[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Replication problem

Posted on 2011-04-19
13
Medium Priority
?
255 Views
Last Modified: 2012-06-27
Event ID 1311 are created , SYSVOL AND NEtlogon is missing
0
Comment
Question by:harispm
  • 9
  • 4
13 Comments
 
LVL 14

Expert Comment

by:Vinchenzo-the-Second
ID: 35426245
I fixed an issue relating to this the other day:
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_26955757.html
#

If the above fails and you have at least two DC's, you can just demote the server and repromote it.
0
 

Author Comment

by:harispm
ID: 35426366
In this case , I have 3 sites , and total 4 DC,  the problem with first site 2nd dc, .the C:\windows\sysvol\sysvol\dc.kia\ntfrs_preexisting folder is thet, I cannot see Scripts and Policies folder , but it is available in ntfrs_preexisitng , the problem with this DC only, it was restored system state lasttime when ad problem occurs. We tried to remove using DCpromo, it is giving error, all other Dc and repication working fine
0
 
LVL 14

Assisted Solution

by:Vinchenzo-the-Second
Vinchenzo-the-Second earned 160 total points
ID: 35426391
Do a dcpromo /forceremoval.  You then need to clean up metadata, i've attached a doc on how to do this. (It does refere to windows 2003 but its the same procedure for windows 2008)

Then promote the server.
Clean-up-Active-Directory-after-.docx
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:harispm
ID: 35426529
Can i Use burflag D4 to fix this issue,  Can I lose the latest update of AD
0
 

Author Comment

by:harispm
ID: 35426931
Burfalg D4 , Can I do on Missing Sysvol Direcoty Domain controller
0
 

Author Comment

by:harispm
ID: 35430457
When netdiag is applied on restored system state Domain controller, I am getting this

Trust relationship test. . . . . . : Failed
    [FATAL] Secure channel to domain 'KIADC' is broken. [ERROR_ACCESS_DENIED]


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed
    [WARNING] Failed to query SPN registration on DC 'Centraldc.dc.kia'.
0
 
LVL 14

Expert Comment

by:Vinchenzo-the-Second
ID: 35433605
You need reset the secure channel, I've never seen this fix the issue, I've in the past demoted the server and re-promoted it
0
 

Author Comment

by:harispm
ID: 35433648
how to reset the secure channel , any way , Let me check it first , at last I can go t demotion
0
 
LVL 14

Assisted Solution

by:Vinchenzo-the-Second
Vinchenzo-the-Second earned 160 total points
ID: 35433764
You need use nltest from the troubled DCm
NLTEST /SC_RESET:<DOMAIN_NAME_TO_RESET
0
 

Author Comment

by:harispm
ID: 35433826
C:\>NLTEST /SC_RESET:DC.kia
I_NetLogonControl failed: Status = 5 0x5 ERROR_ACCESS_DENIED, how to fix this
0
 

Accepted Solution

by:
harispm earned 0 total points
ID: 35434341

I uses this step and it rebuilded trust relatioship, Now working fine

To reset a domain controller in a Windows 2000 domain:
Stop the Kerberos Key Distribution Center (KDC) service, and then set it to Manual startup.
Run the netdom resetpwd /server:replication_partner_server_name /userd:domain_name\admin_user /passwordd:* command.
Restart the computer, start the KDC, and then set it back to Automatic startup.
0
 

Author Comment

by:harispm
ID: 35439364
35434341 is eligible for 500 points
0
 

Author Closing Comment

by:harispm
ID: 35465122
It reset Secure channel
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question