Avatar of ManicD
ManicDFlag for United Kingdom of Great Britain and Northern Ireland asked on

Replication Failing

OK, so i have two DC's on 2 sites, connected by an odd setup

DC1 has IP 10.166.150.250
deafult gateway 10.166.150.1
and from what i can tell tehe outside address of that router is 10.160.28.250
server 2003 x64

DC2 has IP 10.0.0.250
default gateway 10.0.0.1
and from what i can tell tehe outside address of that router is 10.155.24.250
server 2003 x86

(IP addresses changed but designed to still show you the idea)

now obviously the external ips are part of a managed network, from what i see anything sent to the outside addresses is passed stright through to the servers

basically i'm having issues with replication, i've been working on this all day and getting nowhere, now i'm just seeing everything as a blur.

the only change i believe i have made was to move the two servers into different active directory sites, as they are on different physical sites with different subnets. they servers can seem to talk to each other, dcdiag seems to come cleanish.

what tests would you like me to run? i feel like i have run them all, but i'll let you ask and i'll keep you informed
(p.s. its now 23.14GMT, i'll be running these tests in the morning)
(p.p.s. My money is currently on DNS issues, but ask anything and i'll answer)


thanks in advanced
A very very very exausted ManicD



Active DirectoryWindows Server 2003DNS

Avatar of undefined
Last Comment
ManicD

8/22/2022 - Mon
Andrej Pirman

Did you check replication topology, <Automatically generated> replication links? Are they present?

Ok, next: did you run "repadmin" from Windows Server 2003 Support Tools?
Example 1: Display the replication partners of a server
repadmin /showrepl ms-mvps.chicagotech.net

Example 2: Force a replication event between two replication partners
repadmin /replicate ms-mvps1.chicagotech.net ms-mvps2.chicagotech.net

Example 3: Display the connection objects for a server
repadmin /showconn ms-mvps.chicagotech.net

Just to be on safe side, I'd use some port scanning software and check servr-to-server for open ports. At least these ports should be opened if you scan from one to the other server:
TCP: 42,88,135,137,138,139,389,445,1512
there are some other UDP ports, but they are not so easy to scan, so let's check just TCP ports.

Andrej Pirman

Ups...I was too fast with "Submit" :)

I stated too many ports - only these TCP ports are essential for replication:
88
135
139
389
445
Andrew Oakeley

You are probably on the track with DNS being an issue. And I assume that there is a VPN between the sites? So ignore the WAN addresses of the routers, these are not important or useful to you.

1. can you ping DC1 by ip address (ping 10.166.150.250) from DC2
2. can you ping DC2 by ip address (ping 10.0.0.250) from DC1
3. can you ping DC1 by FQDN (ping dc1.mycompany.local) from DC2
4. can you ping DC2 by FQDN (ping dc2.mycompany.local) from DC2

If you cannot ping each server by IP Address you need your VPN fixed

Assuming you can at least ping each server by IP Address do the following....

On the server that you moved to the new site
- set the DNS server address on its NIC to be the DNS Server on the DC in the original site.
- ipconfig /register dns
- stop and restart the NETLOGON service

After you have done the above check DNS on the server in the original site to ensure that the A Record for the Server that was moved to the new site is correct.

Force Replication

Check that DNS on the server in the new site is now correct, and change DNS on the NIC of the server in the new site back to point to itself.

 
Your help has saved me hundreds of hours of internet surfing.
fblack61
Sandesh Dubey

Refer below article the port which need to be open for AD.
http://technet.microsoft.com/en-us/library/bb727063.aspx

Ran repadmin /replsum /AdeP on both the Dc to force the replication between the DC.Also check both the DC and ping each other.

Ran repadmin /replsum on both the DC and post the log.
ASKER
ManicD


Gonna have to say ignore Site1\DC3, it died about 2 months ago before I took over IT Support.
I have to go through the manual process of removing it from the domain

P.S. When i said i moved DC2 to a different site, It was already PHYSICALLY there, i just moved the AD sites and services

I currently have DC2 dns settings on the LAN card set to DC1 external IP
I also have Host file records for

ON DC1
dc2 = to DC2 external IP
dc2.domain.local = to DC2 external IP

ON DC2
dc1 = to dc 1 external IP
dc1.domain.local = to dc 1 external IP

==================================

OK  repadmin /showrepl

=====================
From DC1
=====================

Site1\DC1.domain

DC Options: IS_GC

Site Options: (none)

DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

DC invocationID: 7cfc68b9-f57b-43f9-b542-58f6d564a6fc



==== INBOUND NEIGHBORS ======================================



DC=domain,DC=local

    Site1\DC3 via RPC

        DC object GUID: a1075d5c-fca2-4b66-ae1f-27123dec4d13

        Last attempt @ 2011-07-10 09:54:22 failed, result 8524 (0x214c):

            Can't retrieve message string 8524 (0x214c), error 1815.

        2568 consecutive failure(s).

        Last success @ 2011-03-25 15:15:29.

    SIte2\DC2 via RPC

        DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

        Last attempt @ 2011-07-10 10:39:19 was successful.



CN=Configuration,DC=domain,DC=local

    Site1\DC3 via RPC

        DC object GUID: a1075d5c-fca2-4b66-ae1f-27123dec4d13

        Last attempt @ 2011-07-10 09:54:24 failed, result 8524 (0x214c):

            Can't retrieve message string 8524 (0x214c), error 1815.

        2568 consecutive failure(s).

        Last success @ 2011-03-25 14:58:17.

    SIte2\DC2 via RPC

        DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

        Last attempt @ 2011-07-10 10:39:20 was successful.



CN=Schema,CN=Configuration,DC=domain,DC=local

    Site1\DC3 via RPC

        DC object GUID: a1075d5c-fca2-4b66-ae1f-27123dec4d13

        Last attempt @ 2011-07-10 09:54:26 failed, result 8524 (0x214c):

            Can't retrieve message string 8524 (0x214c), error 1815.

        2568 consecutive failure(s).

        Last success @ 2011-03-25 14:58:18.

    SIte2\DC2 via RPC

        DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

        Last attempt @ 2011-07-10 10:39:20 was successful.



DC=DomainDnsZones,DC=domain,DC=local

    Site1\DC3 via RPC

        DC object GUID: a1075d5c-fca2-4b66-ae1f-27123dec4d13

        Last attempt @ 2011-07-10 09:54:22 failed, result 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        2568 consecutive failure(s).

        Last success @ 2011-03-25 14:58:18.

    SIte2\DC2 via RPC

        DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

        Last attempt @ 2011-07-10 10:39:20 was successful.



DC=ForestDnsZones,DC=domain,DC=local

    Site1\DC3 via RPC

        DC object GUID: a1075d5c-fca2-4b66-ae1f-27123dec4d13

        Last attempt @ 2011-07-10 09:54:22 failed, result 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        2568 consecutive failure(s).

        Last success @ 2011-03-25 14:58:18.

    SIte2\DC2 via RPC

        DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

        Last attempt @ 2011-07-10 10:39:20 was successful.



Source: SIte2\DC2

******* 1 CONSECUTIVE FAILURES since 2011-07-10 10:09:20

Last error: 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.



Source: Site1\DC3

******* 2568 CONSECUTIVE FAILURES since 2011-03-25 15:15:29

Last error: 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.


============================

SIte2\DC2

DC Options: IS_GC

Site Options: (none)

DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

DC invocationID: ecdb72c5-c53b-447a-a858-6506473b2858



==== INBOUND NEIGHBORS ======================================



DC=domain,DC=local

    Site1\DC1 via RPC

        DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

        Last attempt @ 2011-07-10 07:59:48 failed, result 1722 (0x6ba):

            Can't retrieve message string 1722 (0x6ba), error 1815.

        8 consecutive failure(s).

        Last success @ 2011-07-09 11:34:04.



CN=Configuration,DC=domain,DC=local

    Site1\DC1 via RPC

        DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

        Last attempt @ 2011-07-10 08:00:09 failed, result 1722 (0x6ba):

            Can't retrieve message string 1722 (0x6ba), error 1815.

        7 consecutive failure(s).

        Last success @ 2011-07-09 11:34:06.



CN=Schema,CN=Configuration,DC=domain,DC=local

    Site1\DC1 via RPC

        DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

        Last attempt @ 2011-07-10 08:00:30 failed, result 1722 (0x6ba):

            Can't retrieve message string 1722 (0x6ba), error 1815.

        7 consecutive failure(s).

        Last success @ 2011-07-09 14:00:15.



DC=DomainDnsZones,DC=domain,DC=local

    Site1\DC1 via RPC

        DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

        Last attempt @ 2011-07-10 07:59:48 failed, result 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        8 consecutive failure(s).

        Last success @ 2011-07-09 10:00:18.



DC=ForestDnsZones,DC=domain,DC=local

    Site1\DC1 via RPC

        DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

        Last attempt @ 2011-07-10 07:59:48 failed, result 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        8 consecutive failure(s).

        Last success @ 2011-07-09 10:00:18.



Source: Site1\DC1

******* 8 CONSECUTIVE FAILURES since 2011-07-09 14:00:15

Last error: 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.


==================================================
ASKER
ManicD

repadmin /showrepl

=======================
FROM DC2
=======================
Site2\DC2

DC Options: IS_GC

Site Options: (none)

DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

DC invocationID: ecdb72c5-c53b-447a-a858-6506473b2858



==== INBOUND NEIGHBORS ======================================



DC=domain,DC=local

    Site1\DC1 via RPC

        DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

        Last attempt @ 2011-07-10 07:59:48 failed, result 1722 (0x6ba):

            Can't retrieve message string 1722 (0x6ba), error 1815.

        8 consecutive failure(s).

        Last success @ 2011-07-09 11:34:04.



CN=Configuration,DC=domain,DC=local

    Site1\DC1 via RPC

        DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

        Last attempt @ 2011-07-10 08:00:09 failed, result 1722 (0x6ba):

            Can't retrieve message string 1722 (0x6ba), error 1815.

        7 consecutive failure(s).

        Last success @ 2011-07-09 11:34:06.



CN=Schema,CN=Configuration,DC=domain,DC=local

    Site1\DC1 via RPC

        DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

        Last attempt @ 2011-07-10 08:00:30 failed, result 1722 (0x6ba):

            Can't retrieve message string 1722 (0x6ba), error 1815.

        7 consecutive failure(s).

        Last success @ 2011-07-09 14:00:15.



DC=DomainDnsZones,DC=domain,DC=local

    Site1\DC1 via RPC

        DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

        Last attempt @ 2011-07-10 07:59:48 failed, result 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        8 consecutive failure(s).

        Last success @ 2011-07-09 10:00:18.



DC=ForestDnsZones,DC=domain,DC=local

    Site1\DC1 via RPC

        DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

        Last attempt @ 2011-07-10 07:59:48 failed, result 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        8 consecutive failure(s).

        Last success @ 2011-07-09 10:00:18.



Source: Site1\DC1

******* 8 CONSECUTIVE FAILURES since 2011-07-09 14:00:15

Last error: 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.





=================================================================================







Site1\DC1

DC Options: IS_GC

Site Options: (none)

DC object GUID: f3b820e0-fa6e-478b-aabf-eb13934e370f

DC invocationID: 7cfc68b9-f57b-43f9-b542-58f6d564a6fc



==== INBOUND NEIGHBORS ======================================



DC=domain,DC=local

    site1\dc3 via RPC

        DC object GUID: a1075d5c-fca2-4b66-ae1f-27123dec4d13

        Last attempt @ 2011-07-10 10:54:22 failed, result 8524 (0x214c):

            Can't retrieve message string 8524 (0x214c), error 1815.

        2569 consecutive failure(s).

        Last success @ 2011-03-25 15:15:29.

    Site2\DC2 via RPC

        DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

        Last attempt @ 2011-07-10 10:55:29 failed, result 1722 (0x6ba):

            Can't retrieve message string 1722 (0x6ba), error 1815.

        1 consecutive failure(s).

        Last success @ 2011-07-10 10:39:19.



CN=Configuration,DC=domain,DC=local

    site1\dc3 via RPC

        DC object GUID: a1075d5c-fca2-4b66-ae1f-27123dec4d13

        Last attempt @ 2011-07-10 10:54:24 failed, result 8524 (0x214c):

            Can't retrieve message string 8524 (0x214c), error 1815.

        2569 consecutive failure(s).

        Last success @ 2011-03-25 14:58:17.

    Site2\DC2 via RPC

        DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

        Last attempt @ 2011-07-10 10:54:47 failed, result 1722 (0x6ba):

            Can't retrieve message string 1722 (0x6ba), error 1815.

        1 consecutive failure(s).

        Last success @ 2011-07-10 10:39:20.



CN=Schema,CN=Configuration,DC=domain,DC=local

    site1\dc3 via RPC

        DC object GUID: a1075d5c-fca2-4b66-ae1f-27123dec4d13

        Last attempt @ 2011-07-10 10:54:26 failed, result 8524 (0x214c):

            Can't retrieve message string 8524 (0x214c), error 1815.

        2569 consecutive failure(s).

        Last success @ 2011-03-25 14:58:18.

    Site2\DC2 via RPC

        DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

        Last attempt @ 2011-07-10 10:55:08 failed, result 1722 (0x6ba):

            Can't retrieve message string 1722 (0x6ba), error 1815.

        1 consecutive failure(s).

        Last success @ 2011-07-10 10:39:20.



DC=DomainDnsZones,DC=domain,DC=local

    site1\dc3 via RPC

        DC object GUID: a1075d5c-fca2-4b66-ae1f-27123dec4d13

        Last attempt @ 2011-07-10 10:54:22 failed, result 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        2569 consecutive failure(s).

        Last success @ 2011-03-25 14:58:18.

    Site2\DC2 via RPC

        DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

        Last attempt @ 2011-07-10 10:54:47 failed, result 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        1 consecutive failure(s).

        Last success @ 2011-07-10 10:39:20.



DC=ForestDnsZones,DC=domain,DC=local

    site1\dc3 via RPC

        DC object GUID: a1075d5c-fca2-4b66-ae1f-27123dec4d13

        Last attempt @ 2011-07-10 10:54:22 failed, result 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        2569 consecutive failure(s).

        Last success @ 2011-03-25 14:58:18.

    Site2\DC2 via RPC

        DC object GUID: 7ed37514-7623-4424-af99-b9329ce5a071

        Last attempt @ 2011-07-10 10:54:47 failed, result 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        1 consecutive failure(s).

        Last success @ 2011-07-10 10:39:20.



Source: site1\dc3

******* 2568 CONSECUTIVE FAILURES since 2011-03-25 15:15:29

Last error: 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.



Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER
ManicD

readmin /showconns

====================
FROM DC1
===================

Base DN: CN=Hazel,CN=Sites,CN=Configuration,DC=domain,DC=local

==== KCC CONNECTION OBJECTS ============================================

Connection --

    Connection name : 3c52adfb-b330-4c89-ad5e-84f39f480081

    Server DNS name : DC3.domain.local

    Server DN  name : CN=NTDS Settings,CN=DC3,CN=Servers,CN=Hazel,CN=Sites,CN=Configuration,DC=domain,DC=local

DsBindWithCred to DC3 failed with status 1722 (0x6ba):

    Can't retrieve message string 1722 (0x6ba), error 1815.

        Source: SIte2\DC2

                No Failures.

        TransportType: intrasite RPC

        options:  isGenerated

        ReplicatesNC: DC=DomainDnsZones,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: CN=Schema,CN=Configuration,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: CN=Configuration,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: DC=ForestDnsZones,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: DC=domain,DC=local

        Reason:  RingTopology

Connection --

    Connection name : a09f5096-0610-497a-b6c7-392132559125

    Server DNS name : DC3.domain.local

    Server DN  name : CN=NTDS Settings,CN=DC3,CN=Servers,CN=Hazel,CN=Sites,CN=Configuration,DC=domain,DC=local

        Source: SIte1\DC1

                No Failures.

        TransportType: intrasite RPC

        options:  isGenerated

        ReplicatesNC: DC=ForestDnsZones,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: DC=DomainDnsZones,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: CN=Schema,CN=Configuration,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: CN=Configuration,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: DC=domain,DC=local

        Reason:  RingTopology

Connection --

    Connection name : 356f7ffb-a0b6-42ca-8abc-5e21f3396e9a

    Server DNS name : DC1.domain.local

    Server DN  name : CN=NTDS Settings,CN=DC1,CN=Servers,CN=Hazel,CN=Sites,CN=Configuration,DC=domain,DC=local

        Source: SIte2\DC2

                No Failures.

        TransportType: IP

        options:  isGenerated

        ReplicatesNC: CN=Configuration,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=DomainDnsZones,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=ForestDnsZones,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

Connection --

    Connection name : 23d031d5-2332-4347-a335-551ffb07e4ec

    Server DNS name : DC1.domain.local

    Server DN  name : CN=NTDS Settings,CN=DC1,CN=Servers,CN=Hazel,CN=Sites,CN=Configuration,DC=domain,DC=local

        Source: SIte1\DC3

******* 2568 CONSECUTIVE FAILURES since 2011-03-25 15:15:29

Last error: 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        TransportType: intrasite RPC

        options:  isGenerated

        ReplicatesNC: DC=DomainDnsZones,DC=domain,DC=local

        Reason:  StaleServersTopology

                Replica link has been added.

        ReplicatesNC: CN=Schema,CN=Configuration,DC=domain,DC=local

        Reason:  StaleServersTopology

                Replica link has been added.

        ReplicatesNC: CN=Configuration,DC=domain,DC=local

        Reason:  StaleServersTopology

                Replica link has been added.

        ReplicatesNC: DC=ForestDnsZones,DC=domain,DC=local

        Reason:  StaleServersTopology

                Replica link has been added.

        ReplicatesNC: DC=domain,DC=local

        Reason:  StaleServersTopology

                Replica link has been added.

4 connections found.




=========================================================================================







Base DN: CN=York,CN=Sites,CN=Configuration,DC=domain,DC=local

==== KCC CONNECTION OBJECTS ============================================

Connection --

    Connection name : a93384ec-ccec-4331-819e-e8f1552a8aff

    Server DNS name : DC2.domain.local

    Server DN  name : CN=NTDS Settings,CN=DC2,CN=Servers,CN=York,CN=Sites,CN=Configuration,DC=domain,DC=local

        Source: SIte1\DC1

******* 8 CONSECUTIVE FAILURES since 2011-07-09 14:00:15

Last error: 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        TransportType: IP

        options:  isGenerated

        ReplicatesNC: CN=Configuration,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=DomainDnsZones,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=ForestDnsZones,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

1 connections found.



ASKER
ManicD

repadmin /showconn


==============
FROM DC2
===============


Base DN: CN=Site2,CN=Sites,CN=Configuration,DC=domain,DC=local

==== KCC CONNECTION OBJECTS ============================================

Connection --

    Connection name : a93384ec-ccec-4331-819e-e8f1552a8aff

    Server DNS name : DC2.domain.local

    Server DN  name : CN=NTDS Settings,CN=DC2,CN=Servers,CN=Site2,CN=Sites,CN=Configuration,DC=domain,DC=local

        Source: Site1\DC1

******* 9 CONSECUTIVE FAILURES since 2011-07-09 14:00:15

Last error: 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        TransportType: IP

        options:  isGenerated

        ReplicatesNC: CN=Configuration,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=DomainDnsZones,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=ForestDnsZones,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

1 connections found.






===================================================







Base DN: CN=Site1,CN=Sites,CN=Configuration,DC=domain,DC=local

==== KCC CONNECTION OBJECTS ============================================

Connection --

    Connection name : 3c52adfb-b330-4c89-ad5e-84f39f480081

    Server DNS name : DC3.domain.local

    Server DN  name : CN=NTDS Settings,CN=DC3,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=domain,DC=local

DsBindWithCred to DC3 failed with status 1722 (0x6ba):

    Can't retrieve message string 1722 (0x6ba), error 1815.

        Source: SIte2\DC2

                No Failures.

        TransportType: intrasite RPC

        options:  isGenerated

        ReplicatesNC: DC=DomainDnsZones,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: CN=Schema,CN=Configuration,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: CN=Configuration,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: DC=ForestDnsZones,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: DC=domain,DC=local

        Reason:  RingTopology

Connection --

    Connection name : a09f5096-0610-497a-b6c7-392132559125

    Server DNS name : DC3.domain.local

    Server DN  name : CN=NTDS Settings,CN=DC3,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=domain,DC=local

        Source: Site1\DC1

                No Failures.

        TransportType: intrasite RPC

        options:  isGenerated

        ReplicatesNC: DC=ForestDnsZones,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: DC=DomainDnsZones,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: CN=Schema,CN=Configuration,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: CN=Configuration,DC=domain,DC=local

        Reason:  RingTopology

        ReplicatesNC: DC=domain,DC=local

        Reason:  RingTopology

Connection --

    Connection name : 356f7ffb-a0b6-42ca-8abc-5e21f3396e9a

    Server DNS name : DC1.domain.local

    Server DN  name : CN=NTDS Settings,CN=DC1,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=domain,DC=local

        Source: SIte2\DC2

******* 1 CONSECUTIVE FAILURES since 2011-07-10 10:39:20

Last error: 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        TransportType: IP

        options:  isGenerated

        ReplicatesNC: CN=Configuration,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=DomainDnsZones,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=ForestDnsZones,DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

        ReplicatesNC: DC=domain,DC=local

        Reason:  IntersiteTopology

                Replica link has been added.

Connection --

    Connection name : 23d031d5-2332-4347-a335-551ffb07e4ec

    Server DNS name : DC1.domain.local

    Server DN  name : CN=NTDS Settings,CN=DC1,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=domain,DC=local

        Source: Site1\DC3

******* 2569 CONSECUTIVE FAILURES since 2011-03-25 15:15:29

Last error: 1256 (0x4e8):

            Can't retrieve message string 1256 (0x4e8), error 1815.

        TransportType: intrasite RPC

        options:  isGenerated

        ReplicatesNC: DC=DomainDnsZones,DC=domain,DC=local

        Reason:  StaleServersTopology

                Replica link has been added.

        ReplicatesNC: CN=Schema,CN=Configuration,DC=domain,DC=local

        Reason:  StaleServersTopology

                Replica link has been added.

        ReplicatesNC: CN=Configuration,DC=domain,DC=local

        Reason:  StaleServersTopology

                Replica link has been added.

        ReplicatesNC: DC=ForestDnsZones,DC=domain,DC=local

        Reason:  StaleServersTopology

                Replica link has been added.

        ReplicatesNC: DC=domain,DC=local

        Reason:  StaleServersTopology

                Replica link has been added.

4 connections found.



ASKER
ManicD

1. can you ping DC1 by ip address (ping 10.166.150.250) from DC2
 = time outs

2. can you ping DC2 by ip address (ping 10.0.0.250) from DC1
 = time outs






however, with host file entries

"I currently have DC2 dns settings on the LAN card set to DC1 external IP
I also have Host file records for

ON DC1
dc2 = to DC2 external IP
dc2.domain.local = to DC2 external IP

ON DC2
dc1 = to dc 1 external IP
dc1.domain.local = to dc 1 external IP"

i can ping the FQDNS




3. can you ping DC1 by FQDN (ping dc1.mycompany.local) from DC2
= YES

4. can you ping DC2 by FQDN (ping dc2.mycompany.local) from DC1
= YES


Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
ASKER
ManicD

Assuming you can at least ping each server by IP Address do the following....

On the server that you moved to the new site
- set the DNS server address on its NIC to be the DNS Server on the DC in the original site.      =========== DONE
- ipconfig /register dns              =============== DONE
- stop and restart the NETLOGON service              =============== DONE

After you have done the above check DNS on the server in the original site to ensure that the A Record for the Server that was moved to the new site is correct. =========== IT FAILED

Force Replication =========== FAILED

Check that DNS on the server in the new site is now correct, and change DNS on the NIC of the server in the new site back to point to itself. ============= N/A
ASKER
ManicD

================================
repadmin /replsum dc2 FROM DC1
===============================

Replication Summary Start Time: 2011-07-10 11:21:46



Beginning data collection for replication summary, this may take awhile:

  ....





Source DC           largest delta  fails/total  %%  error

 DC1         01d.01h:21m:28s    5 /   5  100  (1256) Can't retrieve message string 1256 (0x4e8), error 1815.





Destination DC    largest delta    fails/total  %%  error

 DC2          01d.01h:21m:29s    5 /   5  100  (1256) Can't retrieve message string 1256 (0x4e8), error 1815.





================================
repadmin /replsum dc1 FROM DC1
===============================



Replication Summary Start Time: 2011-07-10 11:21:59



Beginning data collection for replication summary, this may take awhile:

  ....





Source DC           largest delta  fails/total  %%  error

 DC3         >60 days            5 /   5  100  (8524) Can't retrieve message string 8524 (0x214c), error 1815.

 DC2                  12m:39s    0 /   5    0  




Destination DC    largest delta    fails/total  %%  error

 DC1        >60 days            5 /  10   50  (8524) Can't retrieve message string 8524 (0x214c), error 1815.





================================
repadmin /replsum dc1 FROM DC2
===============================

Replication Summary Start Time: 2011-07-10 11:24:45



Beginning data collection for replication summary, this may take awhile:

  ....









Destination DC    largest delta    fails/total  %%  error

 DC1       >60 days            8 /  10   80  (8524) Can't retrieve message string 8524 (0x214c), error 1815.




================================
repadmin /replsum dc2 FROM DC2
===============================







Replication Summary Start Time: 2011-07-10 11:24:51



Beginning data collection for replication summary, this may take awhile:

  ....





Source DC           largest delta  fails/total  %%  error

 dc1         01d.01h:24m:33s    5 /   5  100  (1256) Can't retrieve message string 1256 (0x4e8), error 1815.





Destination DC    largest delta    fails/total  %%  error

dc2          01d.01h:24m:33s    5 /   5  100  (1256) Can't retrieve message string 1256 (0x4e8), error 1815.


itubaf

sorry but could you please let me know what procedure you followed while moving AD SITE and services? step by step would be highly appreciated.
even if you have two subnets you dont need to move AD you can simply create one more subnet in DNS and all host record associate to other site DNS will come in new section.......

Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
Syed_M_Usman

i do agree with itubaf....
ASKER
ManicD

opened up sites and services,

created new site,
set up subnet for new site
then right click on DC2 and selected move.

allowed 15 mins between each action to keep everything replicated


i do need to setup the additional sites as we have plans to install exchange on both sites in a few weeks,
i needed the servers setup for DFS file  replication, so that clients access the local site for files
and we have an issue that ever two weeks or so the VPN drops out (ISP are looking into it) but by building teh system correctly it shouldn't matter so much
Andrew Oakeley

I am going to get on (another) plane, but I will leave you with this thought. The fact that you can not ping each server from the other server then you have a problem. I do not think that trying to trick the server to ignore DNS and port forwarding the wan IP on the router is a sustainable solution. You may get it to work, but it isn't right.

Andy
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
ASKER
ManicD

I do agree,  but right now i need a temp solution untill such time as i can get the isp to configure the vpn correcly to route traffic, not even 100% that that is the cause
ASKER CERTIFIED SOLUTION
ManicD

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
ASKER
ManicD

Long time to figure out but thought i would leave the answer for future people to see