Avatar of cmadrigal
cmadrigal
 asked on

netlogon and sysvol share missing

Hi,

I performed a disaster recovery restoration of Active Directory on a computer with a different hardware configuration. To do this I Performed a full backup of the domain controller, including the system state and the drive that contains the system volume.

The Restore was OK. But netlogon and sysvol share are missing.

Any suggestions are greatly appreciated.

Windows Server 2003Active DirectoryStorage Software

Avatar of undefined
Last Comment
Chris Dent

8/22/2022 - Mon
shniz123

FRS should replicate those folders and content. This link is stated for Windows 2000 but it's information is valid to help you troubleshoot the issue further. I'd start at FRS and check for any replication problems.
shniz123

http://support.microsoft.com/kb/257338
The link would be helpful....
Network_Data_Support

yes those 2 folders are replicated by the DCs i would check FRS , any errors in the event viewer?  
Your help has saved me hundreds of hours of internet surfing.
fblack61
cmadrigal

ASKER
Yes this errors are listed in event viewer:
1030, 1006, 1054, ...

One thing that I does not explain is that this is a test for a DRP. In which we simulate to have a Full backup full  of a DC, and in a restored alternate place with another computer.

cmadrigal

ASKER
Are there some warnings in Event viewer. File Replication Service:
13566, 13508,

I ready try with the article recommed but did not worked.
Chris Dent


Hey,

Does the AD environment have more servers than one? Is this server attempting to replicate from those?

You can attempt an authoritative rebuild of the FRS Replica set using the D4 flag described in this article:

http://support.microsoft.com/kb/290762

If there is more than one DC involved you should set the flag on the second to D2 (non-authoritative restore) which will force it to replicate from the server which performed authoritative restore.

Chris
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
cmadrigal

ASKER
Folder SYSVOL already shown... but netlogon still missing...
Chris Dent


Still the same set of error messages?

Is the domain clean? Or are there a lot of other DCs listed in the Directory that are not contactable by the restored DC?

Chris
cmadrigal

ASKER
IN the application event shows 1058, 1030

There are one DC no contactable by the DC..
atach result of DCDIAG.
DCDiag.txt
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Chris Dent


You need the FSMO roles, specifically the RID Master but ideally anything that isn't set to be on a live DC.

You're familiar with how to seize them I guess?

Chris
cmadrigal

ASKER
No sir, I have never done this work
Chris Dent


Okay, in that case we should have this bit first :)

If you seize these roles the current role holder can never be restored or brought onto the same network. It would have to be rebuilt as a brand new DC.

That done, this is how we take them over:

Start, Run, cmd

ntdsutil
roles
connections
connect to server <the_current_working_dc>
quit
select operation target
list roles for connected server
quit

This tells you where they are. You need to take over any that aren't accounted for. Continuing on it's time to start taking things over, only do the ones here that you need:

seize rid master
seize infrastructure master
seize schema master
seize pdc
seize domain naming master

It will ask for confirmation at every step, and will attempt transfer prior to seizing.

Chris
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
cmadrigal

ASKER
Chris,

What happen when a DC is no loger available??? :(
StuFox100

I think for DR it would be better to do the following:
1. Install a clean Win 2003 box - ensure you have DNS
2. Do a DCPROMO
3. Restore system state using http://support.microsoft.com/kb/240363

To test this I would do it on a isolated networ so test it correct and not affect the current environment.

Cheers
Stu
ASKER CERTIFIED SOLUTION
Chris Dent

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.