Solved

KCC Errors / Event ID 1865, 1311, 1566 - Active Directory

Posted on 2011-03-14
11
4,362 Views
Last Modified: 2012-09-20
I have a single domain, multi site Active Directory setup and both remote Windows 2008 servers are full of Event ID 1865, 1311 and 1566 in the ADS logs.

All DC's are replicating fine (checked via NTDS) and I have modified the MTU to 1492 as I'm sure I have read on here somewhere and have rebooted the servers.

Can anyone advise on where  to go next?
0
Comment
Question by:Mr_OCD
  • 6
  • 4
11 Comments
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35127300
OK, let's start first by running DCDIAG on all DC's, please post the results.

Do you have them all configured to use a valid Windows DNS server only?

Also, do you have all your Active Directory Sites and Services Sites and Subnets configured correctly?
0
 

Author Comment

by:Mr_OCD
ID: 35127593
From running DCDIAG I can see we have replication errors between the two remote sites that are causing the problems.

I'm not sure how to post the results of the logs as they are quite long?

All DC's are configured to use valid Windows DNS servers only.

I have configured AD sites and services subnets, etc correctly but AD automatically generated the links itself.

0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35127674
Can you run the following:

DCDIAG > C:\DCDIAG-COMPUTERNAME.TXT

Replace the computername with the name of the server and then upload the text files.
0
Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

 

Author Comment

by:Mr_OCD
ID: 35127704
Ok here we go...

 DCDIAG-DRS.txt

*****************************************

 DCDIAG-STC.txt
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35127751
And you have confirmed that both DC's are able to communicate with each other?

Can you run: dcdiag /test:connectivity

On both servers.  What are the results?
0
 

Author Comment

by:Mr_OCD
ID: 35127907
Both servers pass connectivity tests.
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35128483
Can you post the content of the errors you are receiving in the event log please?
0
 

Author Comment

by:Mr_OCD
ID: 35128572
Event 1865:

KCC was unable to form a complete spanning tree network topology. As a result the following list of sites cannot be reached from the locate site.

Sites:
Remote Site 1

Event 1311:

KCC has detected problems with the following directory partition.

There is insufficient site connectivity information for the KCC to create a spanniong tree replication topology. Or, one or more directory servers with this directory partition are unable to replicate the directory information.

Event 1566:

All directory servers in the following site that can replicate the directory partition over this transport are currently unavailable.
0
 
LVL 12

Expert Comment

by:Navdeep
ID: 35129120
Hi,

How about you site links and site link bridging.

Do you have physically connectivity among all sites or it is it like hub - spoke topology.

Your site links should map you physical links. Please re verify site links
0
 

Accepted Solution

by:
Mr_OCD earned 0 total points
ID: 35149635
All fixed.

Re-created the IPSEC VPN tunnel between the remote sites and all of the errors have stopped.
0
 

Author Closing Comment

by:Mr_OCD
ID: 35178786
None
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question