Solved

AD Replication

Posted on 2008-06-10
6
925 Views
Last Modified: 2013-12-05
I have an exchange 2000 mail server which is also a DC for our domain. This is multi site domain. Replication to this mail server will not work due to 'access is denied errors' & ERROR_REPLICA_SYNC_FAILED_ACCESS IS DENIED. The event log on that server is full of NTDS KCC entries in the event logs. It has failed to replicate for over 90 days. Therefore (a) it is fixable and (b) do I want to replicate if it has been offline for that long, bearing in mind our AD activity is pretty minimal.

Regards.
0
Comment
Question by:championit
  • 2
  • 2
6 Comments
 
LVL 3

Expert Comment

by:Karl12347
ID: 21752722
You have major problems due to the fact you have exchnage on a domain controller. If you demote the server from being a domain controller, exchnage will not function correctly at all.

It is a bit tricky, you will have to use the dcdiag tool and ntdsutil tools to troubleshoot why the connection problems are occouring. If you get the connection working again, your latest updated Active directory on another server can be replicated to overwrite this domain controller that is not working correctly.

Hope this helps
0
 

Author Comment

by:championit
ID: 21753642
I thought Exchange had to be installed on a DC for some reason!! We have 5 DC's across our WAN all running Exchange. I take it this is not best practice and we need to get Exchange off their asap.
I am running some dcdiag tests at present and will upload the results in a file when complete.

If I move Exchange to another server then rebuild the DC will Exchange as an enterprise function given that one Exchange server will be running on a member sercer and the other 4 on DC's ?
0
 

Author Comment

by:championit
ID: 21753684
dcdiag attached, not sure whether this test the connectivity as it's a very long time since I used this. Will try ntdsutil also
mail02-dcdiag1.txt
0
 
LVL 3

Accepted Solution

by:
Karl12347 earned 500 total points
ID: 21759152
First of all you should start the windows time service on your mail box.  Kerberos will fail if it cannot verify the time on your systems.
w32time Service is stopped on [MCR-MAIL-02]
Try running DCdiag with the /fixall command.

MCR-MAIL-02 failed test kccevent indicates that you are having problems with the Kerberos Consistecy checker on your domain controller.

Without sitting infront of your servers and having a look, It is very doubtfull that anyone on her could provide a full solution.

If you have any further questions please let me know.

Karl
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
User (Manager) needs all Inbox/Sent items from various users. 5 14
AD Account lockout 11 60
NTP Servers 4 42
Exchange 2013 - Recieve Connectors 4 20
This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
This video discusses moving either the default database or any database to a new volume.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

680 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question