Advertisement

05.01.2008 at 09:14PM PDT, ID: 23370710
[x]
Attachment Details

Problem with FSMO roles after intergrating SBS into domain

Asked by bnierman in Active Directory, Windows 2003 Server, SBS Small Business Server

Tags: Server, Small Businees Server 2003

Here is the scenario:
Started with a 2 server domain:
Server 1: Win 2k Standard
Server 2: Win 2003 standard

Server2 was the GC and held all of the FSMO roles.

We needed to integrate an 2003 Small Business server into the environment. Microsoft have a KB on how to do this KB#884453.

So I started with a Dell poweredge 2900. The SBS came pre-installed and I had to start over as according to the KB you have to interupt the setup process to bring it on the existing domain. I carefully followed all the steps:

dcpromo

Added DNS

Made the SBS Server (Server 3) a GC, and waited for the proper event code signifying that the GC was up.

Uncheck the GC on Server 2

Moved the FSMO Roles to server 3

Redirected the Primary DNS server setting on all three machines to Server 3

Everything looked great until I tried to pick up with the integrated setup and continue. At that point it told me that server 3 wasn't an operational master.

Went back to the GUIs and verified that it was a master in all roles.

The I started looking at the original 2 servers. For some reason both server 1 & 2 list the domain masters as "ERROR". More specifically thier Replica of AD list it as ERROR.  If I open the server 3s replica (even from server 1 and 2) it correctly shows the roles as server 3. I then tried to manually replicate from server 3 to servers 1 and 2 (using AD site and services) and when I do I get the follwing error:

The following error occured during the attempt to syncronize name contect {my domainname} from domain controler SERVER3 to domain Controller SERVER1. The naming context is in the process being removed or not replicated from the specified server. This operation will not continue.

I search microsofts site for t5his error, and it said verify that you can ping (I could after shutting down firewall) and allow dynamic updates.

I played with changing the setting to allow secure to allow secure and non-secure and it doesn't help.

Any ideas would be helpfull. Thanks

(added Next morning)- OK So I check the event log this morning and I'm getting 2 warnings:

1)event ID 1586

The Windows NT 4.0 or earlier replication checkpoint with the PDC emulator master was unsuccessful.
 
A full synchronization of the security accounts manager (SAM) database to domain controllers running Windows NT 4.0 and earlier might take place if the PDC emulator master role is transferred to the local domain controller before the next successful checkpoint.
 
The checkpoint process will be tried again in four hours.
 
Additional Data
Error value:
8452 The naming context is in the process of being removed or is not replicated from the specified server.

and 2)

Event ID:1925
The attempt to establish a replication link for the following writable directory partition failed.
 
Directory partition:
DC=absolutebrilliance,DC=local
Source domain controller:
CN=NTDS Settings,CN=ABSERVER3,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=absolutebrilliance,DC=local
Source domain controller address:
54588eb9-da0f-4b36-95dc-71232eb85868._msdcs.absolutebrilliance.local
Intersite transport (if any):
 
 
This domain controller will be unable to replicate with the source domain controller until this problem is corrected.  
 
User Action
Verify if the source domain controller is accessible or network connectivity is available.
 
Additional Data
Error value:
8418 The replication operation failed because of a schema mismatch between the servers involved.

Start Free Trial
 
 
[+][-]05.02.2008 at 04:55AM PDT, ID: 21485888

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]05.02.2008 at 06:51AM PDT, ID: 21486606

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]05.16.2008 at 02:39PM PDT, ID: 21586661

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Active Directory, Windows 2003 Server, SBS Small Business Server
Tags: Server, Small Businees Server 2003
Sign Up Now!
Solution Provided By: bnierman
Participating Experts: 1
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628