AD Replication Problem

AD Environment
It’s a W2K AD.  There is a root and three domains.  Each domain has multiple domain controllers.  Each domain represents a business function/company.  All domain controllers within the AD have been patched will all current Microsoft patches.  

I have two problems.
1.  I changed my GPO to force account lockout after three invalid password attempts.  All of a sudden, users started having problems with being locked out of their accounts.  Only one of the three domains is having this problem.  Most of the users swear they never entered their password but one time.  This leads to my second problem.

2.  One on my domain controllers is having problems communicating to all servers in another domain.  When I do a repadmin /showreps I get the following issue for all servers associated with that domain, which is about seven servers.

    OUNAME\server1 via RPC
        objectGuid: 16fb0d39-bbe8-4cc3-a9b2-0a302b6a8405
        Last attempt @ 2004-11-11 20:14.16 failed, result 1908:
            Could not find the domain controller for this domain.
        Last success @ 2004-10-31 11:05.29.  

I am able to ping all of the servers that the domain controller says it is having problems communicating with.  I did notice that the administrator account kept getting locked out with the policy above when I forced replication.  I turned off the policy to stop the administrator account from getting locked out.

Any ideas on how to solve these problems?

Thanks for your help!
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Have you run DCDIAG on the enterprise yet? If not, run it with the following switches:

dcdiag /s:SERVERNAME /e /c /v > c:\dcdiag.txt

SERVERNAME = the name of the server

After that, go find c:\dcdiag.txt on the server and post up the text of the file here and we can try trouble shooting from there.

Also, here are some questions:

Are all the servers in a single site?

Gone in to AD Sites & Services to make sure all the servers are in there and have replication partners listed?

The forest or domain root servers haven't been decommishioned or anything have they? Anotherwords, are all the FSMO role holders still intact?

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Just following up to see if you had forgotten about this question.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 2000

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.