Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

DFS File Replication

Posted on 2013-11-05
18
Medium Priority
?
412 Views
Last Modified: 2013-12-06
I have my main DC which is the fismo master. I also have 5 other DC's as site links that need to be replicated. I am having a serious problem with with one of the DC's not being able to replicate system volume group. I receive the event id 5002 and additionally error 1825 (security package specific error). I can ping adn nslookup brings up correct DNS server which is the fismo from the other DC sitelink. I have also checked to see if there is enough space on the sitelink DC for replication which there is. Unfortunately, the sitelink DC hosts our virtual servers and is our pipline to the internet. Please advise....

Thank you in advance,
Wendy
0
Comment
Question by:wmbuchan2013
18 Comments
 

Author Comment

by:wmbuchan2013
ID: 39624454
Also, I looke up the DNS events from DC sitelkink and found error 4013 AD DS is waiting for the signal that the initial synchronization of the directory has completed.

Thanks again in advance,
Wendy
0
 
LVL 27

Expert Comment

by:Blue Street Tech
ID: 39626641
What server OS versions are we dealing with here?
0
 

Author Comment

by:wmbuchan2013
ID: 39628302
DC's are all win 2008 server R2 standard with the exception of the fismo DC which has the enterprise version of 2008 R2. The workstations are all win 7.
0
Lessons on Wi-Fi & Recommendations on KRACK

Simplicity and security can be a difficult  balance for any business to tackle. Join us on December 6th for a look at your company's biggest security gap. We will also address the most recent attack, "KRACK" and provide recommendations on how to secure your Wi-Fi network today!

 
LVL 24

Expert Comment

by:Mike Thomas
ID: 39628401
On the problematic dc, could you run dcdiag /test:dns and post the output.

Can you go into all DC's into the main yourdomain.whatever zone and note the number of  records that you have, let me know if there is any major (more than 5) difference. (basic simple visual check for replication issues)

Could you also download, install and run this tool on the problematic DC and your PDC, just post any issues it shows. http://www.microsoft.com/en-gb/download/details.aspx?id=30005
0
 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 39629336
I will recommend to also run dcdiag /q and repadmin /replsum and post the log.Most of the time replication issue is due to dns misconfig ensure that you have set dns as this:http://abhijitw.wordpress.com/2012/03/03/best-practices-for-dns-client-settings-on-domain-controller/
0
 

Author Comment

by:wmbuchan2013
ID: 39640120
I have attached the dcdiag test for your review. I am now downloading the replication tool on both DC's.

Thank you very much!
dcdiagdnstest.txt
0
 

Author Comment

by:wmbuchan2013
ID: 39640518
Hi All,

Here is the file after running the replication tool. The DC that it was ran on is the FISMO Master. I will also run the tool on our virtual 2012 DC and post that as well.

Again, thanks for all of your help!
ADReplicationStatus.2013.11.11.1.csv
0
 

Author Comment

by:wmbuchan2013
ID: 39641648
Hi to all,

I wanted to update you on DC's. The BL-DC is going to be demoted and powered down, I didn't want you to have that error be part of our problem solving.

Hoping all have a great day!
0
 

Author Comment

by:wmbuchan2013
ID: 39642874
Attached is the problematic DC's DNS test. I noticed that the DNS server is being referenced as 192.168.244.1.... The DNS server is 192.168.244.2 .. maybe this might be the beginning of the light in the tunnel.

Let me know your thoughts1
Wendy
dcdiagdnstestbjprob.txt
0
 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 39643451
The dcdiag output indicates dns forwarder failed,you can contact ISP to get the valid forwarders.Can you post the dcdiag /q and repadmin /replsun from all DC to get the clear view of AD health.

If you are planning to remove BL-DC perform normal demotion and check.If this is faulty server which is causing the issue and normal demotion is not possible perform forcefull demotion followed by metadata cleanup.
http://msmvps.com/blogs/acefekay/archive/2010/10/05/complete-step-by-step-to-remove-an-orphaned-domain-controller.aspx
0
 

Author Comment

by:wmbuchan2013
ID: 39643639
Thank you  Sandeshdubey! I will finish up and post the output for both dcdiag /q and repad min /repel sum.

Thanks again,
Wendy
0
 

Author Comment

by:wmbuchan2013
ID: 39669224
Hi again,

Attached are the dc's dcdiag /q and repadmin /replsum from all dc's in forest.
bj-dc.txt
br-dc.txt
pk-dc.txt
wd-dc.txt
hq-dc-fismo.txt
0
 

Author Comment

by:wmbuchan2013
ID: 39669233
Thanks again, hopefully it won't be too painful!

Wendy
0
 

Author Comment

by:wmbuchan2013
ID: 39669653
i wanted to make sure I posted the DNS test after changing to correct DNS Server IP. Forwarders are now all valid!
dcdiag-test-after-dns-chg.txt
0
 
LVL 24

Accepted Solution

by:
Sandeshdubey earned 2000 total points
ID: 39670911
You are getting the error "The RPC server is unavailable" relates to port being blocked or network connectivity issue or due to dns misconfig or it could be due to AD sites and services not configured as per physical topology.I would suggest contact network/security team to verify whether all the related AD ports being configured and allowed on the firewall for communication. Portquery is free tool from the MS which can be downloaded and installed to verify the necessary ports are opened or not.

Also, disable local windows firewall service, by default it is enabled in vista/windows 2008 and above. Check the network connectivity and latency.
Disable Windows Firewall: http://technet.microsoft.com/en-us/library/cc766337(WS.10).aspx

It can also be caused by antivirus software with many of them sporting a new feature called "network traffic protection," which can efffectively block necessary AD traffic

Active Directory and Active Directory Domain Services Port Requirements
http://technet.microsoft.com/en-us/library/dd772723%28WS.10%29.aspx

Troubleshooting “RPC server is unavailable” error, reported in failing AD replication scenario.
http://blogs.technet.com/b/abizerh/archive/2009/06/11/troubleshooting-rpc-server-is-unavailable-error-reported-in-failing-ad-replication-scenario.aspx
0
 

Author Comment

by:wmbuchan2013
ID: 39674774
Thank you so much, I have already found DC's are running local firewall, I am going to connect to each DC and make sure all local FW's are disabled.
0

Featured Post

WatchGuard Case Study: NCR

With business operations for thousands of customers largely depending on the internal systems they support, NCR can’t afford to waste time or money on security products that are anything less than exceptional. That’s why they chose WatchGuard.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
In this blog we highlight approaches to managed security as a service.  We also look into ConnectWise’s value in aiding MSPs’ security management and indicate why critical alerting is a necessary integration.
In this video tutorial I show you the main steps to install and configure  a VMware ESXi6.0 server. The video has my comments as text on the screen and you can pause anytime when needed. Hope this will be helpful. Verify that your hardware and BIO…
This course is ideal for IT System Administrators working with VMware vSphere and its associated products in their company infrastructure. This course teaches you how to install and maintain this virtualization technology to store data, prevent vuln…

886 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question