DFSR replication Issue A security package specific error occurred

BrendanKing
BrendanKing used Ask the Experts™
on
Hey Guys.

Hope someone has an Idea about this.

Setting up DFSR between two servers. Both W2k3 R2 Member server, One a Virtual server running on Windows XP sp2. SBS Domain Controllor, Connected over IPsec Cisco VPN.

The setup of the DFSR all looks to work ok. I can even see the dsfrprivate folder being created at both the master and replication folder.

Yet I am gettting this error in Event log.

The DFS Replication service encountered an error communicating with partner MEL-VR01 for replication group domain.local\Data\sharedit.
 
Partner DNS address: mel-vr01.domain.local
 
Optional data if available:
Partner WINS Address: mel-vr01
Partner IP Address: 192.168.3.10
 
The service will retry the connection periodically.
 
Additional Information:
Error: 1825 (A security package specific error occurred.)
Connection ID: B0B13F7A-23E4-4FA6-AD63-BB76FC4663E3
Replication Group ID: ABECEFD9-0EE1-4B97-B172-2D7F0C9F5AEE

If I run DFSRdiag /syncnow I get this error.
The DFS Replication service encountered an error communicating with partner MEL-VR01 for replication group domain.local\incorp\sharedit.
 
Partner DNS address: mel-vr01.domain.local
 
Optional data if available:
Partner WINS Address: mel-vr01
Partner IP Address: 192.168.3.10
 
The service will retry the connection periodically.
 
Additional Information:
Error: 1825 (A security package specific error occurred.)
Connection ID: B0B13F7A-23E4-4FA6-AD63-BB76FC4663E3
Replication Group ID: ABECEFD9-0EE1-4B97-B172-2D7F0C9F5AEE

I have tried recreating the Replication folders a few times and changed the service to run under my Domain Admin account.

Does anyone have any Idea what could be the problem.

Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Distinguished Expert 2017

Commented:
Can you ping 192.168.3.10 and is it really the IP address of the DFSR partner mel-vr01?
I doubt that this is an issue with permissions on the folders.

Check the DFS tab in the properties of the maped drive to the share to see whether mel-vr01 is listed as available.

Author

Commented:
Hi Aronld

Yes I can ping 192.168.3.10 and it is the correct Static IP. I agree that it is unlikly to be a permissions issue. As the DFSRprivate folder is created.

I have check the DFS tab of the share and run a status. Both show as OK and are seen.

Any other Ideas.

C
Distinguished Expert 2017

Commented:
What events are being reported on mel-vr01?
If you look under the replication section of DFS management dealing with connections,  what is being reported there?  Access DFS management replication from both members.
Based on the name mel-vr01 is the virtual host.
Did you also try running the dfsrdiag /syncnow directive on the mel-vr01 system?

Author

Commented:
Hi Arnold.

Under DFS management/Replication I get the namespace show
domain\data\test-dfsr (New Namespace I created)
Membership
d:\data\firstfolder member fs01
c:\data\firstfoler member mel-vr01
connections
fs01 default-1st enable mel-vr91
mel-vr01 default-1st fs01

If I run dfsrdiag /syncnow /RGname:domain\data\test-dfsr  in melbourne or sydney I get sync successful.

Yet the sub folder is not updated.

I did notice that if I go to \\domain\data\firstfolder I looks like I am connecting to the Melbourne server even if I am in the sydney domain.

errors in eventlog are
The DFS Replication service failed to communicate with partner MEL-VR01 for replication group domain.local\data\test-dfsr. This error can occur if the host is unreachable, or if the DFS Replication service is not running on the server.
 
Partner DNS Address: mel-vr01.domain.local
 
Optional data if available:
Partner WINS Address: mel-vr01
Partner IP Address: 192.168.3.10
 
The service will retry the connection periodically.
 
Additional Information:
Error: 1722 (The RPC server is unavailable.)
Connection ID: B322ACA0-E2D1-48A6-A3B2-70F01396F5F8
Replication Group ID: 4E6675BA-44F5-435F-8089-03D6B3DA0A83

For more information, see Help and Support Center at

This is the errors I get with a dns report

 Communication errors are preventing replication with partner MEL-VR01.  
  Affected replicated folders: All replicated folders on this server.
  Description: DFS Replication cannot replicate with partner MEL-VR01 due to a communication error. This error can occur if the host is unreachable, or if the DFS Replication service is not running on the server. The DFS Replication service used partner DNS name mel-vr01.domain.local, IP address 192.168.3.10, and WINS address mel-vr01 but failed with error ID: 1722 (The RPC server is unavailable.). Event ID: 5008
  Last occurred: Wednesday, 7 January 2009 at 1:57:50 PM (GMT10:00)
  Suggested action: Check for network connectivity and service related problems. For troubleshooting RPC issues see RPC KB 839880 and for additional troubleshooting information, see The Microsoft Web Site.  




Ok just worked out the problem.

The issue was that the Virtual machine was running on a Window XP sp2 box that had windows Firewall enabled.

I ran DFSRdiag staticrpc:3000 to set the port to 3000
Then allow both TCP 143 and 3000 through the firstwall. Now replication is working.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial