Link to home
Create AccountLog in
Avatar of eloredo
eloredoFlag for United States of America

asked on

Multiple Domain Controllers and one failed

Hi, I have three sites connected via Sonicwall VPN.  Site A hosts 3 Domain Controllers (1 x 2008 and 2 x 2003).  Site B and Site C, each have their own Domain Controller (each on 2003).  All sites replicate to the same domain and forest.  Recently, one of the original domain controllers in Site A went down and would not come back up.  So I officially seized the FSMO roles onto one of the other domain controllers in Site A and removed the dead domain controller from the domain.  All Site A and B domain controllers are working fine.

However, Site C domain controller will no longer replicate.  I checked Sites and Services/NTDS settings and confirmed that Site C was automatically replicating to the dead domain controller. When trying to manually replicate I get the below error.  I also went into properties and can change to an active domain controller in site a but still get the same error.  Unfortunately, this is has been an issue for over 30 days now.

Is there another way to reconnect this domain controller to the site a domain controllers?
error1.png
Avatar of sharjeel ashraf
sharjeel ashraf
Flag of United Kingdom of Great Britain and Northern Ireland image

check your DNS settings for the domain controller, can you ping the fqdn of a domain controller in site a or b from site c.

if they seem correct point the controllers DNS settings to the main controller at site A and reboot, then try to configure site replication.
Avatar of eloredo

ASKER

Correction, this issue has been over 60days now and I did a DCDIAG and got the below.  In addition, Site B does not replicate with Site C, both Site B and Site C replicate directly to SITE A only.  Also, Site C does not that the FSMO roles have been changed because I did that with SITE A after the original DC died.  I am afraid to make changes like that to Site C because I am not sure what that will do to Site A when they replicate.




               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from SITE_A_DC1 at 2013-04-25 10:37:50.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from DEAD_DC at 2013-04-25 10:42:08.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

            DC=ForestDnsZones,DC=corp,DC=CONTOSO,DC=com
               Last replication recieved from SITE_B_DC1 at 2013-04-25 10:23:36.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from SITE_A_DC2 at 2013-04-25 10:27:16.

               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from SITE_A_DC1 at 2013-04-25 10:27:27.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from DEAD_DC at 2013-04-25 10:42:08.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

            CN=Schema,CN=Configuration,DC=corp,DC=CONTOSO,DC=com
               Last replication recieved from SITE_B_DC1 at 2013-04-25 09:38:37.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from SITE_A_DC2 at 2013-04-25 09:48:44.

               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from SITE_A_DC1 at 2013-04-25 09:48:44.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from DEAD_DC at 2013-04-25 10:42:08.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

            CN=Configuration,DC=corp,DC=CONTOSO,DC=com
               Last replication recieved from SITE_B_DC1 at 2013-04-25 09:38:36.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from SITE_A_DC2 at 2013-04-25 09:48:44.

               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from SITE_A_DC1 at 2013-04-25 10:37:41.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from DEAD_DC at 2013-04-25 10:42:08.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

            DC=corp,DC=CONTOSO,DC=com
               Last replication recieved from SITE_B_DC1 at 2013-04-25 10:38:36.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from SITE_A_DC2 at 2013-04-25 10:41:32.

               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from SITE_A_DC1 at 2013-04-25 10:41:43.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

               Last replication recieved from DEAD_DC at 2013-04-25 10:42:08.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

         ......................... SITE_C_DC1 passed test Replications
      Starting test: NCSecDesc
         ......................... SITE_C_DC1 passed test NCSecDesc
      Starting test: NetLogons
         ......................... SITE_C_DC1 passed test NetLogons
      Starting test: Advertising
         ......................... SITE_C_DC1 passed test Advertising
      Starting test: KnowsOfRoleHolders
         [DEAD_DC] DsBindWithSpnEx() failed with error 1722,
         The RPC server is unavailable..
         Warning: DEAD_DC is the Schema Owner, but is not responding to DS RPC B
ind.
         [DEAD_DC] LDAP search failed with error 58,
         The specified server cannot perform the requested operation..
         Warning: DEAD_DC is the Schema Owner, but is not responding to LDAP Bin
d.
         Warning: DEAD_DC is the Domain Owner, but is not responding to DS RPC B
ind.
         Warning: DEAD_DC is the Domain Owner, but is not responding to LDAP Bin
d.
         Warning: DEAD_DC is the PDC Owner, but is not responding to DS RPC Bind
.
         Warning: DEAD_DC is the PDC Owner, but is not responding to LDAP Bind.
         Warning: DEAD_DC is the Rid Owner, but is not responding to DS RPC Bind
.
         Warning: DEAD_DC is the Rid Owner, but is not responding to LDAP Bind.
         Warning: DEAD_DC is the Infrastructure Update Owner, but is not respond
ing to DS RPC Bind.
         Warning: DEAD_DC is the Infrastructure Update Owner, but is not respond
ing to LDAP Bind.
         ......................... SITE_C_DC1 failed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... SITE_C_DC1 failed test RidManager
      Starting test: MachineAccount
         ......................... SITE_C_DC1 passed test MachineAccount
      Starting test: Services
         ......................... SITE_C_DC1 passed test Services
      Starting test: ObjectsReplicated
         ......................... SITE_C_DC1 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... SITE_C_DC1 passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... SITE_C_DC1 failed test frsevent
      Starting test: kccevent
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 07/18/2013   16:20:08
            Event String: All domain controllers in the following site that
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 07/18/2013   16:20:08
            Event String: All domain controllers in the following site that
         An Error Event occured.  EventID: 0xC000051F
            Time Generated: 07/18/2013   16:20:08
            Event String: The Knowledge Consistency Checker (KCC) has
         An Warning Event occured.  EventID: 0x80000749
            Time Generated: 07/18/2013   16:20:08
            Event String: The Knowledge Consistency Checker (KCC) was
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 07/18/2013   16:20:08
            Event String: All domain controllers in the following site that
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 07/18/2013   16:20:08
            Event String: All domain controllers in the following site that
         An Error Event occured.  EventID: 0xC000051F
            Time Generated: 07/18/2013   16:20:08
            Event String: The Knowledge Consistency Checker (KCC) has
         An Warning Event occured.  EventID: 0x80000749
            Time Generated: 07/18/2013   16:20:08
            Event String: The Knowledge Consistency Checker (KCC) was
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 07/18/2013   16:20:08
            Event String: All domain controllers in the following site that
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 07/18/2013   16:20:08
            Event String: All domain controllers in the following site that
         An Error Event occured.  EventID: 0xC000051F
            Time Generated: 07/18/2013   16:20:08
            Event String: The Knowledge Consistency Checker (KCC) has
         An Warning Event occured.  EventID: 0x80000749
            Time Generated: 07/18/2013   16:20:08
            Event String: The Knowledge Consistency Checker (KCC) was
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 07/18/2013   16:20:08
            Event String: All domain controllers in the following site that
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 07/18/2013   16:20:08
            Event String: All domain controllers in the following site that
         An Error Event occured.  EventID: 0xC000051F
            Time Generated: 07/18/2013   16:20:08
            Event String: The Knowledge Consistency Checker (KCC) has
         An Warning Event occured.  EventID: 0x80000749
            Time Generated: 07/18/2013   16:20:08
            Event String: The Knowledge Consistency Checker (KCC) was
         An Warning Event occured.  EventID: 0x80000785
            Time Generated: 07/18/2013   16:22:15
            Event String: The attempt to establish a replication link for
         An Warning Event occured.  EventID: 0x80000785
            Time Generated: 07/18/2013   16:22:16
            Event String: The attempt to establish a replication link for
         An Warning Event occured.  EventID: 0x80000785
            Time Generated: 07/18/2013   16:22:16
            Event String: The attempt to establish a replication link for
         An Warning Event occured.  EventID: 0x80000785
            Time Generated: 07/18/2013   16:22:16
            Event String: The attempt to establish a replication link for
         An Warning Event occured.  EventID: 0x80000785
            Time Generated: 07/18/2013   16:22:17
            Event String: The attempt to establish a replication link for
         An Warning Event occured.  EventID: 0x80000785
            Time Generated: 07/18/2013   16:22:17
            Event String: The attempt to establish a replication link for
         ......................... SITE_C_DC1 failed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:30:01
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:30:53
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:31:27
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:31:39
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x00000423
            Time Generated: 07/18/2013   15:31:39
            Event String: The DHCP service failed to see a directory server
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:32:24
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:37:50
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:39:53
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:39:54
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:40:37
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:40:38
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:53:15
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:55:47
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   15:56:46
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   16:04:24
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   16:05:32
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   16:13:41
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   16:14:30
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 07/18/2013   16:15:00
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   16:15:33
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   16:15:41
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   16:22:16
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   16:24:26
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   16:24:38
            Event String: The kerberos client received a
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 07/18/2013   16:24:50
            Event String: The kerberos client received a
         ......................... SITE_C_DC1 failed test systemlog
      Starting test: VerifyReferences
         ......................... SITE_C_DC1 passed test VerifyReferences

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : corp
      Starting test: CrossRefValidation
         ......................... corp passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... corp passed test CheckSDRefDom

   Running enterprise tests on : corp.CONTOSO.com
      Starting test: Intersite
         ......................... corp.CONTOSO.com passed test Intersite
      Starting test: FsmoCheck
         Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355
         A Primary Domain Controller could not be located.
         The server holding the PDC role is down.
         ......................... corp.CONTOSO.com failed test FsmoCheck

C:\Program Files\Support Tools>^A
theres not a lot you can do other then remove then demote the DC and promote back to a DC, it should work as long as theres nothing unique on the server, i.e. exchange or something, what services do run on the server.

File share
DNS
DHCP
WINS
Avatar of eloredo

ASKER

I verified that the server can ping the FDQN of the domain controllers in SITE A.  I made sure the local nic card has the SITEA domain controllers/dns listed as DNS servers and verified that the DNS forwarding on the DNS server is also pointed to the domain controllers.  I am waiting for the last user to leave the office for the reboot.  The server roles are:  AD, DHCP, DNS, File Share and DFSshare (syncing files with the file server/domain controller in SITE A).  That is all, this SITE C domain contoller has NO WINS, Exchange, SQL, etc.  Does the DFSsharing rely on the server being a domain controller or does it not care?

That said, if I run dcpromo on the SITE C domain controller to demote, reboot, and rerun dcpromo to promote back, will that have any problems since I assume the Site A domain controllers will not know it was demoted?

Thanks for all the responses so far.
SOLUTION
Avatar of sharjeel ashraf
sharjeel ashraf
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
See answer
Avatar of eloredo

ASKER

Ok, thanks.  Trying the the demote process now as the reboot did not resolve.  Will the demote process affect the dfs sharing?  I know that since the issue began, the dfs sharing has stopped as well.
unsure, i have setup dfs on non domain controllers, but you have to remember that this server is not being seen by any of the other servers as a DC so it can not communicate the DFS stuff to the other servers until it rejoins the domain.
ASKER CERTIFIED SOLUTION
Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
Avatar of eloredo

ASKER

Thanks everyone!  It worked.  AD is back online.  Unfortunately, I have to readd the 5 computers back to the domain in this office because they lost the trust relationship with the domain but I am almost done so it is all good.