Solved

Active Directory not replicating

Posted on 2010-11-22
14
738 Views
Last Modified: 2012-06-21
I have a Windows 2003 domain, where the main DC is a Windows 2003 server, but all the other DCs are 2000. All of the FSMO roles are on the 2003 server and each of the 2000 servers are GCs.

Recently I noticed that one of the 2000 servers are not replicating AD. Many user records that have been dsiabled or deleted or moved to different containers are still active in the 2000 server.

When I look at the event log there are many errors including a "Konwledge Consistency" error event ID 1265 that shows access denied.

When I run DC Diag I get LDAP bind failure where the 2003 server is identified as the Schema Owner, Domain Owner, PDC Owner, Rid Owner etc....but all of them give not responding to LDAP and DS RPC bind messages.

Is this a DNS issue? If so, should I remove DNS and reinstall it? If so what are the steps to remove DNS? Do I simply delete the forward and reverse zones and rebuild or do I uninstall DNS and reinstall and then recreate the zones?

Thank you.
0
Comment
Question by:cfgchiran
  • 7
  • 6
14 Comments
 
LVL 4

Expert Comment

by:patterned
ID: 34191141
Can you post the full dcdiag results?

Is that 2000 server a DNS server?

When you run an nslookup on that machine for the windows 2003 hostname, what is the resultant IP address and is it correct?
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 34191149
I doubt it's DNS, although it doesn't hurt to be sure about that one. I don't advise re-installing anything in DNS at this stage, it's rare for DNS itself to be broken (to an extent that requires you to reinstall stuff).

First, can you run DCDiag and "repadmin /showreps", I'd be worried that one of the servers is over the tombstone lifetime.

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34191360
Thank you for your responses. This 2000 server is a DNS server. (All my DCs are)

If I run a nslookup for 2003 hostname it identifies it correctly.

Here are the dcdiag and repadmin results.

 
Domain Controller Diagnosis



Performing initial setup:

   Done gathering initial info.



Doing initial required tests

   

   Testing server: CFC\CFC-FILESRVR

      Starting test: Connectivity

         ......................... CFC-FILESRVR passed test Connectivity



Doing primary tests

   

   Testing server: CFC\CFC-FILESRVR

      Starting test: Replications

         ......................... CFC-FILESRVR passed test Replications

      Starting test: NCSecDesc

         ......................... CFC-FILESRVR passed test NCSecDesc

      Starting test: NetLogons

         ......................... CFC-FILESRVR passed test NetLogons

      Starting test: Advertising

         ......................... CFC-FILESRVR passed test Advertising

      Starting test: KnowsOfRoleHolders

         [CFGC-PDC] DsBind() failed with error -2146893022,

         The target principal name is incorrect..

         Warning: CFGC-PDC is the Schema Owner, but is not responding to DS RPC Bind.

         [CFGC-PDC] LDAP bind failed with error 31,

         A device attached to the system is not functioning..

         Warning: CFGC-PDC is the Schema Owner, but is not responding to LDAP Bind.

         Warning: CFGC-PDC is the Domain Owner, but is not responding to DS RPC Bind.

         Warning: CFGC-PDC is the Domain Owner, but is not responding to LDAP Bind.

         Warning: CFGC-PDC is the PDC Owner, but is not responding to DS RPC Bind.

         Warning: CFGC-PDC is the PDC Owner, but is not responding to LDAP Bind.

         Warning: CFGC-PDC is the Rid Owner, but is not responding to DS RPC Bind.

         Warning: CFGC-PDC is the Rid Owner, but is not responding to LDAP Bind.

         Warning: CFGC-PDC is the Infrastructure Update Owner, but is not responding to DS RPC Bind.

         Warning: CFGC-PDC is the Infrastructure Update Owner, but is not responding to LDAP Bind.

         ......................... CFC-FILESRVR failed test KnowsOfRoleHolders

      Starting test: RidManager

         [CFC-FILESRVR] DsBindWithCred() failed with error -2146893022. The target principal name is incorrect.

         ......................... CFC-FILESRVR failed test RidManager

      Starting test: MachineAccount

         ldap_search_sW failed with 234: More data is available.

         ldap_search_sW subtree of DC=childguidance,DC=org for sam account failed with 234: More data is available.

         ldap_search_sW subtree of DC=childguidance,DC=org for sam account failed with 234: More data is available.

         ......................... CFC-FILESRVR failed test MachineAccount

      Starting test: Services

         ......................... CFC-FILESRVR passed test Services

      Starting test: ObjectsReplicated

         ......................... CFC-FILESRVR passed test ObjectsReplicated

      Starting test: frssysvol

         There are errors after the SYSVOL has been shared.

         The SYSVOL can prevent the AD from starting.

         ......................... CFC-FILESRVR passed test frssysvol

      Starting test: kccevent

         An Warning Event occured.  EventID: 0x8000061E

            Time Generated: 11/22/2010   11:32:24

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x8000061E

            Time Generated: 11/22/2010   11:32:24

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x8000061E

            Time Generated: 11/22/2010   11:32:24

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x8000061E

            Time Generated: 11/22/2010   11:32:24

            (Event String could not be retrieved)

         An Error Event occured.  EventID: 0xC000051F

            Time Generated: 11/22/2010   11:32:24

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x8000061E

            Time Generated: 11/22/2010   11:32:24

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x8000061E

            Time Generated: 11/22/2010   11:32:24

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x8000061E

            Time Generated: 11/22/2010   11:32:24

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x8000061E

            Time Generated: 11/22/2010   11:32:24

            (Event String could not be retrieved)

         An Error Event occured.  EventID: 0xC000051F

            Time Generated: 11/22/2010   11:32:24

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:25

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:25

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:25

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:25

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:25

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:25

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:25

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:25

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:26

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:26

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:26

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:26

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:32:49

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:33:12

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:33:35

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:33:35

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:33:35

            (Event String could not be retrieved)

         An Warning Event occured.  EventID: 0x800004F1

            Time Generated: 11/22/2010   11:33:35

            (Event String could not be retrieved)

         ......................... CFC-FILESRVR failed test kccevent

      Starting test: systemlog

         An Error Event occured.  EventID: 0x0000168F

            Time Generated: 11/22/2010   10:57:25

            (Event String could not be retrieved)

         An Error Event occured.  EventID: 0x0000168F

            Time Generated: 11/22/2010   10:57:25

            (Event String could not be retrieved)

         An Error Event occured.  EventID: 0x0000168F

            Time Generated: 11/22/2010   10:57:26

            (Event String could not be retrieved)

         An Error Event occured.  EventID: 0x0000168F

            Time Generated: 11/22/2010   10:57:26

            (Event String could not be retrieved)

         An Error Event occured.  EventID: 0x0000041B

            Time Generated: 11/22/2010   11:24:41

            Event String: The DHCP/BINL service has determined that it is



         ......................... CFC-FILESRVR failed test systemlog

   

   Running enterprise tests on : childguidance.org

      Starting test: Intersite

         ......................... childguidance.org passed test Intersite

      Starting test: FsmoCheck

         ......................... childguidance.org passed test FsmoCheck

Open in new window


 
CFC\CFC-FILESRVR

DSA Options : IS_GC 

objectGuid  : a67ef845-dc40-4c7c-9032-e1c0193bbdaf

invocationID: 14d79a14-8022-4485-84a1-bdcb26599015



==== INBOUND NEIGHBORS ======================================



==== OUTBOUND NEIGHBORS FOR CHANGE NOTIFICATIONS ============



CN=Schema,CN=Configuration,DC=childguidance,DC=org

    VN\VN-BDC via RPC

        objectGuid: cf39a15d-6192-4408-b4bc-67d71e6c7edf



CN=Configuration,DC=childguidance,DC=org

    VN\VN-BDC via RPC

        objectGuid: cf39a15d-6192-4408-b4bc-67d71e6c7edf



DC=childguidance,DC=org

    VN\VN-BDC via RPC

        objectGuid: cf39a15d-6192-4408-b4bc-67d71e6c7edf

Open in new window

0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 34191414

CFC-FILESRVR doesn't seem to think it even has a replication partner.  Could you tell me which OU CFC-FILESRVR is in please?

And would you run the same tests on your other DC please?

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34191512
Chris,

It is in the Domain Controllers OU on both the CFC-FileSrvr AD as well as the CFGC-PDC AD.

Here are the results from my CFGC-PDC (my 2003 DC) dcdiag and repadmin.

 
Domain Controller Diagnosis



Performing initial setup:

   Done gathering initial info.



Doing initial required tests

   

   Testing server: WO\CFGC-PDC

      Starting test: Connectivity

         ......................... CFGC-PDC passed test Connectivity



Doing primary tests

   

   Testing server: WO\CFGC-PDC

      Starting test: Replications

         ......................... CFGC-PDC passed test Replications

      Starting test: NCSecDesc

         ......................... CFGC-PDC passed test NCSecDesc

      Starting test: NetLogons

         ......................... CFGC-PDC passed test NetLogons

      Starting test: Advertising

         ......................... CFGC-PDC passed test Advertising

      Starting test: KnowsOfRoleHolders

         ......................... CFGC-PDC passed test KnowsOfRoleHolders

      Starting test: RidManager

         ......................... CFGC-PDC passed test RidManager

      Starting test: MachineAccount

         ......................... CFGC-PDC passed test MachineAccount

      Starting test: Services

         ......................... CFGC-PDC passed test Services

      Starting test: ObjectsReplicated

         ......................... CFGC-PDC passed test ObjectsReplicated

      Starting test: frssysvol

         ......................... CFGC-PDC passed test frssysvol

      Starting test: frsevent

         There are warning or error events within the last 24 hours after the



         SYSVOL has been shared.  Failing SYSVOL replication problems may cause



         Group Policy problems. 

         ......................... CFGC-PDC failed test frsevent

      Starting test: kccevent

         ......................... CFGC-PDC passed test kccevent

      Starting test: systemlog

         An Error Event occured.  EventID: 0x000016AD

            Time Generated: 11/22/2010   11:58:23

            Event String: The session setup from the computer CFGC-WEBPROXY



         ......................... CFGC-PDC failed test systemlog

      Starting test: VerifyReferences

         ......................... CFGC-PDC passed test VerifyReferences

   

   Running partition tests on : ForestDnsZones

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

   

   Running partition tests on : DomainDnsZones

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

   

   Running partition tests on : Schema

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

   

   Running partition tests on : Configuration

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

   

   Running partition tests on : childguidance

      Starting test: CrossRefValidation

         ......................... childguidance passed test CrossRefValidation

      Starting test: CheckSDRefDom

         ......................... childguidance passed test CheckSDRefDom

   

   Running enterprise tests on : childguidance.org

      Starting test: Intersite

         ......................... childguidance.org passed test Intersite

      Starting test: FsmoCheck

         ......................... childguidance.org passed test FsmoCheck

Open in new window


 
WO\CFGC-PDC



DC Options: IS_GC 



Site Options: (none)



DC object GUID: 73556410-ac36-44e6-b8b3-27eed96485f9



DC invocationID: 01cd1621-ef27-474f-a63b-ce0366c86753







==== INBOUND NEIGHBORS ======================================







DC=childguidance,DC=org



    VN\VN-BDC via RPC



        DC object GUID: cf39a15d-6192-4408-b4bc-67d71e6c7edf



        Last attempt @ 2010-11-22 11:53:12 was successful.



    LAN-DP\LAN-DHCP via RPC



        DC object GUID: 410ad669-e675-4591-b498-a87c0c9681c3



        Last attempt @ 2010-11-22 11:53:12 was successful.



    WO\MAIL via RPC



        DC object GUID: 0507430b-795a-4c4c-af48-abfa2c2f5e44



        Last attempt @ 2010-11-22 12:00:11 was successful.



    WO\CFGC-BDC via RPC



        DC object GUID: 0c6f82c6-cafa-40c5-b3e3-f58022159c1a



        Last attempt @ 2010-11-22 12:01:01 was successful.







CN=Configuration,DC=childguidance,DC=org



    LAN-DP\LAN-DHCP via RPC



        DC object GUID: 410ad669-e675-4591-b498-a87c0c9681c3



        Last attempt @ 2010-11-22 11:53:12 was successful.



    VN\VN-BDC via RPC



        DC object GUID: cf39a15d-6192-4408-b4bc-67d71e6c7edf



        Last attempt @ 2010-11-22 11:53:12 was successful.



    WO\CFGC-BDC via RPC



        DC object GUID: 0c6f82c6-cafa-40c5-b3e3-f58022159c1a



        Last attempt @ 2010-11-22 12:00:01 was successful.



    WO\MAIL via RPC



        DC object GUID: 0507430b-795a-4c4c-af48-abfa2c2f5e44



        Last attempt @ 2010-11-22 12:03:29 was successful.







CN=Schema,CN=Configuration,DC=childguidance,DC=org



    WO\CFGC-BDC via RPC



        DC object GUID: 0c6f82c6-cafa-40c5-b3e3-f58022159c1a



        Last attempt @ 2010-11-22 11:53:12 was successful.



    WO\MAIL via RPC



        DC object GUID: 0507430b-795a-4c4c-af48-abfa2c2f5e44



        Last attempt @ 2010-11-22 11:53:12 was successful.



    VN\VN-BDC via RPC



        DC object GUID: cf39a15d-6192-4408-b4bc-67d71e6c7edf



        Last attempt @ 2010-11-22 11:53:12 was successful.



    LAN-DP\LAN-DHCP via RPC



        DC object GUID: 410ad669-e675-4591-b498-a87c0c9681c3



        Last attempt @ 2010-11-22 11:53:12 was successful.







DC=DomainDnsZones,DC=childguidance,DC=org



    LAN-DP\LAN-DHCP via RPC



        DC object GUID: 410ad669-e675-4591-b498-a87c0c9681c3



        Last attempt @ 2010-11-22 11:53:12 was successful.







DC=ForestDnsZones,DC=childguidance,DC=org



    LAN-DP\LAN-DHCP via RPC



        DC object GUID: 410ad669-e675-4591-b498-a87c0c9681c3



        Last attempt @ 2010-11-22 11:53:13 was successful.

Open in new window

0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34191529
Just FYI at our HQ we have the CFGC-PDC and another 2000 DC server CFGC-BDC, along with an older 2000 exchange server which also has AD and DNS.

In addition I have DCs at five satellite locaitons, all of which are 2k servers, all with DNS. One of which is CFC-FileSrvr.
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 34191554

Can you head to AD Sites and Services, head to CFC-FILESRVR, then NTDS Settings underneath it. Does it have any connections listed with any other DCs?

Chris
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 1

Author Comment

by:cfgchiran
ID: 34192218
I went to AD Sites and Services on both servers and under CFC-FileSrvr, under NTDS there are six automatically.generated DCs including the CFGC-PDC.
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 34194976

Hmm did you do that while logged onto CFC-FileSrvr? It's strange that "repadmin /showreps" isn't showing any inbound connections, and only one outbound to VN-BDC.

If that is the only DC that's malfunctioning I would seriously consider demoting it. It's likely that it can be fixed, eventually, but unless you are utterly reliant on the server letting it go is a cleaner / faster path.

Before doing that, we should put DNS somewhere more reliable. Nominate a server? :) If DNS is already installed, is the version of the zone hosted by that server up to date? Or horribly out of date? If it's out of date, I'd be tempted to delete it and start again. If it's up to date, you'll need to change all your clients (end-user systems and servers) to refer to that DNS server.

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34197590
Yes I idid that while logged into both the CFC-FileSrvr and the CFGC-PDC. Both had the same info. The DNS does not seem to be that out dated. I suppose I could demote and rebuild AD and DNS on that server.  

I was hoping I would not have to rebuild AD as I use that server for file storage, and therefore it has individual user permissions on folders, which I fear I may lose if I demote it. Is that correct?

Since I have nothing to lose, I am thinking of removing DNS and recreating the zone to see if that makes a difference. What do you think?

Thanks.

0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 34197933

You won't lose them, but do be aware that if you run DCPromo /force (and you will have to if we're to demote it) the server will be bumped out of the domain. The permissions will not be modified, but they won't be valid until you join it back into the domain.

You won't need to change the server name or anything, but you must clean up AD before you re-join it or you'll have a mess.

If you're worried about the permissions we can backup the permission structure independently.

Rebuilding DNS... I think it won't gain anything.

I agree that this is a risk, but I feel trying to recover from this situation is going to be messy and far more disruptive than bumping it off. What do you think? We can put together a more detailed plan if you think it might be a reasonable approach.

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34198198
Chris,

Thanks for the response. Since I am coming into a long weekend, I will remove the server from the domain tomorrow night and add it back to the domain over the weekend. Nobody will be using it until Monday.

When you say AD clean up, do I have to do a metadata cleanup, or will removing it from the domain, and giving it enough be sufficient? Or will that not be enough since the domain is not synching properly?

I will proberbly just take off DNS and reinstall DNS tonight, just to see whether it makes a difference.

I am not overly concerned about the permissions as that server does not have too many users, and I can easily redo the permissions for the user folders manually.

When I use DCPromo does it not simply make it a member server, thus keeping it in the domain, and retaining the security structure?

Thanks,

Hiran
0
 
LVL 70

Accepted Solution

by:
Chris Dent earned 500 total points
ID: 34198442

Not when you use Force, no. We're ripping AD off instead of gracefully demoting it. This is because of the lack of connectivity to the rest of the domain / forest.

A more detailed list of steps:

1. Execute "DCPromo /Force" on CFC-FileSrvr
2. On one of the other DCs, run through MetaData Cleanup to remove the "failed" DC: http://technet.microsoft.com/en-us/library/cc736378%28WS.10%29.aspx
3. Allow time for replication to occur
4. Remove entries for CFC-FileSrvr from DNS (you don't need to go far with this, just the obvious entries)
5. Execute DCDiag and "RepAdmin /showreps" to check the domain
6. Check event logs on remaining DCs for failures relating to CFC-FileSrvr
7. Quick check for the Computer Account, and any entries for CFC-FileSrvr under AD Sites and Services (the first should be gone, the second might not). Delete if found.
7. Join CFC-FileSrvr to the domain again
8. Promote the server to Domain Controller (if it is appropriate to do so)
9. Another round of DCDiag / repadmin and checking of the event logs to make sure it's happy and you're done

You might insert a system state backup of an operational DC before and after and possibly during the change so you have a way back at each stage.

Chris
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 34198774
Thank you Chris. I will try these steps and get back to you by the weekend. Really appreciate your help.

I was thinking of trying a DCPromo without the force option, just to see if it does establish connectivity, but I assume it won't.
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Create MX, A and PTR in Godaddy 8 35
Speed up DNS resolution 19 57
New MX Records 12 65
Guest VLAN not syncing email 13 21
I wrote this article to explain some important DNS concepts that should be known to avoid some typical configuration errors I often see in forums. I assume that what is described here is the typical behavior of Microsoft DNS client. I don't know …
BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (https://kb.isc.org/article/AA-01272), affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now