?
Solved

Active Directory not replicating

Posted on 2010-11-22
14
Medium Priority
?
746 Views
Last Modified: 2012-06-21
I have a Windows 2003 domain, where the main DC is a Windows 2003 server, but all the other DCs are 2000. All of the FSMO roles are on the 2003 server and each of the 2000 servers are GCs.

Recently I noticed that one of the 2000 servers are not replicating AD. Many user records that have been dsiabled or deleted or moved to different containers are still active in the 2000 server.

When I look at the event log there are many errors including a "Konwledge Consistency" error event ID 1265 that shows access denied.

When I run DC Diag I get LDAP bind failure where the 2003 server is identified as the Schema Owner, Domain Owner, PDC Owner, Rid Owner etc....but all of them give not responding to LDAP and DS RPC bind messages.

Is this a DNS issue? If so, should I remove DNS and reinstall it? If so what are the steps to remove DNS? Do I simply delete the forward and reverse zones and rebuild or do I uninstall DNS and reinstall and then recreate the zones?

Thank you.
0
Comment
Question by:cfgchiran
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 6
14 Comments
 
LVL 4

Expert Comment

by:patterned
ID: 34191141
Can you post the full dcdiag results?

Is that 2000 server a DNS server?

When you run an nslookup on that machine for the windows 2003 hostname, what is the resultant IP address and is it correct?
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 34191149
I doubt it's DNS, although it doesn't hurt to be sure about that one. I don't advise re-installing anything in DNS at this stage, it's rare for DNS itself to be broken (to an extent that requires you to reinstall stuff).

First, can you run DCDiag and "repadmin /showreps", I'd be worried that one of the servers is over the tombstone lifetime.

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34191360
Thank you for your responses. This 2000 server is a DNS server. (All my DCs are)

If I run a nslookup for 2003 hostname it identifies it correctly.

Here are the dcdiag and repadmin results.

 
Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests
   
   Testing server: CFC\CFC-FILESRVR
      Starting test: Connectivity
         ......................... CFC-FILESRVR passed test Connectivity

Doing primary tests
   
   Testing server: CFC\CFC-FILESRVR
      Starting test: Replications
         ......................... CFC-FILESRVR passed test Replications
      Starting test: NCSecDesc
         ......................... CFC-FILESRVR passed test NCSecDesc
      Starting test: NetLogons
         ......................... CFC-FILESRVR passed test NetLogons
      Starting test: Advertising
         ......................... CFC-FILESRVR passed test Advertising
      Starting test: KnowsOfRoleHolders
         [CFGC-PDC] DsBind() failed with error -2146893022,
         The target principal name is incorrect..
         Warning: CFGC-PDC is the Schema Owner, but is not responding to DS RPC Bind.
         [CFGC-PDC] LDAP bind failed with error 31,
         A device attached to the system is not functioning..
         Warning: CFGC-PDC is the Schema Owner, but is not responding to LDAP Bind.
         Warning: CFGC-PDC is the Domain Owner, but is not responding to DS RPC Bind.
         Warning: CFGC-PDC is the Domain Owner, but is not responding to LDAP Bind.
         Warning: CFGC-PDC is the PDC Owner, but is not responding to DS RPC Bind.
         Warning: CFGC-PDC is the PDC Owner, but is not responding to LDAP Bind.
         Warning: CFGC-PDC is the Rid Owner, but is not responding to DS RPC Bind.
         Warning: CFGC-PDC is the Rid Owner, but is not responding to LDAP Bind.
         Warning: CFGC-PDC is the Infrastructure Update Owner, but is not responding to DS RPC Bind.
         Warning: CFGC-PDC is the Infrastructure Update Owner, but is not responding to LDAP Bind.
         ......................... CFC-FILESRVR failed test KnowsOfRoleHolders
      Starting test: RidManager
         [CFC-FILESRVR] DsBindWithCred() failed with error -2146893022. The target principal name is incorrect.
         ......................... CFC-FILESRVR failed test RidManager
      Starting test: MachineAccount
         ldap_search_sW failed with 234: More data is available.
         ldap_search_sW subtree of DC=childguidance,DC=org for sam account failed with 234: More data is available.
         ldap_search_sW subtree of DC=childguidance,DC=org for sam account failed with 234: More data is available.
         ......................... CFC-FILESRVR failed test MachineAccount
      Starting test: Services
         ......................... CFC-FILESRVR passed test Services
      Starting test: ObjectsReplicated
         ......................... CFC-FILESRVR passed test ObjectsReplicated
      Starting test: frssysvol
         There are errors after the SYSVOL has been shared.
         The SYSVOL can prevent the AD from starting.
         ......................... CFC-FILESRVR passed test frssysvol
      Starting test: kccevent
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 11/22/2010   11:32:24
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 11/22/2010   11:32:24
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 11/22/2010   11:32:24
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 11/22/2010   11:32:24
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC000051F
            Time Generated: 11/22/2010   11:32:24
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 11/22/2010   11:32:24
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 11/22/2010   11:32:24
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 11/22/2010   11:32:24
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 11/22/2010   11:32:24
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC000051F
            Time Generated: 11/22/2010   11:32:24
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:25
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:25
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:25
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:25
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:25
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:25
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:25
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:25
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:26
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:26
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:26
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:26
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:32:49
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:33:12
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:33:35
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:33:35
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:33:35
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x800004F1
            Time Generated: 11/22/2010   11:33:35
            (Event String could not be retrieved)
         ......................... CFC-FILESRVR failed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x0000168F
            Time Generated: 11/22/2010   10:57:25
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x0000168F
            Time Generated: 11/22/2010   10:57:25
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x0000168F
            Time Generated: 11/22/2010   10:57:26
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x0000168F
            Time Generated: 11/22/2010   10:57:26
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x0000041B
            Time Generated: 11/22/2010   11:24:41
            Event String: The DHCP/BINL service has determined that it is

         ......................... CFC-FILESRVR failed test systemlog
   
   Running enterprise tests on : childguidance.org
      Starting test: Intersite
         ......................... childguidance.org passed test Intersite
      Starting test: FsmoCheck
         ......................... childguidance.org passed test FsmoCheck

Open in new window


 
CFC\CFC-FILESRVR
DSA Options : IS_GC 
objectGuid  : a67ef845-dc40-4c7c-9032-e1c0193bbdaf
invocationID: 14d79a14-8022-4485-84a1-bdcb26599015

==== INBOUND NEIGHBORS ======================================

==== OUTBOUND NEIGHBORS FOR CHANGE NOTIFICATIONS ============

CN=Schema,CN=Configuration,DC=childguidance,DC=org
    VN\VN-BDC via RPC
        objectGuid: cf39a15d-6192-4408-b4bc-67d71e6c7edf

CN=Configuration,DC=childguidance,DC=org
    VN\VN-BDC via RPC
        objectGuid: cf39a15d-6192-4408-b4bc-67d71e6c7edf

DC=childguidance,DC=org
    VN\VN-BDC via RPC
        objectGuid: cf39a15d-6192-4408-b4bc-67d71e6c7edf

Open in new window

0
Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

 
LVL 71

Expert Comment

by:Chris Dent
ID: 34191414

CFC-FILESRVR doesn't seem to think it even has a replication partner.  Could you tell me which OU CFC-FILESRVR is in please?

And would you run the same tests on your other DC please?

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34191512
Chris,

It is in the Domain Controllers OU on both the CFC-FileSrvr AD as well as the CFGC-PDC AD.

Here are the results from my CFGC-PDC (my 2003 DC) dcdiag and repadmin.

 
Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests
   
   Testing server: WO\CFGC-PDC
      Starting test: Connectivity
         ......................... CFGC-PDC passed test Connectivity

Doing primary tests
   
   Testing server: WO\CFGC-PDC
      Starting test: Replications
         ......................... CFGC-PDC passed test Replications
      Starting test: NCSecDesc
         ......................... CFGC-PDC passed test NCSecDesc
      Starting test: NetLogons
         ......................... CFGC-PDC passed test NetLogons
      Starting test: Advertising
         ......................... CFGC-PDC passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... CFGC-PDC passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... CFGC-PDC passed test RidManager
      Starting test: MachineAccount
         ......................... CFGC-PDC passed test MachineAccount
      Starting test: Services
         ......................... CFGC-PDC passed test Services
      Starting test: ObjectsReplicated
         ......................... CFGC-PDC passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... CFGC-PDC passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours after the

         SYSVOL has been shared.  Failing SYSVOL replication problems may cause

         Group Policy problems. 
         ......................... CFGC-PDC failed test frsevent
      Starting test: kccevent
         ......................... CFGC-PDC passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x000016AD
            Time Generated: 11/22/2010   11:58:23
            Event String: The session setup from the computer CFGC-WEBPROXY

         ......................... CFGC-PDC failed test systemlog
      Starting test: VerifyReferences
         ......................... CFGC-PDC passed test VerifyReferences
   
   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
   
   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
   
   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
   
   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
   
   Running partition tests on : childguidance
      Starting test: CrossRefValidation
         ......................... childguidance passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... childguidance passed test CheckSDRefDom
   
   Running enterprise tests on : childguidance.org
      Starting test: Intersite
         ......................... childguidance.org passed test Intersite
      Starting test: FsmoCheck
         ......................... childguidance.org passed test FsmoCheck

Open in new window


 
WO\CFGC-PDC

DC Options: IS_GC 

Site Options: (none)

DC object GUID: 73556410-ac36-44e6-b8b3-27eed96485f9

DC invocationID: 01cd1621-ef27-474f-a63b-ce0366c86753



==== INBOUND NEIGHBORS ======================================



DC=childguidance,DC=org

    VN\VN-BDC via RPC

        DC object GUID: cf39a15d-6192-4408-b4bc-67d71e6c7edf

        Last attempt @ 2010-11-22 11:53:12 was successful.

    LAN-DP\LAN-DHCP via RPC

        DC object GUID: 410ad669-e675-4591-b498-a87c0c9681c3

        Last attempt @ 2010-11-22 11:53:12 was successful.

    WO\MAIL via RPC

        DC object GUID: 0507430b-795a-4c4c-af48-abfa2c2f5e44

        Last attempt @ 2010-11-22 12:00:11 was successful.

    WO\CFGC-BDC via RPC

        DC object GUID: 0c6f82c6-cafa-40c5-b3e3-f58022159c1a

        Last attempt @ 2010-11-22 12:01:01 was successful.



CN=Configuration,DC=childguidance,DC=org

    LAN-DP\LAN-DHCP via RPC

        DC object GUID: 410ad669-e675-4591-b498-a87c0c9681c3

        Last attempt @ 2010-11-22 11:53:12 was successful.

    VN\VN-BDC via RPC

        DC object GUID: cf39a15d-6192-4408-b4bc-67d71e6c7edf

        Last attempt @ 2010-11-22 11:53:12 was successful.

    WO\CFGC-BDC via RPC

        DC object GUID: 0c6f82c6-cafa-40c5-b3e3-f58022159c1a

        Last attempt @ 2010-11-22 12:00:01 was successful.

    WO\MAIL via RPC

        DC object GUID: 0507430b-795a-4c4c-af48-abfa2c2f5e44

        Last attempt @ 2010-11-22 12:03:29 was successful.



CN=Schema,CN=Configuration,DC=childguidance,DC=org

    WO\CFGC-BDC via RPC

        DC object GUID: 0c6f82c6-cafa-40c5-b3e3-f58022159c1a

        Last attempt @ 2010-11-22 11:53:12 was successful.

    WO\MAIL via RPC

        DC object GUID: 0507430b-795a-4c4c-af48-abfa2c2f5e44

        Last attempt @ 2010-11-22 11:53:12 was successful.

    VN\VN-BDC via RPC

        DC object GUID: cf39a15d-6192-4408-b4bc-67d71e6c7edf

        Last attempt @ 2010-11-22 11:53:12 was successful.

    LAN-DP\LAN-DHCP via RPC

        DC object GUID: 410ad669-e675-4591-b498-a87c0c9681c3

        Last attempt @ 2010-11-22 11:53:12 was successful.



DC=DomainDnsZones,DC=childguidance,DC=org

    LAN-DP\LAN-DHCP via RPC

        DC object GUID: 410ad669-e675-4591-b498-a87c0c9681c3

        Last attempt @ 2010-11-22 11:53:12 was successful.



DC=ForestDnsZones,DC=childguidance,DC=org

    LAN-DP\LAN-DHCP via RPC

        DC object GUID: 410ad669-e675-4591-b498-a87c0c9681c3

        Last attempt @ 2010-11-22 11:53:13 was successful.

Open in new window

0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34191529
Just FYI at our HQ we have the CFGC-PDC and another 2000 DC server CFGC-BDC, along with an older 2000 exchange server which also has AD and DNS.

In addition I have DCs at five satellite locaitons, all of which are 2k servers, all with DNS. One of which is CFC-FileSrvr.
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 34191554

Can you head to AD Sites and Services, head to CFC-FILESRVR, then NTDS Settings underneath it. Does it have any connections listed with any other DCs?

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34192218
I went to AD Sites and Services on both servers and under CFC-FileSrvr, under NTDS there are six automatically.generated DCs including the CFGC-PDC.
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 34194976

Hmm did you do that while logged onto CFC-FileSrvr? It's strange that "repadmin /showreps" isn't showing any inbound connections, and only one outbound to VN-BDC.

If that is the only DC that's malfunctioning I would seriously consider demoting it. It's likely that it can be fixed, eventually, but unless you are utterly reliant on the server letting it go is a cleaner / faster path.

Before doing that, we should put DNS somewhere more reliable. Nominate a server? :) If DNS is already installed, is the version of the zone hosted by that server up to date? Or horribly out of date? If it's out of date, I'd be tempted to delete it and start again. If it's up to date, you'll need to change all your clients (end-user systems and servers) to refer to that DNS server.

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34197590
Yes I idid that while logged into both the CFC-FileSrvr and the CFGC-PDC. Both had the same info. The DNS does not seem to be that out dated. I suppose I could demote and rebuild AD and DNS on that server.  

I was hoping I would not have to rebuild AD as I use that server for file storage, and therefore it has individual user permissions on folders, which I fear I may lose if I demote it. Is that correct?

Since I have nothing to lose, I am thinking of removing DNS and recreating the zone to see if that makes a difference. What do you think?

Thanks.

0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 34197933

You won't lose them, but do be aware that if you run DCPromo /force (and you will have to if we're to demote it) the server will be bumped out of the domain. The permissions will not be modified, but they won't be valid until you join it back into the domain.

You won't need to change the server name or anything, but you must clean up AD before you re-join it or you'll have a mess.

If you're worried about the permissions we can backup the permission structure independently.

Rebuilding DNS... I think it won't gain anything.

I agree that this is a risk, but I feel trying to recover from this situation is going to be messy and far more disruptive than bumping it off. What do you think? We can put together a more detailed plan if you think it might be a reasonable approach.

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34198198
Chris,

Thanks for the response. Since I am coming into a long weekend, I will remove the server from the domain tomorrow night and add it back to the domain over the weekend. Nobody will be using it until Monday.

When you say AD clean up, do I have to do a metadata cleanup, or will removing it from the domain, and giving it enough be sufficient? Or will that not be enough since the domain is not synching properly?

I will proberbly just take off DNS and reinstall DNS tonight, just to see whether it makes a difference.

I am not overly concerned about the permissions as that server does not have too many users, and I can easily redo the permissions for the user folders manually.

When I use DCPromo does it not simply make it a member server, thus keeping it in the domain, and retaining the security structure?

Thanks,

Hiran
0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 2000 total points
ID: 34198442

Not when you use Force, no. We're ripping AD off instead of gracefully demoting it. This is because of the lack of connectivity to the rest of the domain / forest.

A more detailed list of steps:

1. Execute "DCPromo /Force" on CFC-FileSrvr
2. On one of the other DCs, run through MetaData Cleanup to remove the "failed" DC: http://technet.microsoft.com/en-us/library/cc736378%28WS.10%29.aspx
3. Allow time for replication to occur
4. Remove entries for CFC-FileSrvr from DNS (you don't need to go far with this, just the obvious entries)
5. Execute DCDiag and "RepAdmin /showreps" to check the domain
6. Check event logs on remaining DCs for failures relating to CFC-FileSrvr
7. Quick check for the Computer Account, and any entries for CFC-FileSrvr under AD Sites and Services (the first should be gone, the second might not). Delete if found.
7. Join CFC-FileSrvr to the domain again
8. Promote the server to Domain Controller (if it is appropriate to do so)
9. Another round of DCDiag / repadmin and checking of the event logs to make sure it's happy and you're done

You might insert a system state backup of an operational DC before and after and possibly during the change so you have a way back at each stage.

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34198774
Thank you Chris. I will try these steps and get back to you by the weekend. Really appreciate your help.

I was thinking of trying a DCPromo without the force option, just to see if it does establish connectivity, but I assume it won't.
0

Featured Post

Enroll in August's Course of the Month

August's CompTIA IT Fundamentals course includes 19 hours of basic computer principle modules and prepares you for the certification exam. It's free for Premium Members, Team Accounts, and Qualified Experts!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains how a domain name may be inadvertently appended to all DNS queries. This exhibits as described below. (CODE)And / Or: (CODE) Cause This issue can occur in either of these two scenarios. EITHER 1. A Primary DNS S…
I will assume you are running a non-server version of some sort of Windows throughout this article. There are many flavors of Windows since Windows Server 2000 - 2008, XP Home & Pro, Vista Home & Pro, and Windows 7 Starter, Home, Pro, Ultimate, etc.…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…
Suggested Courses
Course of the Month11 days, 12 hours left to enroll

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question