Solved

AD Replication

Posted on 2008-06-10
6
911 Views
Last Modified: 2013-12-05
I have an exchange 2000 mail server which is also a DC for our domain. This is multi site domain. Replication to this mail server will not work due to 'access is denied errors' & ERROR_REPLICA_SYNC_FAILED_ACCESS IS DENIED. The event log on that server is full of NTDS KCC entries in the event logs. It has failed to replicate for over 90 days. Therefore (a) it is fixable and (b) do I want to replicate if it has been offline for that long, bearing in mind our AD activity is pretty minimal.

Regards.
0
Comment
Question by:championit
  • 2
  • 2
6 Comments
 
LVL 3

Expert Comment

by:Karl12347
ID: 21752722
You have major problems due to the fact you have exchnage on a domain controller. If you demote the server from being a domain controller, exchnage will not function correctly at all.

It is a bit tricky, you will have to use the dcdiag tool and ntdsutil tools to troubleshoot why the connection problems are occouring. If you get the connection working again, your latest updated Active directory on another server can be replicated to overwrite this domain controller that is not working correctly.

Hope this helps
0
 

Author Comment

by:championit
ID: 21753642
I thought Exchange had to be installed on a DC for some reason!! We have 5 DC's across our WAN all running Exchange. I take it this is not best practice and we need to get Exchange off their asap.
I am running some dcdiag tests at present and will upload the results in a file when complete.

If I move Exchange to another server then rebuild the DC will Exchange as an enterprise function given that one Exchange server will be running on a member sercer and the other 4 on DC's ?
0
 

Author Comment

by:championit
ID: 21753684
dcdiag attached, not sure whether this test the connectivity as it's a very long time since I used this. Will try ntdsutil also
mail02-dcdiag1.txt
0
 
LVL 3

Accepted Solution

by:
Karl12347 earned 500 total points
ID: 21759152
First of all you should start the windows time service on your mail box.  Kerberos will fail if it cannot verify the time on your systems.
w32time Service is stopped on [MCR-MAIL-02]
Try running DCdiag with the /fixall command.

MCR-MAIL-02 failed test kccevent indicates that you are having problems with the Kerberos Consistecy checker on your domain controller.

Without sitting infront of your servers and having a look, It is very doubtfull that anyone on her could provide a full solution.

If you have any further questions please let me know.

Karl
0

Featured Post

Why spend so long doing email signature updates?

Do you spend loads of your time carrying out email signature updates? Not very interesting are they? Don’t let signature updates get you down. Let Exclaimer Cloud - Signatures for Office 365 make managing email signatures a breeze.

Join & Write a Comment

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Not sure what the best email signature size is? Are you worried about email signature image size? Follow this best practice guide.
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now