NTDS KCC Errors with Event ID 1566, 1311 & 1865

Posted on 2006-05-09
Last Modified: 2012-11-06
Setup: IN our single domain there are 3 sites, each site has a subnet, Site 1 (HQ) has 2 domain controllers running Server 2003 Standard SP1, remote Site 2 and remote Site 3 each have 1 domain controller running Server 2003 Standard Sp1. Domain is 2003 Native mode. At the HQ site the FSMO roles are split across the 2 DC's server 1 has Infrastructure master, Server 2 has PDC and RID and is a GC. The DC at each remote site is a GC. DNS is Dynamic and AD integrated and replicates to all DCs in the AD domain.
Sites and subnets created in AD sites and services. Replication Links created from: HQ site server 1 from HQ Site server 3 and remote site 2 DC; HQ server 2 from HQ server 1 and remote site 2 DC; Remote site 2 from HQ server 1 and HQ server 2; Remote site 3 from HQ server 1 and HQ server 2. Time sync is internal windows time from the HQ Server 2.
Each site has a firewall which is open to replication traffic as far as can be told by following other technical documents on ports needed to allow replication

Issue: replication works with no issues for 7-10 days, then HQ server 2 begins to record KCC errors in the Directory service log with event ids 1566, 1311 & 1865 Along with DNS event error 6002.

The text of error 1566 :
All domain controllers in the following site that can replicate the directory partition over this transport are currently unavailable.
Directory partition:
CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=mycompany,DC=co,DC=uk

The text of error 1311:
The Knowledge Consistency Checker (KCC) has detected problems with the following directory partition.
Directory partition:
 There is insufficient site connectivity information in Active Directory Sites and Services for the KCC to create a spanning tree replication topology. Or, one or more domain controllers with this directory partition are unable to replicate the directory partition information. This is probably due to inaccessible domain controllers.

The text of error 1865 is:
The Knowledge Consistency Checker (KCC) was unable to form a complete spanning tree network topology. As a result, the following list of sites cannot be reached from the local site.

The DNS evnt id 6002 text is:
The transfer of version 11001 of zone by the DNS server was aborted by the server at To restart the transfer of the zone, you must initiate transfer at the secondary server

While these errors occur the HQ server 1 cannot connect to the DC at remote sites 2 & 3 by \\servername the error returned is Windows cannot find the server "servername". Although ping will reply with response and normal response time. Nslookup remote servername returns result fine.
Dcdiag will fail the kccevent test as well as reporting number of failed replications
The only way this can be cured is to reboot the server. HQ Server 2 will also report this error a few days later.

Question: what is the issue here? why would KCC errors happen consistently after the same time period on each HQ server?

Thanks for any help.
Question by:Singnetsvc
    LVL 20

    Accepted Solution

    I think this site should be of great help to you: is very good for helping find specfic examples of Event ID problems. The Link I gave here specfically deals with your problems and can point in the right direction
    LVL 20

    Expert Comment

    LVL 20

    Expert Comment

    Singnetsvc, Any headway on this problem ?
    LVL 20

    Expert Comment

    Have you abandoned me? ;(
    LVL 1

    Expert Comment

    Future viewers - set all connection MTUs to the lowest tested threshold. If you don't know how to test & set an MTU, 1492 is a much better default than 1500.

    Turn on BH Discovery.

    Restart your DCs

    You should have proper replication topology.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    I'm a big fan of Windows' offline folder caching and have used it on my laptops for over a decade.  One thing I don't like about it, however, is how difficult Microsoft has made it for the cache to be moved out of the Windows folder.  Here's how to …
    This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
    Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    21 Experts available now in Live!

    Get 1:1 Help Now