2008 R2 DC replication issues

KratosDefense
KratosDefense used Ask the Experts™
on
Im having some win2008 replication issues as follows:
I have a DC on the east coast called dt-2k8dc01 (2008 R2)
It replicates to my 2008 R2 DC’s in San Diego called: sd-ktosdc01 & sd-ktosdc02.
The San Deigo DC replicate to DT-2k8dc01 just fine; however, changes on dt-2k8dc01 replication to San Diego takes up to 3 hours.
All unplugged Nics are disabled. Only sd-ktosdc02 has R2 load balancing.
The DNS Server service & the Intersite Messaging service on dt-2k8dc01 stop after reboot. Both start up with no error If I manually start them. The DNS Event logs are clean.
Im getting event 2087 below. Any ideas?
I have event error:
Log Name:      Directory Service
Source:        Microsoft-Windows-ActiveDirectory_DomainService
Date:          10/16/2010 12:59:11 PM
Event ID:      2087
Task Category: DS RPC Client
Level:         Error
Keywords:      Classic
User:          ANONYMOUS LOGON
Computer:      DT-2K8DC01.kratos.us
Description:
Active Directory Domain Services could not resolve the following DNS host name of the source domain controller to an IP address. This error prevents additions, deletions and changes in Active Directory Domain Services from replicating between one or more domain controllers in the forest. Security groups, group policy, users and computers and their passwords will be inconsistent between domain controllers until this error is resolved, potentially affecting logon authentication and access to network resources.
 
Source domain controller:
 hou-2k3dc01
Failing DNS host name:
 e4ef0e1c-c055-41ba-85aa-cba2df58f942._msdcs.wfinet.com
 
NOTE: By default, only up to 10 DNS failures are shown for any given 12 hour period, even if more than 10 failures occur.  To log all individual failure events, set the following diagnostics registry value to 1:
 
Registry Path:
HKLM\System\CurrentControlSet\Services\NTDS\Diagnostics\22 DS RPC Client
 
User Action:
 
 1) If the source domain controller is no longer functioning or its operating system has been reinstalled with a different computer name or NTDSDSA object GUID, remove the source domain controller's metadata with ntdsutil.exe, using the steps outlined in MSKB article 216498.
 
 2) Confirm that the source domain controller is running Active Directory Domain Services and is accessible on the network by typing "net view \\<source DC name>" or "ping <source DC name>".
 
 3) Verify that the source domain controller is using a valid DNS server for DNS services, and that the source domain controller's host record and CNAME record are correctly registered, using the DNS Enhanced version of DCDIAG.EXE available on http://www.microsoft.com/dns 
 
  dcdiag /test:dns
 
 4) Verify that this destination domain controller is using a valid DNS server for DNS services, by running the DNS Enhanced version of DCDIAG.EXE command on the console of the destination domain controller, as follows:
 
  dcdiag /test:dns
 
 5) For further analysis of DNS error failures see KB 824449:
   http://support.microsoft.com/?kbid=824449
 
Additional Data
Error value:
 11004 The requested name is valid, but no data of the requested type was found.

Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®

Author

Commented:
C:\Users\jrouse>dcdiag /test:dns

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = DT-2K8DC01
   * Identified AD Forest.
   Ldap search capabality attribute search failed on server ELP-2K3DC01, return
   value = 81
   Got error while checking if the DC is using FRS or DFSR. Error:
   Win32 Error 81The VerifyReferences, FrsEvent and DfsrEvent tests might fail
   because of this error.
   Done gathering initial info.

Doing initial required tests

   Testing server: KGS-DALLASTOWN\DT-2K8DC01
      Starting test: Connectivity
         ......................... DT-2K8DC01 passed test Connectivity

Doing primary tests

   Testing server: KGS-DALLASTOWN\DT-2K8DC01

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... DT-2K8DC01 passed test DNS

   Running partition tests on : DomainDnsZones

   Running partition tests on : kratos

   Running partition tests on : ForestDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running enterprise tests on : wfinet.com
      Starting test: DNS
         ......................... wfinet.com passed test DNS

C:\Users\jrouse>

Author

Commented:
C:\Users\jrouse>dcdiag

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = DT-2K8DC01
   * Identified AD Forest.
   Ldap search capabality attribute search failed on server ELP-2K3DC01, return
   value = 81
   Got error while checking if the DC is using FRS or DFSR. Error:
   Win32 Error 81The VerifyReferences, FrsEvent and DfsrEvent tests might fail
   because of this error.
   Done gathering initial info.

Doing initial required tests

   Testing server: KGS-DALLASTOWN\DT-2K8DC01
      Starting test: Connectivity
         ......................... DT-2K8DC01 passed test Connectivity

Doing primary tests

   Testing server: KGS-DALLASTOWN\DT-2K8DC01
      Starting test: Advertising
         ......................... DT-2K8DC01 passed test Advertising
      Starting test: FrsEvent
         ......................... DT-2K8DC01 passed test FrsEvent
      Starting test: DFSREvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... DT-2K8DC01 failed test DFSREvent
      Starting test: SysVolCheck
         ......................... DT-2K8DC01 passed test SysVolCheck
      Starting test: KccEvent
         ......................... DT-2K8DC01 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... DT-2K8DC01 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... DT-2K8DC01 passed test MachineAccount
      Starting test: NCSecDesc
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=ForestDnsZones,DC=wfinet,DC=com
         ......................... DT-2K8DC01 failed test NCSecDesc
      Starting test: NetLogons
         ......................... DT-2K8DC01 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... DT-2K8DC01 passed test ObjectsReplicated
      Starting test: Replications
         ......................... DT-2K8DC01 passed test Replications
      Starting test: RidManager
         ......................... DT-2K8DC01 passed test RidManager
      Starting test: Services
         ......................... DT-2K8DC01 passed test Services
      Starting test: SystemLog
         A warning event occurred.  EventID: 0x000003F6
            Time Generated: 10/16/2010   14:37:46
            Event String:
            Name resolution for the name kratos.us timed out after none of the c
onfigured DNS servers responded.
         ......................... DT-2K8DC01 passed test SystemLog
      Starting test: VerifyReferences
         ......................... DT-2K8DC01 passed test VerifyReferences


   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : kratos
      Starting test: CheckSDRefDom
         ......................... kratos passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... kratos passed test CrossRefValidation

   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running enterprise tests on : wfinet.com
      Starting test: LocatorCheck
         ......................... wfinet.com passed test LocatorCheck
      Starting test: Intersite
         ......................... wfinet.com passed test Intersite

C:\Users\jrouse>

Author

Commented:
C:\Users\jrouse>repadmin /showreps
KGS-DALLASTOWN\DT-2K8DC01
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 6bbfe16f-99bc-475e-81e1-69ef6289fbdb
DSA invocationID: 37d03879-5099-4916-ac6a-2b6356a483a7

==== INBOUND NEIGHBORS ======================================

CN=Configuration,DC=wfinet,DC=com
    ENS-HOUSTON\HOU-2K3DC01 via RPC
        DSA object GUID: e4ef0e1c-c055-41ba-85aa-cba2df58f942
        Last attempt @ 2010-10-16 14:47:16 was successful.
    WFINET\SD-KTOSDC02 via RPC
        DSA object GUID: 62747a33-2679-4f8b-a49e-cac79c5f9661
        Last attempt @ 2010-10-16 14:47:17 was successful.

CN=Schema,CN=Configuration,DC=wfinet,DC=com
    ENS-HOUSTON\HOU-2K3DC01 via RPC
        DSA object GUID: e4ef0e1c-c055-41ba-85aa-cba2df58f942
        Last attempt @ 2010-10-16 14:47:18 was successful.
    WFINET\SD-KTOSDC02 via RPC
        DSA object GUID: 62747a33-2679-4f8b-a49e-cac79c5f9661
        Last attempt @ 2010-10-16 14:47:18 was successful.

DC=ForestDnsZones,DC=wfinet,DC=com
    ENS-HOUSTON\HOU-2K3DC01 via RPC
        DSA object GUID: e4ef0e1c-c055-41ba-85aa-cba2df58f942
        Last attempt @ 2010-10-16 14:47:18 was successful.
    WFINET\SD-KTOSDC02 via RPC
        DSA object GUID: 62747a33-2679-4f8b-a49e-cac79c5f9661
        Last attempt @ 2010-10-16 14:47:18 was successful.

DC=kratos,DC=us
    WFINET\SD-KTOSDC02 via RPC
        DSA object GUID: 62747a33-2679-4f8b-a49e-cac79c5f9661
        Last attempt @ 2010-10-16 14:47:18 was successful.

DC=DomainDnsZones,DC=kratos,DC=us
    WFINET\SD-KTOSDC02 via RPC
        DSA object GUID: 62747a33-2679-4f8b-a49e-cac79c5f9661
        Last attempt @ 2010-10-16 14:47:19 was successful.

DC=wfinet,DC=com
    ENS-HOUSTON\HOU-2K3DC01 via RPC
        DSA object GUID: e4ef0e1c-c055-41ba-85aa-cba2df58f942
        Last attempt @ 2010-10-16 14:47:19 was successful.
    WFINET\SD-KTOSDC02 via RPC
        DSA object GUID: 62747a33-2679-4f8b-a49e-cac79c5f9661
        Last attempt @ 2010-10-16 14:47:19 was successful.

Source: ENS-HOUSTON\HOU-2K3DC01
******* 1 CONSECUTIVE FAILURES since 2010-10-16 10:59:14
Last error: 1256 (0x4e8):
            The remote system is not available. For information about network
oubleshooting, see Windows Help.
Should you be charging more for IT Services?

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Commented:
HI, I see you are still having problems with replication today.

Can you try this.
PIng this host

e4ef0e1c-c055-41ba-85aa-cba2df58f942._msdcs.wfinet.com

See what the results are


Look in your _msdcs DNS zone and see if there are any duplicate records for any DCs and make sure there is one for every DC.

In you Domain zone with the 3 2k8 servers make sure there is only one record for each DC and verify they are correct. Leave the ones that say "Same as Parent alone for now)

Then go to the properties of the zone and click on name servers. Make sure only the DNS servers for that domain are listed and the IP address for them is correct.



Author

Commented:
Ken, Good to have you back. Yes issues still happening. I can ping e4ef0e1c-c055-41ba-85aa-cba2df58f942._msdcs.wfinet.com, it resolves to Hou-2k3dc01 which is a windows 2003 DC in the WFINET domain! Keeping in mind the DC were working on are in the Kratos.us domain.

2nd. There are 4 win2008 DC in the kratos.us domain: sd-ktosdc01, sd-ktosdc02, dt-2k8dc01, chs-2k8dc01.
Im attaching screen shot of _msdcs. Is this the right location.

3rd: I had all the names servers in both domain in the in the properties of the Kratos.us Zone. Could that be the problem? I took all the other names servers from wfinet.com out and just left the 4 kratos.us name servers - See before and after screen shots of DNS


DNS.jpg
dns2.jpg
dns3.jpg

Author

Commented:
Im guessing that all the name servers were in the kratos.us zone becouse i copied a wfinet zone (as a secondary) to dt-2k8dc01.kratos.us. Should I not copy zones from different domains and just use forwarders?

Author

Commented:
C:\Users\jrouse>dcdiag

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = DT-2K8DC01
   * Identified AD Forest.
   Ldap search capabality attribute search failed on server ELP-2K3DC01, return
   value = 81
   Got error while checking if the DC is using FRS or DFSR. Error:
   Win32 Error 81The VerifyReferences, FrsEvent and DfsrEvent tests might fail
   because of this error.
   Done gathering initial info.

Doing initial required tests

   Testing server: KGS-DALLASTOWN\DT-2K8DC01
      Starting test: Connectivity
         ......................... DT-2K8DC01 passed test Connectivity

Doing primary tests

   Testing server: KGS-DALLASTOWN\DT-2K8DC01
      Starting test: Advertising
         ......................... DT-2K8DC01 passed test Advertising
      Starting test: FrsEvent
         ......................... DT-2K8DC01 passed test FrsEvent
      Starting test: DFSREvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... DT-2K8DC01 failed test DFSREvent
      Starting test: SysVolCheck
         ......................... DT-2K8DC01 passed test SysVolCheck
      Starting test: KccEvent
         ......................... DT-2K8DC01 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... DT-2K8DC01 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... DT-2K8DC01 passed test MachineAccount
      Starting test: NCSecDesc
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=ForestDnsZones,DC=wfinet,DC=com
         ......................... DT-2K8DC01 failed test NCSecDesc
      Starting test: NetLogons
         ......................... DT-2K8DC01 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... DT-2K8DC01 passed test ObjectsReplicated
      Starting test: Replications
         ......................... DT-2K8DC01 passed test Replications
      Starting test: RidManager
         ......................... DT-2K8DC01 passed test RidManager
      Starting test: Services
         ......................... DT-2K8DC01 passed test Services
      Starting test: SystemLog
         ......................... DT-2K8DC01 passed test SystemLog
      Starting test: VerifyReferences
         ......................... DT-2K8DC01 passed test VerifyReferences


   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : kratos
      Starting test: CheckSDRefDom
         ......................... kratos passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... kratos passed test CrossRefValidation

   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running enterprise tests on : wfinet.com
      Starting test: LocatorCheck
         ......................... wfinet.com passed test LocatorCheck
      Starting test: Intersite
         ......................... wfinet.com passed test Intersite

C:\Users\jrouse>

Author

Commented:
Still having the same issue... Ken what do you think? anyone?

Commented:
Looking through all this now. I would recomend to not have copies of zones but just use forwaders.

THe replications errrors are for this
e4ef0e1c-c055-41ba-85aa-cba2df58f942._msdcs.wfinet.com

so if you can ping it are there any firewalls in plcae that would be blovking other ports?

Author

Commented:
yes there would be; however, what port should I be looking for? I tested some ports that were in the KB article you provided with success. Is there a particular port I should focus on?

Commented:
Not sure if this is the same link I sent before. But all ports in this link. The one most secuirty teams do not link is everything over 1024 for the dynamic rpc.

http://technet.microsoft.com/en-us/library/bb727063.aspx

Author

Commented:
ok, I will run some test in 1 hour. BTW, the dns server service does not start after a reboot. any thoughts on that?

Commented:
Not sure about the DNS server service. THere are no errros in the event logs, correct? Can you try to set it to automatic delayed start and see if that helps?

Author

Commented:
Just one more quick thought. If a required port was blocked, wouldn't that cause replication to fail all together? Replication seems to work, it just takes 3 hours for it to do so.... Food for thought

J

Commented:
It really depends on how your connection obejcts are setup in AD.

Author

Commented:
can you elaborate on that? site links?

Commented:
Site links and the connections objects under the NTDS settings in S&S.
Make sure the correct SItes are in the site links.
Make sure that all the connection objects are automatically configured and there are no manual ones unless there is a specific reason they are manual.

Author

Commented:
Site question.
The kratos.us domain has  4 win2008 DC’s. The WFINET domain has 18 win2k3 DC’s.  Kratos DC's are in the same site at the WFINET DC’s. Is that a problem? Should they be in their own separate site considering they are in a different domain?
Also, the kratos.us  2008 DC’s have auto connection (site links) setup to the WFINET 2k3 DC’s. these are 2 separate domain under the same forest with a 2 way trust. Should they have links between them?
?

Author

Commented:
The kratos DC's that having the issues has only one auto connection site link setup to a wfinet DC.... I had to setup manual site links to the kratos DC's it suppose to talk too. Could this be the issue? could the Kratos.us  DC in question be trying to replicate with the a WFINET.com DC and getting denied because they are different domain, and if so taking a couple hours to try the manually setup site links to the correct kratos.us DCs?

Just a thought?

Commented:
sites go by the subnets setup in AD. So since all these servers are in the same AD forest they will be in the same site if their subnet is defined for that site.
The servers will have connection objects to other servers in other domain because they are replicating othe partitions.
Commented:
I would not create a manual connection obejct. I would verify that the site link is setup the correct way and run the KCC to rebuild the connection objects.

http://technet.microsoft.com/en-us/library/cc736571%28WS.10%29.aspx#BKMK_7

Author

Commented:
Ok, so Im going to drop the DNS zones that I have copied over to the kratos.us DC (dt-2k8dc01) and setup forwarders to wfinet DNS zones instead. Maybe this will drop the site connection that the Kratos.us dc has to that wfinet DC, then I will execute the steps in the above article in the morning and check the subnets.

I will report my progress tomorrow. Thxs again for your help!

J

Author

Commented:
Ken, It was the default sitelink. Someone set it to 120 min replication time. Fixed. Thxs

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial