Solved

AD Sites and Replication Implementation.

Posted on 2001-06-06
12
187 Views
Last Modified: 2010-04-13
I've setup AD single domain with child domains underneath.
I want my root DC to replicate to all 31 child domain controllers. Is it a good idea to replicate all dc's among each other or just all child dc's to root dc. Also, in one of the child domains I accidentally erased the ndts settings from the AD Sites and Services MMC. Cannot bring it back, to specify who it will be replicating to. Any clues or suggestions.
0
Comment
Question by:hadame
  • 7
  • 5
12 Comments
 
LVL 12

Expert Comment

by:Housenet
ID: 6161963
-Configure bridgehead servers to handle replication trafic for the sites. You can setup schedules to have the traffic send at off hrs or via smtp.. I would perform a non-authoritative restore of the system state of the DC with the deleted objects with ntdsutil.
0
 

Author Comment

by:hadame
ID: 6163813
I've designated my root dc as the preferred bridgehead server with the IP transport. I also have created sites and moved their proper child dc to it. Additionally, created site links betweeen each child dc to the root dc. Subnets were created and assigned to their respective site.
Should I designate each child dc as bridgehead server too? My network consists of 31 T1 lines coming to a Central Office location, which is where my root dc is at.
0
 
LVL 12

Accepted Solution

by:
Housenet earned 200 total points
ID: 6165789
-No... Install a global catalog server at each site..
-Designate 1 DC at each site to replicate to the root bridgehead server.. This means 1 bridgehead per site...Not every server as a bridgehead server...
0
 

Author Comment

by:hadame
ID: 6168588
I setup the root domain controller of each site as a global catalog server. Also all root child dc are setup to replicate with the main root bridgehead server. I'm goin to designate each root child dc as bridgehead server as sugested. I'm noticing that each root child dc is being getting automatic connections among each other by itself. I guess is a KCC process. I did a non authorative restore on my failed dc, and it worked. Now I can see those lost NTDS settings from that server. Let me try that.
0
 
LVL 12

Expert Comment

by:Housenet
ID: 6169505
-I'm goin to designate each root child dc as
bridgehead server as sugested.
-Thats very good.

-I'm noticing that each root child dc is being getting automatic connections among each other by itself. I guess is a KCC process.
-Yes , among each other within the site is perfectly normal. If they're replicating between sites to each other, thats okay too but you want to make sure this only happens in the bridgehead is down, so... Assign a higher cost to any connections you do not want used frequently.
-Default cost is 100 ...A good hogh cost number is 200..
0
 
LVL 12

Expert Comment

by:Housenet
ID: 6200143
-Any news Hadame ?>
0
Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

 

Author Comment

by:hadame
ID: 6202411
I'm still having problems with 3 dc's not replicating properly. I've tried a force replicate, the repadmin, and no success. Here are the messages:

Partner Name: sgm-site\SGM-DC
               Partner GUID: A4F28F29-C75C-4F8E-9207-AA465F479092
               Last Attempted Replication: 6/18/2001 6:34:56 AM (local)
               Last Successful Replication: 6/14/2001 6:03:15 PM (local)
               Number of Failures:  56
               Failure Reason Error Code:  1722
               Failure Description: The RPC server is unavailable.
               Synchronization Flags: DRS_PER_SYNC,DRS_USE_COMPRESSION,DRS_NEVER_NOTIFY
               USN of Last Property Updated:  196247
               USN of Last Object Updated:  196247
               Transport: Inter-Site RPC

          Partner Name: um-site\UM-DC
               Partner GUID: 0B748D9D-85DB-4E33-B7F1-AC8955E95ABF
               Last Attempted Replication: 6/18/2001 6:35:19 AM (local)
               Last Successful Replication: 6/11/2001 11:51:34 AM (local)
               Number of Failures:  110
               Failure Reason Error Code:  1722
               Failure Description: The RPC server is unavailable.
               Synchronization Flags: DRS_PER_SYNC,DRS_USE_COMPRESSION,DRS_NEVER_NOTIFY
               USN of Last Property Updated:  143896
               USN of Last Object Updated:  143896
               Transport: Inter-Site RPC
Partner Name: fe-site\FE-DC
               Partner GUID: 5FA9E947-87F9-493F-B629-23B337C97652
               Last Attempted Replication: 6/18/2001 5:53:39 AM (local)
               Last Successful Replication: 6/6/2001 2:59:23 PM (local)
               Number of Failures:  186
               Failure Reason Error Code:  1723
               Failure Description: The RPC server is too busy to complete this operation.
               Synchronization Flags: DRS_WRIT_REP,DRS_PER_SYNC,DRS_USE_COMPRESSION,DRS_NEVER_NOTIFY
               USN of Last Property Updated:  17103
               USN of Last Object Updated:  17103
               Transport: Inter-Site RPC

I already checked the connections, ping, UNC, http, and they are working fine.  Any suggestions?
0
 

Author Comment

by:hadame
ID: 6204245
I'm still having problems with 3 dc's not replicating properly. I've tried a force replicate, the repadmin, and no success. Here are the messages:

Partner Name: sgm-site\SGM-DC
               Partner GUID: A4F28F29-C75C-4F8E-9207-AA465F479092
               Last Attempted Replication: 6/18/2001 6:34:56 AM (local)
               Last Successful Replication: 6/14/2001 6:03:15 PM (local)
               Number of Failures:  56
               Failure Reason Error Code:  1722
               Failure Description: The RPC server is unavailable.
               Synchronization Flags: DRS_PER_SYNC,DRS_USE_COMPRESSION,DRS_NEVER_NOTIFY
               USN of Last Property Updated:  196247
               USN of Last Object Updated:  196247
               Transport: Inter-Site RPC

          Partner Name: um-site\UM-DC
               Partner GUID: 0B748D9D-85DB-4E33-B7F1-AC8955E95ABF
               Last Attempted Replication: 6/18/2001 6:35:19 AM (local)
               Last Successful Replication: 6/11/2001 11:51:34 AM (local)
               Number of Failures:  110
               Failure Reason Error Code:  1722
               Failure Description: The RPC server is unavailable.
               Synchronization Flags: DRS_PER_SYNC,DRS_USE_COMPRESSION,DRS_NEVER_NOTIFY
               USN of Last Property Updated:  143896
               USN of Last Object Updated:  143896
               Transport: Inter-Site RPC
Partner Name: fe-site\FE-DC
               Partner GUID: 5FA9E947-87F9-493F-B629-23B337C97652
               Last Attempted Replication: 6/18/2001 5:53:39 AM (local)
               Last Successful Replication: 6/6/2001 2:59:23 PM (local)
               Number of Failures:  186
               Failure Reason Error Code:  1723
               Failure Description: The RPC server is too busy to complete this operation.
               Synchronization Flags: DRS_WRIT_REP,DRS_PER_SYNC,DRS_USE_COMPRESSION,DRS_NEVER_NOTIFY
               USN of Last Property Updated:  17103
               USN of Last Object Updated:  17103
               Transport: Inter-Site RPC

I already checked the connections, ping, UNC, http, and they are working fine.  Any suggestions?
0
 
LVL 12

Expert Comment

by:Housenet
ID: 6204692
0
 
LVL 12

Expert Comment

by:Housenet
ID: 6204698
0
 
LVL 12

Expert Comment

by:Housenet
ID: 6204707
-I remember using this tool before.. Its pretty good..& can test replication & offer advice... try it..
http://www.netiq.com/ADcheck/ThankYou.asp?prod=
0
 

Author Comment

by:hadame
ID: 6206437
Replication is getting better after applying these changes.  Also your links are very useful.  Thanks again Housenet :-)
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now