Solved

FRS DIAG ISSUES

Posted on 2010-09-13
29
1,393 Views
Last Modified: 2012-05-10
Having issues with mixed Server OS's 2003 R2 and 2008 R2 with FRS Diag: The was working pretty well before. All servers were demoted except DC3 then brought back up over 3 day weeekend. All were working with no errors untill several days later, presumably afterl replications finally completed. Now its a mess. I cannot seem to get a fix on the cause(s). repadmin /showrepl shows everything replicating correctly. SPN's all appear to be correct. as well. Can anyone give me a clue on this one. I'm to close to itand tired and am beating my head against the wall out of frustration.  DC2-3 are 2008 R2 all else are 2003 R2.
Thanks...

DC1
NtFrs      9/5/2010 8:02:36 PM      Warning      13508      The File Replication Service is having trouble enabling replication  from DC3 to DC1for c:\windows\sysvol\domain using the DNS name DC3.domain.com. FRS will keep retrying.     Following are some of the reasons you would see this warning.         [1] FRS can not correctly resolve the DNS name DC3.domain.com from this computer.     [2] FRS is not running on DC3.domain.com.     [3] The topology information in the Active Directory for this replica has not  yet replicated to all the Domain Controllers.         This event log message will appear once per connection, After the problem  is fixed you will see another event log message indicating that the connection  has been established.
      WARNING: Found Event ID 13508 errors without trailing 13509 ... see above for (up to) the 3 latest entries!

DC2
NTDS Replication      9/6/2010 1:02:36 PM      Error      1645      Active Directory did not perform an authenticated remote procedure call (RPC) to another domain controller because the desired service principal name (SPN) for the destination domain controller is not registered on the Key Distribution Center (KDC) domain controller that resolves the SPN.        Destination domain controller:  50ecd707-d579-41e0-b220-1ac48dfcba76._msdcs.domain.com    SPN:  E3514235-4B06-11D1-AB04-00C04FC2DCD2/50ecd707-d579-41e0-b220-1ac48dfcba76/domain.com@domain.com        User Action    Verify that the names of the destination domain controller and domain are correct. Also, verify that the SPN is registered on the KDC domain controller. If the destination domain controller has been recently promoted, it will be necessary for the local domain controller’s computer account data to replicate to the KDC before this computer can be authenticated.
      WARNING: Found Directory Service Errors in the past 15 days! FRS Depends on AD so Check AD Replication!

DC3
NtFrs      9/7/2010 9:31:57 PM      Warning      13508      The File Replication Service is having trouble enabling replication  from DC4 to DC3 for c:\windows\sysvol\domain using the DNS name DC4.domain.com. FRS will keep retrying.     Following are some of the reasons you would see this warning.         [1] FRS can not correctly resolve the DNS name DC4.domain.com from this computer.     [2] FRS is not running on DC4.domain.com.     [3] The topology information in the Active Directory for this replica has not  yet replicated to all the Domain Controllers.         This event log message will appear once per connection, After the problem  is fixed you will see another event log message indicating that the connection  has been established.
      WARNING: Found Event ID 13508 errors without trailing 13509 ... see above for (up to) the 3 latest entries!

 ......... failed 1
Checking for errors in Directory Service Event Log ....       
NTDS Replication      9/10/2010 11:29:16 AM      Error      1791      Replication of Naming Context DC=domain,DC=org from source f7cab657-9f79-4b00-be4f-91735ec9cbc0 (DC5.domain.com) has been aborted.  Replication requires consistent schema but last attempt to sync  the schema had failed. It is crucial that schema replication  functions properly. See previous errors for more diagnostics.  If this issue persists, please contact Microsoft Product DC4  Services for assistance.  Error 8418: The replication operation failed because of a schema mismatch between the servers involved..      
NTDS Replication      9/10/2010 11:29:16 AM      Error      1791      Replication of Naming Context DC=DomainDnsZones,DC=domain,DC=org from source f7cab657-9f79-4b00-be4f-91735ec9cbc0 (DC5.domain.com) has been aborted.  Replication requires consistent schema but last attempt to sync  the schema had failed. It is crucial that schema replication  functions properly. See previous errors for more diagnostics.  If this issue persists, please contact Microsoft Product DC4  Services for assistance.  Error 8418: The replication operation failed because of a schema mismatch between the servers involved..      
NTDS Replication      9/10/2010 11:26:37 AM      Error      1791      Replication of Naming Context DC=domain,DC=org from source f7cab657-9f79-4b00-be4f-91735ec9cbc0 (DC5.domain.com) has been aborted.  Replication requires consistent schema but last attempt to sync  the schema had failed. It is crucial that schema replication  functions properly. See previous errors for more diagnostics.  If this issue persists, please contact Microsoft Product DC4  Services for assistance.  Error 8418: The replication operation failed because of a schema mismatch between the servers involved..      
NTDS General      9/5/2010 12:16:45 AM      Error      1311      The Knowledge Consistency Checker (KCC) has detected problems with the following directory partition.        Directory partition:  CN=Configuration,DC=domain,DC=org        There is insufficient site connectivity information in Active Directory Sites and Services for the KCC to create a spanning tree replication topology. Or, one or more domain controllers with this directory partition are unable to replicate the directory partition information. This is probably due to inaccessible domain controllers.        User Action    Use Active Directory Sites and Services to perform one of the following actions:    - Publish sufficient site connectivity information so that the KCC can determine a route by which this directory partition can reach this site. This is the preferred option.    - Add a Connection object to a domain controller that contains the directory partition in this site from a domain controller that contains the same directory partition in another site.        If neither of the Active Directory Sites and Services tasks correct this condition, see previous events logged by the KCC that identify the inaccessible domain controllers.      
NTDS General      9/5/2010 12:16:45 AM      Error      1311      The Knowledge Consistency Checker (KCC) has detected problems with the following directory partition.        Directory partition:  DC=ForestDnsZones,DC=domain,DC=org        There is insufficient site connectivity information in Active Directory Sites and Services for the KCC to create a spanning tree replication topology. Or, one or more domain controllers with this directory partition are unable to replicate the directory partition information. This is probably due to inaccessible domain controllers.        User Action    Use Active Directory Sites and Services to perform one of the following actions:    - Publish sufficient site connectivity information so that the KCC can determine a route by which this directory partition can reach this site. This is the preferred option.    - Add a Connection object to a domain controller that contains the directory partition in this site from a domain controller that contains the same directory partition in another site.        If neither of the Active Directory Sites and Services tasks correct this condition, see previous events logged by the KCC that identify the inaccessible domain controllers.      
NTDS General      9/5/2010 12:16:45 AM      Error      1311      The Knowledge Consistency Checker (KCC) has detected problems with the following directory partition.        Directory partition:  DC=DomainDnsZones,DC=domain,DC=org        There is insufficient site connectivity information in Active Directory Sites and Services for the KCC to create a spanning tree replication topology. Or, one or more domain controllers with this directory partition are unable to replicate the directory partition information. This is probably due to inaccessible domain controllers.        User Action    Use Active Directory Sites and Services to perform one of the following actions:    - Publish sufficient site connectivity information so that the KCC can determine a route by which this directory partition can reach this site. This is the preferred option.    - Add a Connection object to a domain controller that contains the directory partition in this site from a domain controller that contains the same directory partition in another site.        If neither of the Active Directory Sites and Services tasks correct this condition, see previous events logged by the KCC that identify the inaccessible domain controllers.      
NTDS General      9/5/2010 12:16:45 AM      Error      1311      The Knowledge Consistency Checker (KCC) has detected problems with the following directory partition.        Directory partition:  DC=domain,DC=org        There is insufficient site connectivity information in Active Directory Sites and Services for the KCC to create a spanning tree replication topology. Or, one or more domain controllers with this directory partition are unable to replicate the directory partition information. This is probably due to inaccessible domain controllers.        User Action    Use Active Directory Sites and Services to perform one of the following actions:    - Publish sufficient site connectivity information so that the KCC can determine a route by which this directory partition can reach this site. This is the preferred option.    - Add a Connection object to a domain controller that contains the directory partition in this site from a domain controller that contains the same directory partition in another site.        If neither of the Active Directory Sites and Services tasks correct this condition, see previous events logged by the KCC that identify the inaccessible domain controllers.      
NTDS General      9/5/2010 12:01:45 AM      Error      1311      The Knowledge Consistency Checker (KCC) has detected problems with the following directory partition.        Directory partition:  CN=Configuration,DC=domain,DC=org        There is insufficient site connectivity information in Active Directory Sites and Services for the KCC to create a spanning tree replication topology. Or, one or more domain controllers with this directory partition are unable to replicate the directory partition information. This is probably due to inaccessible domain controllers.        User Action    Use Active Directory Sites and Services to perform one of the following actions:    - Publish sufficient site connectivity information so that the KCC can determine a route by which this directory partition can reach this site. This is the preferred option.    - Add a Connection object to a domain controller that contains the directory partition in this site from a domain controller that contains the same directory partition in another site.        If neither of the Active Directory Sites and Services tasks correct this condition, see previous events logged by the KCC that identify the inaccessible domain controllers.      
NTDS General      9/5/2010 12:01:45 AM      Error      1311      The Knowledge Consistency Checker (KCC) has detected problems with the following directory partition.        Directory partition:  DC=ForestDnsZones,DC=domain,DC=org        There is insufficient site connectivity information in Active Directory Sites and Services for the KCC to create a spanning tree replication topology. Or, one or more domain controllers with this directory partition are unable to replicate the directory partition information. This is probably due to inaccessible domain controllers.        User Action    Use Active Directory Sites and Services to perform one of the following actions:    - Publish sufficient site connectivity information so that the KCC can determine a route by which this directory partition can reach this site. This is the preferred option.    - Add a Connection object to a domain controller that contains the directory partition in this site from a domain controller that contains the same directory partition in another site.        If neither of the Active Directory Sites and Services tasks correct this condition, see previous events logged by the KCC that identify the inaccessible domain controllers.      
NTDS General      9/5/2010 12:01:45 AM      Error      1311      The Knowledge Consistency Checker (KCC) has detected problems with the following directory partition.        Directory partition:  DC=DomainDnsZones,DC=domain,DC=org        There is insufficient site connectivity information in Active Directory Sites and Services for the KCC to create a spanning tree replication topology. Or, one or more domain controllers with this directory partition are unable to replicate the directory partition information. This is probably due to inaccessible domain controllers.        User Action    Use Active Directory Sites and Services to perform one of the following actions:    - Publish sufficient site connectivity information so that the KCC can determine a route by which this directory partition can reach this site. This is the preferred option.    - Add a Connection object to a domain controller that contains the directory partition in this site from a domain controller that contains the same directory partition in another site.        If neither of the Active Directory Sites and Services tasks correct this condition, see previous events logged by the KCC that identify the inaccessible domain controllers.      
NTDS General      9/5/2010 12:01:45 AM      Error      1311      The Knowledge Consistency Checker (KCC) has detected problems with the following directory partition.        Directory partition:  DC=domain,DC=org        There is insufficient site connectivity information in Active Directory Sites and Services for the KCC to create a spanning tree replication topology. Or, one or more domain controllers with this directory partition are unable to replicate the directory partition information. This is probably due to inaccessible domain controllers.        User Action    Use Active Directory Sites and Services to perform one of the following actions:    - Publish sufficient site connectivity information so that the KCC can determine a route by which this directory partition can reach this site. This is the preferred option.    - Add a Connection object to a domain controller that contains the directory partition in this site from a domain controller that contains the same directory partition in another site.        If neither of the Active Directory Sites and Services tasks correct this condition, see previous events logged by the KCC that identify the inaccessible domain controllers.
      WARNING: Found Directory Service Errors in the past 15 days! FRS Depends on AD so Check AD Replication!

 ......... failed 11
Checking for minimum FRS version requirement ... passed
Checking for errors/warnings in ntfrsutl ds ... passed
Checking for Replica Set configuration triggers... passed
Checking for suspicious file Backlog size... passed
Checking Overall Disk Space and SYSVOL structure (note: integrity is not checked)... passed
Checking for suspicious inlog entries ... passed
Checking for suspicious outlog entries ... passed
Checking for appropriate staging area size ... passed
Checking for errors in debug logs ...
      ERROR on NtFrs_0001.log : "RPC_S_CALL_FAILED_DNE(Indicates RPC Session was established to target, but there was a failure to send RPC call package. Check for Networking problems!)" : <SndCsMain:                     6760:   883: S0: 05:00:21> ++ ERROR - EXCEPTION (000006bf) :  WStatus: RPC_S_CALL_FAILED_DNE
      ERROR on NtFrs_0001.log : "RPC_S_CALL_FAILED_DNE(Indicates RPC Session was established to target, but there was a failure to send RPC call package. Check for Networking problems!)" : <SndCsMain:                     6760:   884: S0: 05:00:21> :SR: Cmd 12716f80, CxtG efb7a625, WS RPC_S_CALL_FAILED_DNE, To   DC4.domain.com Len:  (374) [SndFail - rpc exception]
      ERROR on NtFrs_0001.log : "RPC_S_CALL_FAILED_DNE(Indicates RPC Session was established to target, but there was a failure to send RPC call package. Check for Networking problems!)" : <SndCsMain:                     6760:   904: S0: 05:00:21> :SR: Cmd 12716f80, CxtG efb7a625, WS RPC_S_CALL_FAILED_DNE, To   DC4.domain.com Len:  (374) [SndFail - Send Penalty]

      Found 3 RPC_S_CALL_FAILED_DNE error(s)! Latest ones (up to 3) listed above

DC4
ONLY ONE PASSING

DC5
Checking for errors in debug logs ...
      ERROR on NtFrs_0004.log : "ERROR_ACCESS_DENIED" : <SndCsMain:                     5832:   904: S0: 00:36:08> :SR: Cmd 0152a9d0, CxtG 7a31f797, WS ERROR_ACCESS_DENIED, To   DC2.domain.com Len:  (372) [SndFail - Send Penalty]
      ERROR on NtFrs_0004.log : "ERROR_ACCESS_DENIED" : <SndCsMain:                     5832:   877: S0: 00:37:34> :SR: Cmd 01539168, CxtG 7a31f797, WS ERROR_ACCESS_DENIED, To   DC2.domain.com Len:  (372) [SndFail - rpc call]
      ERROR on NtFrs_0004.log : "ERROR_ACCESS_DENIED" : <SndCsMain:                     5832:   904: S0: 00:37:34> :SR: Cmd 01539168, CxtG 7a31f797, WS ERROR_ACCESS_DENIED, To   DC2.domain.com Len:  (372) [SndFail - Send Penalty]
0
Comment
Question by:Lazarus
  • 15
  • 12
29 Comments
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
Make sure all DCs are pointing to internal DNS servers only in their TCP\IP settings.

The burflag method is an option.

Stopped NTFRS service on both DCs.
Make one of the DC authoritative server by modifying registry setting : Navigate to registry HKLM\System\CCS\Services\NTFRS\Parameters\CumlativeReplicaSets and Set the Burflags value to D4. This should be done with server which has the Updated information available or correct data.
Go to other DC and make that Non-authoritative by navigating to same registry location HKLM\System\CCS\Services\NTFRS\Parameters\CumlativeReplicaSets and Set the Burflags value to D2.
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
Now to make sure your talking teh same lingo. Your talking,  point Preferred DNS server to self correct? Which I am already doing.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
Yes.

Run dcdiag
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
I have run DCDIAG on all of them. All passing, with the exception of systemlogs, which is not abnormal really and DC3 not passing Advertising.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
DC03 is not passing what advertising Time? Or could be that DC3 is not advertising as a DC as well.

You can clear your syslogs to see if new ones populate
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
I didnt really understand that. Can you perhaps rephrase? Also clear which logs? System Event logs or which?
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
DCDIAG.txt file attached if that helps.

dcdiag.txt
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
You are passing everything. Are you getting new errors in the Event logs?
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
No, I'm just getting the errors in FRSDIAG. I did find that there were a couple of DNS issues, minor though. No Zone transfers betwwen DNS Servers. Also a slightly off DHCP Setting. But no others reaslly. Waiting for a bit before I rerun FRSDIAG again.
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
Still even after fixing what seemed very minor, FRSDIAG has not change. I still have the issues above.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
What errors are you gettingin FRSDIAG. Run repadmin /syncall.
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
Ive already run "repadmin /syncall" The errors I'm getting in FRSDIAG are all pasted above.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
Those could be old errors. What are the results from repadmin /syncall
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
I get no errors on it, from any dc.
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
Looks like you are ok there was an issue in the pass but I don't see any current issues FRSDIAG looks at your logs which can be very old logs.
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
ok, so what can I do to see if they are passing now? Do I need to delete all my logs the rerun FRS?
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
Are you getting any errors in the Event viewer now?
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
I still get a 13508 on DC1, 1791 and 1311 on DC3 and 5832 on DC5, DC2 and DC4 pass
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
You might are going to have to demote DC3 then repromote
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
I'll have to try that, but it will be next week before I can attempt it.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
Once you demote run metadata cleanup to make sure you don't have any lingering objects
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
ok after trying to clean a tad more up.

DC1 - 1 error, 13508.
DC2 - 4 errors, 13508 and 1791 which points at replication on DC5.
DC3 - passes
DC4 - passes
DC5 - 70 errors, 5832 access denied to DC3.

I have tried in site and services to deleted and let it rebuild the link which it does but seems to be no help.
After looking at these errors do you still think DC3 needs rebuilt, sices it passes? I would think there are other things to do?
0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 500 total points
Comment Utility
Seems like DC5 has a bunch of issues.

Do this with DC5.

Stopped NTFRS service on both DCs.
Make one of the DC authoritative server by modifying registry setting : Navigate to registry HKLM\System\CCS\Services\NTFRS\Parameters\CumlativeReplicaSets and Set the Burflags value to D4. This should be done with server which has the Updated information available or correct data.
Go to other DC and make that Non-authoritative by navigating to same registry location HKLM\System\CCS\Services\NTFRS\Parameters\CumlativeReplicaSets and Set the Burflags value to D2.
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
Shouldnt that be Stop NTFRS on ALL DCs? make one of the passing DCs a burflag D4, then all others D2?
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
Just the ones you are going to place the burflag in
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
I must mis-understand then how the burflag works. I had thought that by setting D4 on the one that it would affect ALL DCs, not just the one with D2.
0
 
LVL 20

Author Comment

by:Lazarus
Comment Utility
Sorry, this had forgoten.
0
 
LVL 68

Expert Comment

by:Qlemo
Comment Utility
This question has been classified as abandoned and is being closed as part of the Cleanup Program. See my comment at the end of the question for more details.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now