I have a synchronization problem between my two domains controllers. The synchronization work between AD1 to TA1 but not from TA1 to AD1 (Users created on AD1 will appear on TA1).
AD1 was my first domain created for ZRx.local. TA1 was added as the second controller a few months later. I can see clearly what causing the problem; but Ive been unable to fix it.
Here a list of the thing I have tried until now
Reset machine account passwords (
http://support.microsoft.com/kb/325850)
I try a few /fix with utilities that support it without success ... I did not take note about them though, so will be glad to retry them if needed.
Here the information I have gathered with various tools:
EVENT LOGS ON AD1
First, here the 3 warning that appears in the Event Logs from AD1 in the Directory Service folder every 15 mins.
The KCC seem unable to create the replication link.
**************************
**********
**********
****
Event Type: Warning
Event Source: NTDS KCC
Event Category: Knowledge Consistency Checker
Event ID: 1925
Date: 3/6/2008
Time: 4:05:28 PM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: AD1
Description:
The attempt to establish a replication link for the following writable directory partition failed.
Directory partition:
CN=Configuration,DC=ZRx,DC
=local
Source domain controller:
CN=NTDS Settings,CN=TA1,CN=Servers
,CN=Defaul
t-First-Si
te-Name,CN
=Sites,CN=
Configurat
ion,DC=ZRx
,DC=local
Source domain controller address:
c3e5a5f2-645e-46b6-a91d-a5
7ff7603b69
._msdcs.ZR
x.local
Intersite transport (if any):
This domain controller will be unable to replicate with the source domain controller until this problem is corrected.
User Action
Verify if the source domain controller is accessible or network connectivity is available.
Additional Data
Error value:
5 Access is denied.
**************************
**********
**********
****
**************************
**********
**********
****
Event Type: Warning
Event Source: NTDS KCC
Event Category: Knowledge Consistency Checker
Event ID: 1925
Date: 3/6/2008
Time: 4:05:28 PM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: AD1
Description:
The attempt to establish a replication link for the following writable directory partition failed.
Directory partition:
CN=Schema,CN=Configuration
,DC=ZRx,DC
=local
Source domain controller:
CN=NTDS Settings,CN=TA1,CN=Servers
,CN=Defaul
t-First-Si
te-Name,CN
=Sites,CN=
Configurat
ion,DC=ZRx
,DC=local
Source domain controller address:
c3e5a5f2-645e-46b6-a91d-a5
7ff7603b69
._msdcs.ZR
x.local
Intersite transport (if any):
This domain controller will be unable to replicate with the source domain controller until this problem is corrected.
User Action
Verify if the source domain controller is accessible or network connectivity is available.
Additional Data
Error value:
5 Access is denied.
**************************
**********
**********
****
**************************
**********
**********
****
Event Type: Warning
Event Source: NTDS KCC
Event Category: Knowledge Consistency Checker
Event ID: 1925
Date: 3/6/2008
Time: 4:05:28 PM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: AD1
Description:
The attempt to establish a replication link for the following writable directory partition failed.
Directory partition:
DC=ZRx,DC=local
Source domain controller:
CN=NTDS Settings,CN=TA1,CN=Servers
,CN=Defaul
t-First-Si
te-Name,CN
=Sites,CN=
Configurat
ion,DC=ZRx
,DC=local
Source domain controller address:
c3e5a5f2-645e-46b6-a91d-a5
7ff7603b69
._msdcs.ZR
x.local
Intersite transport (if any):
This domain controller will be unable to replicate with the source domain controller until this problem is corrected.
User Action
Verify if the source domain controller is accessible or network connectivity is available.
Additional Data
Error value:
5 Access is denied.
**************************
**********
**********
****
Here is an example of information that appear once in while right after the previous three warning.
**************************
**********
**********
****
Event Type: Information
Event Source: NTDS KCC
Event Category: Knowledge Consistency Checker
Event ID: 1104
Date: 3/6/2008
Time: 4:05:28 PM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: AD1
Description:
The Knowledge Consistency Checker (KCC) successfully terminated the following change notifications.
Directory partition:
DC=ZRx,DC=local
Destination network address:
c3e5a5f2-645e-46b6-a91d-a5
7ff7603b69
._msdcs.ZR
x.local
Destination domain controller (if available):
CN=NTDS Settings,CN=TA1,CN=Servers
,CN=Defaul
t-First-Si
te-Name,CN
=Sites,CN=
Configurat
ion,DC=ZRx
,DC=local
This event can occur if either this domain controller or the destination domain controller has been moved to another site.
**************************
**********
**********
****
EVENT LOGS on TA1
**************************
**********
**********
****
Event Type: Warning
Event Source: NtFrs
Event Category: None
Event ID: 13508
Date: 3/17/2008
Time: 12:02:28 PM
User: N/A
Computer: TA1
Description:
The File Replication Service is having trouble enabling replication from AD1 to TA1 for c:\windows\sysvol\domain using the DNS name AD1.ZRx.local. FRS will keep retrying.
Following are some of the reasons you would see this warning.
[1] FRS can not correctly resolve the DNS name AD1.ZRx.local from this computer.
[2] FRS is not running on AD1.ZRx.local.
[3] The topology information in the Active Directory for this replica has not yet replicated to all the Domain Controllers.
This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.
**************************
**********
**********
****
SUCCESSFULL PING DONE ON BOTH COMPUTER
c3e5a5f2-645e-46b6-a91d-a5
7ff7603b69
._msdcs.ZR
x.local
7ecd9744-f6ad-452b-b294-6e
166a49b11e
._msdcs.ZR
x.local
ad1.zrx.local
ta1.zrx.local
ad1
ta1
DCDIAG - AD1
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\AD
1
Starting test: Connectivity
......................... AD1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\AD
1
Starting test: Replications
......................... AD1 passed test Replications
Starting test: NCSecDesc
......................... AD1 passed test NCSecDesc
Starting test: NetLogons
......................... AD1 passed test NetLogons
Starting test: Advertising
......................... AD1 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... AD1 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... AD1 passed test RidManager
Starting test: MachineAccount
......................... AD1 passed test MachineAccount
Starting test: Services
......................... AD1 passed test Services
Starting test: ObjectsReplicated
......................... AD1 passed test ObjectsReplicated
Starting test: frssysvol
......................... AD1 passed test frssysvol
Starting test: frsevent
......................... AD1 passed test frsevent
Starting test: kccevent
An Warning Event occured. EventID: 0x80000785
Time Generated: 03/14/2008 14:51:32
Event String: The attempt to establish a replication link for An Warning Event occured. EventID: 0x80000785
Time Generated: 03/14/2008 14:51:32
Event String: The attempt to establish a replication link for An Warning Event occured. EventID: 0x80000785
Time Generated: 03/14/2008 14:51:32
Event String: The attempt to establish a replication link for ......................... AD1 failed test kccevent
Starting test: systemlog
......................... AD1 passed test systemlog
Starting test: VerifyReferences
......................... AD1 passed test VerifyReferences
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : ZRx
Starting test: CrossRefValidation
......................... ZRx passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ZRx passed test CheckSDRefDom
Running enterprise tests on : ZRx.local
Starting test: Intersite
......................... ZRx.local passed test Intersite
Starting test: FsmoCheck
......................... ZRx.local passed test FsmoCheck
DCDIAG - TA1
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\TA
1
Starting test: Connectivity
......................... TA1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\TA
1
Starting test: Replications
REPLICATION LATENCY WARNING
ERROR: Expected notification link is missing.
Source AD1
Replication of new changes along this path will be delayed.
This problem should self-correct on the next periodic sync.
......................... TA1 passed test Replications
Starting test: NCSecDesc
......................... TA1 passed test NCSecDesc
Starting test: NetLogons
......................... TA1 passed test NetLogons
Starting test: Advertising
......................... TA1 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... TA1 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... TA1 passed test RidManager
Starting test: MachineAccount
......................... TA1 passed test MachineAccount
Starting test: Services
......................... TA1 passed test Services
Starting test: ObjectsReplicated
......................... TA1 passed test ObjectsReplicated
Starting test: frssysvol
......................... TA1 passed test frssysvol
Starting test: frsevent
There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems.
......................... TA1 failed test frsevent
Starting test: kccevent
......................... TA1 passed test kccevent
Starting test: systemlog
......................... TA1 passed test systemlog
Starting test: VerifyReferences
......................... TA1 passed test VerifyReferences
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : ZRx
Starting test: CrossRefValidation
......................... ZRx passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ZRx passed test CheckSDRefDom
Running enterprise tests on : ZRx.local
Starting test: Intersite
......................... ZRx.local passed test Intersite
Starting test: FsmoCheck
......................... ZRx.local passed test FsmoCheck
DNSLINT REPORT ON AD1
DNSLint Report
System Date: Fri Mar 14 14:54:55 2008
Command run:
dnslint /ad 192.168.5.13 /s 192.168.5.13 /v
Root of Active Directory Forest:
ZRx.local
Active Directory Forest Replication GUIDs Found:
DC: AD1
GUID: 7ecd9744-f6ad-452b-b294-6e
166a49b11e
DC: TA1
GUID: c3e5a5f2-645e-46b6-a91d-a5
7ff7603b69
Total GUIDs found: 2
The following 2 DNS servers were checked for records related to AD forest replication:
DNS server: User Specified DNS Server
IP Address: 192.168.5.13
UDP port 53 responding to queries: YES
TCP port 53 responding to queries: Not tested
Answering authoritatively for domain: Unknown
SOA record data from server:
Authoritative name server: ad1.ZRx.local
Hostmaster: hostmaster
Zone serial number: 30
Zone expires in: 1.00 day(s)
Refresh period: 900 seconds
Retry delay: 600 seconds
Default (minimum) TTL: 3600 seconds
Additional authoritative (NS) records from server:
ad1.zrx.local 192.168.5.13
Alias (CNAME) and glue (A) records for forest GUIDs from server:
CNAME: 7ecd9744-f6ad-452b-b294-6e
166a49b11e
._msdcs.ZR
x.local
Alias: ad1.ZRx.local
Glue: 192.168.5.13
CNAME: c3e5a5f2-645e-46b6-a91d-a5
7ff7603b69
._msdcs.ZR
x.local
Alias: ta1.ZRx.local
Glue: 192.168.5.12
Total number of CNAME records found on this server: 2
Total number of CNAME records missing on this server: 0
Total number of glue (A) records this server could not find: 0
DNS server: ad1.zrx.local
IP Address: 192.168.5.13
UDP port 53 responding to queries: YES
TCP port 53 responding to queries: Not tested
Answering authoritatively for domain: YES
SOA record data from server:
Authoritative name server: ad1.ZRx.local
Hostmaster: hostmaster
Zone serial number: 30
Zone expires in: 1.00 day(s)
Refresh period: 900 seconds
Retry delay: 600 seconds
Default (minimum) TTL: 3600 seconds
Additional authoritative (NS) records from server:
ad1.zrx.local 192.168.5.13
Alias (CNAME) and glue (A) records for forest GUIDs from server:
CNAME: 7ecd9744-f6ad-452b-b294-6e
166a49b11e
._msdcs.ZR
x.local
Alias: ad1.ZRx.local
Glue: 192.168.5.13
CNAME: c3e5a5f2-645e-46b6-a91d-a5
7ff7603b69
._msdcs.ZR
x.local
Alias: ta1.ZRx.local
Glue: 192.168.5.12
Total number of CNAME records found on this server: 2
Total number of CNAME records missing on this server: 0
Total number of glue (A) records this server could not find: 0
Notes:
One or more DNS servers may not be authoritative for the domain
Legend: warning, error
DNSLint developed by Tim Rains
ACTIVE DIRECTORY REPLICATION MONITOR
From "Active Directory Replication Monitor" tools, i found the following information:
In Monitored Servers - Default-First-Site-Name - AD1 - Server Properties - Inbound Replication Connnections
Connection Name: c78c179e-ad16-4a98-992d-a2
316dc818a0
Replication Partner: Default-First-Site-Name\TA
1
Administrator Generated?: AUTO
Reasons for this connection:
--------------------------
--
Directory Partition (CN=Configuration,DC=ZRx,D
C=local)
This replication connection is created because another replication partner has surpassed the allowed failure limit.
Directory Partition (CN=Schema,CN=Configuratio
n,DC=ZRx,D
C=local)
This replication connection is created because another replication partner has surpassed the allowed failure limit.
Directory Partition (DC=ZRx,DC=local)
This replication connection is created because another replication partner has surpassed the allowed failure limit.
ACTIVE DIRECTORY SITES AND SERVICES
The KCC seem unable to create one of the four links required.
From "Active Directory Sites and Services" tools on AD1, i found the following information:
AD1
Default-First-Site-Name
Servers
AD1
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/AD1
NTDS Settings
7ECD9744-F6AD-452B-B294-6E
166A49B11E
._msdcs.ZR
x.local
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/AD1/
NTDS Settings
1 object
<automatically generated>
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/AD1/
NTDS Settings/c78c179e-ad16-4a9
8-992d-a23
16dc818a0
TA1
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/TA1
NTDS Settings
C3E5A5F2-645E-46B6-A91D-A5
7FF7603B69
._msdcs.ZR
x.local
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/TA1/
NTDS Settings
0 object
From "Active Directory Sites and Services" tools on TA1, i found the following information:
TA1
Default-First-Site-Name
Servers
AD1
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/AD1
NTDS Settings
7ECD9744-F6AD-452B-B294-6E
166A49B11E
._msdcs.ZR
x.local
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/AD1/
NTDS Settings
1 object
<automatically generated>
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/AD1/
NTDS Settings/c78c179e-ad16-4a9
8-992d-a23
16dc818a0
TA1
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/TA1
NTDS Settings
C3E5A5F2-645E-46B6-A91D-A5
7FF7603B69
._msdcs.ZR
x.local
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/TA1/
NTDS Settings
1 object
<automatically generated>
ZRx.local/Configuration/Si
tes/Defaul
t-First-Si
te-Name/Se
rvers/TA1/
NTDS Settings/cc63068c-6928-4b4
c-be3c-e0e
a1e89cd3f
From "adsiedit.msc", the tombstone lifetime is 180 days.
TA1 have been promoted to Active Directory November 12, 1007
IPCONFIG /ALL on AD1
Windows IP Configuration
Host Name . . . . . . . . . . . . : AD1
Primary Dns Suffix . . . . . . . : ZRx.local
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : ZRx.local
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : VMware PCI Ethernet Adapter
Physical Address. . . . . . . . . : 00-50-56-00-00-13
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.5.13
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.5.1
DNS Servers . . . . . . . . . . . : 127.0.0.1
IPCONFIG /ALL on TA1
Windows IP Configuration
Host Name . . . . . . . . . . . . : TA1
Primary Dns Suffix . . . . . . . : ZRx.local
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : ZRx.local
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : VMware PCI Ethernet Adapter
Physical Address. . . . . . . . . : 00-50-56-00-00-12
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.5.12
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.5.1
DNS Servers . . . . . . . . . . . : 192.168.5.13
66.38.189.141
DCDIAG /TEST:CHECKSECURITYERROR on AD1
C:\Program Files\Support Tools>dcdiag /test:CheckSecurityError
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\AD
1
Starting test: Connectivity
......................... AD1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\AD
1
Starting test: CheckSecurityError
Source DC TA1 has possible security error (5). Diagnosing...
C:\Program Files\Support Tools>
DCDIAG /TEST:CHECKSECURITYERROR on TA1
C:\Program Files\Support Tools>dcdiag /test:CheckSecurityError
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\TA
1
Starting test: Connectivity
......................... TA1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\TA
1
Starting test: CheckSecurityError
[TA1] No security related replication errors were found on this DC! To
target the connection to a specific source DC use /ReplSource:<DC>.
......................... TA1 passed test CheckSecurityError
Running partition tests on : Schema
Running partition tests on : Configuration
Running partition tests on : ZRx
Running enterprise tests on : ZRx.local
C:\Program Files\Support Tools>
DCDIAG /TEST:REPLICATiONS on AD1
C:\Program Files\Support Tools>dcdiag /test:Replications
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\AD
1
Starting test: Connectivity
......................... AD1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\AD
1
Starting test: Replications
......................... AD1 passed test Replications
Running partition tests on : DomainDnsZones
Running partition tests on : Schema
Running partition tests on : Configuration
Running partition tests on : ZRx
Running enterprise tests on : ZRx.local
C:\Program Files\Support Tools>
DCDIAG /TEST:REPLICATiONS on TA1
C:\Program Files\Support Tools>dcdiag /test:replications
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\TA
1
Starting test: Connectivity
......................... TA1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\TA
1
Starting test: Replications
REPLICATION LATENCY WARNING
ERROR: Expected notification link is missing.
Source AD1
Replication of new changes along this path will be delayed.
This problem should self-correct on the next periodic sync.
......................... TA1 passed test Replications
Running partition tests on : Schema
Running partition tests on : Configuration
Running partition tests on : ZRx
Running enterprise tests on : ZRx.local
C:\Program Files\Support Tools>
REPADMIN
showrepl_COLUMNS,Destinati
on DC Site,Destination DC,Naming Context,Source DC Site,Source DC,Transport Type,Number of Failures,Last Failure Time,Last Success Time,Last Failure Status
showrepl_INFO,Default-Firs
t-Site-Nam
e,TA1,"DC=
ZRx,DC=loc
al",Defaul
t-First-Si
te-Name,AD
1,RPC,0,0,
2008-03-17
12:49:10,0
showrepl_INFO,Default-Firs
t-Site-Nam
e,TA1,"CN=
Configurat
ion,DC=ZRx
,DC=local"
,Default-F
irst-Site-
Name,AD1,R
PC,0,0,200
8-03-17 12:49:10,0
showrepl_INFO,Default-Firs
t-Site-Nam
e,TA1,"CN=
Schema,CN=
Configurat
ion,DC=ZRx
,DC=local"
,Default-F
irst-Site-
Name,AD1,R
PC,0,0,200
8-03-17 12:49:10,0