Solved

Remote domain controller errors - not receiving updates via active directory

Posted on 2009-04-14
3
541 Views
Last Modified: 2012-05-06
I'm getting errors indicating that a remote domain controller has not been receiving updates via active directory.  The only thing different with this domain controller is that it is connected to the main network via an IPSEC VPN.
0
Comment
Question by:kahuna7
  • 2
3 Comments
 
LVL 1

Expert Comment

by:htam
ID: 24140766
Was it working before ?

Are using Site & Services to create a new site ?
Are you attaching each IP subnet to all site ?
Be sure to have an "Intersite-Site Transports" Rules betwen you site

You can try to report the exact error with SONAR
http://www.microsoft.com/downloads/details.aspx?FamilyID=158cb0fb-fe09-477c-8148-25ae02cf15d8&displaylang=en
0
 
LVL 2

Accepted Solution

by:
kahuna7 earned 500 total points
ID: 24149123
The answer was found after reading the open discussion area of the following thread   http://www.experts-exchange.com/Software/System_Utilities/Remote_Access/VPN/Q_22496206.html 

It appears that by default, the Windows Server Active Directory Replication will use UDP.  When using a VPN, a portion of the MTU of 1500 is taken up by overheat, leaving something like 1340 bytes available.  UDP will not fragment, so these packets never reach the remote domain controller.  There is a registry setting that will force Windows to use TCP instead.  TCP will fragment.
0
 
LVL 2

Author Closing Comment

by:kahuna7
ID: 31570503
This feels weird to award points to myself when the original thread gave me the impetus for the answer, but according to the close answer pop-up, this is how the answer and subsequent point assigning should be done.
0

Featured Post

Now Available: Firebox Cloud for AWS and FireboxV

Firebox Cloud brings the protection of WatchGuard’s leading Firebox UTM appliances to public cloud environments. It enables organizations to extend their security perimeter to protect business-critical assets in Amazon Web Services (AWS).

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question