specified server.  This operation will not continue."

I tried restarting the net logon service and continue to get the same error message.  Also, when I look at the event logs for ABDSERVER, I see that I am still getting all error messages above as well as 13508 from NtFrs.  See below for content of error messages.  Please advise - I'd really appreciate it.  Thanks.

1.
Event Type:      Warning
Event Source:      NTDS KCC
Event Category:      Knowledge Consistency Checker
Event ID:      1925
Date:            10/6/2008
Time:            2:27:42 PM
User:            NT AUTHORITY\ANONYMOUS LOGON
Computer:      ABDSERVER
Description:
The attempt to establish a replication link for the following writable directory partition failed.
 
Directory partition:
CN=Configuration,DC=nwjustice,DC=corp
Source domain controller:
CN=NTDS Settings,CN=SeaDC2,CN=Servers,CN=Seattle,CN=Sites,CN=Configuration,DC={domain name},DC=corp
Source domain controller address:
3daf82c8-07e9-4ff5-a725-fc3e7cc499c0._msdcs.{domain name}.corp
Intersite transport (if any):
CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC={domain name},DC=corp
 
This domain controller will be unable to replicate with the source domain controller until this problem is corrected.  
 
User Action
Verify if the source domain controller is accessible or network connectivity is available.
 
Additional Data
Error value:
2148074274 The target principal name is incorrect.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


2.
Event Type:      Warning
Event Source:      NTDS KCC
Event Category:      Knowledge Consistency Checker
Event ID:      1865
Date:            10/6/2008
Time:            2:27:39 PM
User:            NT AUTHORITY\ANONYMOUS LOGON
Computer:      ABDSERVER
Description:
The Knowledge Consistency Checker (KCC) was unable to form a complete spanning tree network topology. As a result, the following list of sites cannot be reached from the local site.
 
Sites:
CN=Olympia,CN=Sites,CN=Configuration,DC={domain name},DC=corp
CN=Yakima,CN=Sites,CN=Configuration,DC={domain name},DC=corp
CN=Colville,CN=Sites,CN=Configuration,DC={domain name},DC=corp
CN=Spokane,CN=Sites,CN=Configuration,DC={domain name},DC=corp
CN=Seattle,CN=Sites,CN=Configuration,DC={domain name},DC=corp
CN=Wenatchee,CN=Sites,CN=Configuration,DC={domain name},DC=corp
CN=Omak,CN=Sites,CN=Configuration,DC={domain name},DC=corp
CN=PortAngeles,CN=Sites,CN=Configuration,DC={domain name},DC=corp

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


3.
Event Type:      Error
Event Source:      NTDS KCC
Event Category:      Knowledge Consistency Checker
Event ID:      1311
Date:            10/6/2008
Time:            2:27:39 PM
User:            NT AUTHORITY\ANONYMOUS LOGON
Computer:      ABDSERVER
Description:
The Knowledge Consistency Checker (KCC) has detected problems with the following directory partition.
 
Directory partition:
CN=Configuration,DC={domain name},DC=corp
 
There is insufficient site connectivity information in Active Directory Sites and Services for the KCC to create a spanning tree replication topology. Or, one or more domain controllers with this directory partition are unable to replicate the directory partition information. This is probably due to inaccessible domain controllers.
 
User Action
Use Active Directory Sites and Services to perform one of the following actions:
- Publish sufficient site connectivity information so that the KCC can determine a route by which this directory partition can reach this site. This is the preferred option.
- Add a Connection object to a domain controller that contains the directory partition in this site from a domain controller that contains the same directory partition in another site.
 
If neither of the Active Directory Sites and Services tasks correct this condition, see previous events logged by the KCC that identify the inaccessible domain controllers.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


4.
Event Type:      Warning
Event Source:      NTDS KCC
Event Category:      Knowledge Consistency Checker
Event ID:      1566
Date:            10/6/2008
Time:            2:27:39 PM
User:            NT AUTHORITY\ANONYMOUS LOGON
Computer:      ABDSERVER
Description:
All domain controllers in the following site that can replicate the directory partition over this transport are currently unavailable.
 
Site:
CN=Seattle,CN=Sites,CN=Configuration,DC={domain name},DC=corp
Directory partition:
CN=Configuration,DC={domain name},DC=corp
Transport:
CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC={domain name},DC=corp

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


5.
Event Type:      Warning
Event Source:      NtFrs
Event Category:      None
Event ID:      13508
Date:            10/6/2008
Time:            11:02:34 AM
User:            N/A
Computer:      ABDSERVER
Description:
The File Replication Service is having trouble enabling replication from SeaDC1 to ABDSERVER for c:\windows\sysvol\domain using the DNS name SeaDC1.{domain name}.corp. FRS will keep retrying.
 Following are some of the reasons you would see this warning.
 
 [1] FRS can not correctly resolve the DNS name SeaDC1.{domain name}.corp from this computer.
 [2] FRS is not running on SeaDC1.{domain name}.corp.
 [3] The topology information in the Active Directory for this replica has not yet replicated to all the Domain Controllers.
 
 This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 21 07 00 00               !...    


6.
Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      4
Date:            10/6/2008
Time:            2:12:35 PM
User:            N/A
Computer:      ABDSERVER
Description:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the server SeaDC1$.  The target name used was LDAP/29d040c8-9bfb-4266-9726-c62adcae6ae6._msdcs.{domain name}.corp. This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named  machine accounts in the target realm ({domain name}.CORP), and the client realm.   Please contact your system administrator.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Start Free Trial
[+][-]10.06.2008 at 03:07PM PDT, ID: 22654840

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]10.06.2008 at 03:38PM PDT, ID: 22655053

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.06.2008 at 03:50PM PDT, ID: 22655120

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]10.06.2008 at 03:54PM PDT, ID: 22655165

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.06.2008 at 03:59PM PDT, ID: 22655206

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.07.2008 at 10:07AM PDT, ID: 22661369

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.07.2008 at 04:10PM PDT, ID: 22664778

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Active Directory, Windows 2003 Server, Windows 2000 Server
Tags: Microsoft, Windows Server, 2000, 2003, Active Directory, DNS
Sign Up Now!
Solution Provided By: NWJustice
Participating Experts: 2
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 - Hierarchy / EE_QW_2_20070628