Solved

Cannot get the sysvol folders to replicate between Domain Controllers

Posted on 2008-06-25
3
239 Views
Last Modified: 2011-10-19
I have 2 domain controllers communicating thru a Cisco site to site VPN tunnel.  One domain controller is on a 192.168.0.0 network and the other is on a 10.0.0.0 network. I have checked with Cisco and the VPN tunnel is working correctly.  I have DFS set up on both domain controllers and that seems to work fine.  I can also add and remove users from both domain controllers with no problem.  The problem I am having is the sysvol folders are not replicating.  I get errors when I run dcdiag and dcdiag /fix or netdiag /fix.  The error I get with dcdiag is:  

"Warning could not confirm the identity of this serverin the directory versus the name returned by the DNS servers.  If there are problems accessing this directory server then you may need to check that this server is correctly registered with DNS [servername] Directory binding error 5".  

I have registered the DNS server, I can ping both servers with no problem using "servername" and "servername.DNSsuffix" I checked the sysvol shares and they seem to have the correct permissions on them.  The sysvol has never replicated from the beginning.  
Any help would be appreciated.
0
Comment
Question by:Sandtoy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 38

Accepted Solution

by:
ChiefIT earned 500 total points
ID: 21871531
DFS is responsible for sharing Sysvol. It uses netbios broadcasts to do this. Netbios is a not routable protocol. So, you have to use WINS between your two lead site servers in order for DFS to share between them.

Non-routeable is defined as going over NAT, through a firewall or over a VPN tunnel.

Below is a picture of what it should look like and to confirm that DFS uses netbios please look at the following link:
http://www.microsoft.com/smallbusiness/support/articles/ref_net_ports_ms_prod.mspx

This pic explains how to set up the master browser service for a VPN. It too uses netbios broadcasts.
browser-interaction.JPG
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
In this video, viewers will be given step by step instructions on adjusting mouse, pointer and cursor visibility in Microsoft Windows 10. The video seeks to educate those who are struggling with the new Windows 10 Graphical User Interface. Change Cu…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question