Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

KCC Errors / Event ID 1865, 1311, 1566 - Active Directory

Posted on 2011-03-14
11
Medium Priority
?
4,767 Views
Last Modified: 2012-09-20
I have a single domain, multi site Active Directory setup and both remote Windows 2008 servers are full of Event ID 1865, 1311 and 1566 in the ADS logs.

All DC's are replicating fine (checked via NTDS) and I have modified the MTU to 1492 as I'm sure I have read on here somewhere and have rebooted the servers.

Can anyone advise on where  to go next?
0
Comment
Question by:Mr_OCD
  • 6
  • 4
11 Comments
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35127300
OK, let's start first by running DCDIAG on all DC's, please post the results.

Do you have them all configured to use a valid Windows DNS server only?

Also, do you have all your Active Directory Sites and Services Sites and Subnets configured correctly?
0
 

Author Comment

by:Mr_OCD
ID: 35127593
From running DCDIAG I can see we have replication errors between the two remote sites that are causing the problems.

I'm not sure how to post the results of the logs as they are quite long?

All DC's are configured to use valid Windows DNS servers only.

I have configured AD sites and services subnets, etc correctly but AD automatically generated the links itself.

0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35127674
Can you run the following:

DCDIAG > C:\DCDIAG-COMPUTERNAME.TXT

Replace the computername with the name of the server and then upload the text files.
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 

Author Comment

by:Mr_OCD
ID: 35127704
Ok here we go...

 DCDIAG-DRS.txt

*****************************************

 DCDIAG-STC.txt
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35127751
And you have confirmed that both DC's are able to communicate with each other?

Can you run: dcdiag /test:connectivity

On both servers.  What are the results?
0
 

Author Comment

by:Mr_OCD
ID: 35127907
Both servers pass connectivity tests.
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35128483
Can you post the content of the errors you are receiving in the event log please?
0
 

Author Comment

by:Mr_OCD
ID: 35128572
Event 1865:

KCC was unable to form a complete spanning tree network topology. As a result the following list of sites cannot be reached from the locate site.

Sites:
Remote Site 1

Event 1311:

KCC has detected problems with the following directory partition.

There is insufficient site connectivity information for the KCC to create a spanniong tree replication topology. Or, one or more directory servers with this directory partition are unable to replicate the directory information.

Event 1566:

All directory servers in the following site that can replicate the directory partition over this transport are currently unavailable.
0
 
LVL 12

Expert Comment

by:Navdeep
ID: 35129120
Hi,

How about you site links and site link bridging.

Do you have physically connectivity among all sites or it is it like hub - spoke topology.

Your site links should map you physical links. Please re verify site links
0
 

Accepted Solution

by:
Mr_OCD earned 0 total points
ID: 35149635
All fixed.

Re-created the IPSEC VPN tunnel between the remote sites and all of the errors have stopped.
0
 

Author Closing Comment

by:Mr_OCD
ID: 35178786
None
0

Featured Post

Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Redirected folders in a windows domain can be quite useful for a number of reasons, one of them being that with redirected application data, you can give users more seamless experience when logging into different workstations.  For example, if a use…
After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

926 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question