Solved

Remote domain controller errors - not receiving updates via active directory

Posted on 2009-04-14
3
538 Views
Last Modified: 2012-05-06
I'm getting errors indicating that a remote domain controller has not been receiving updates via active directory.  The only thing different with this domain controller is that it is connected to the main network via an IPSEC VPN.
0
Comment
Question by:kahuna7
  • 2
3 Comments
 
LVL 1

Expert Comment

by:htam
ID: 24140766
Was it working before ?

Are using Site & Services to create a new site ?
Are you attaching each IP subnet to all site ?
Be sure to have an "Intersite-Site Transports" Rules betwen you site

You can try to report the exact error with SONAR
http://www.microsoft.com/downloads/details.aspx?FamilyID=158cb0fb-fe09-477c-8148-25ae02cf15d8&displaylang=en
0
 
LVL 2

Accepted Solution

by:
kahuna7 earned 500 total points
ID: 24149123
The answer was found after reading the open discussion area of the following thread   http://www.experts-exchange.com/Software/System_Utilities/Remote_Access/VPN/Q_22496206.html 

It appears that by default, the Windows Server Active Directory Replication will use UDP.  When using a VPN, a portion of the MTU of 1500 is taken up by overheat, leaving something like 1340 bytes available.  UDP will not fragment, so these packets never reach the remote domain controller.  There is a registry setting that will force Windows to use TCP instead.  TCP will fragment.
0
 
LVL 2

Author Closing Comment

by:kahuna7
ID: 31570503
This feels weird to award points to myself when the original thread gave me the impetus for the answer, but according to the close answer pop-up, this is how the answer and subsequent point assigning should be done.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
Synchronize a new Active Directory domain with an existing Office 365 tenant
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now