Solved

Active Directory 2003 High Replication

Posted on 2014-01-02
6
222 Views
Last Modified: 2014-02-05
Hello experts,

We have a domain reporting very high replication traffic. Do you have any suggestions on what tool/s I could use to determine where or what source it is coming from?

Thank you!
0
Comment
Question by:syseng007
6 Comments
 

Author Comment

by:syseng007
ID: 39752325
..
0
 
LVL 19

Expert Comment

by:helpfinder
ID: 39752345
0
 

Author Comment

by:syseng007
ID: 39752382
I actually meant what application is triggering the high replication.......thanks again.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 39753208
If this is AD replication traffic, you may run in command-line on your DC this command

repadmin /replsummary

Open in new window


and you will see how much time the replication took and how many objects were replicated

Regards,
Krzysztof
0
 
LVL 24

Accepted Solution

by:
Sandeshdubey earned 500 total points
ID: 39755702
High bandwidth utilization between DCs
http://www.frickelsoft.net/blog/?p=185

You can use Netmon or Wireshark to capture the traffic & analyze the packet from where they are coming.

Check the zone type and change to Forestdnszone or domain dns zone if it set to All domain controllers in this domain (for Windows 2000 compatibility) :http://technet.microsoft.com/en-us/library/%20cc730964

Also verify the health of dcs by dcdiag /q and repadmin /replsum and post the log if error is reported.
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39757246
AD replication and application replication are two different terms
Because most of the applications use AD for authentication and few applications like MS Exchange adds attributes with values in AD that's get replicated across.
Are you talking about authentication traffic getting increased by AD integrated applications \ native AD authentication by users \ computers ?
If any application is storing data in AD application directory partitions, it can cause trigger replication, but I don't think it can create Hugh replication traffic because basic purpose of AD application directory partitions is to limit the replication traffic exposing to all DCs and its most probably static contents hopefully.
http://technet.microsoft.com/en-us/library/cc784421(v=ws.10).aspx

How big is you AD environment in terms of users \ computers \ and how frequently  you change active directory objects by any AD integrated applications ?
Also what is the replication interval between all sites and what is the minimum bandwidth between sites?

You can also capture traffic form individual applications to AD with netmon, wireshark etc as suggest by Sandesh above

At a minimum, since you have 2003 active directory,
You need to raise your domain and forest functional level to windows 2003 to enable Linked Value replication (LVR), a technology established with 2003 AD to replicate incremental changes only as opposed to full replication occurring in windows 2000 domain

Increasing the forest functional level to Windows Server 2003 interim or higher does not modify the way that existing group members are stored or replicated. To do that, you must remove the members that were added to the group before the forest functional level was increased to Windows Server 2003 and then add them back again to the appropriate groups. Any group members that you either add or remove after the forest functional level is increased will be LVR enabled, even if the group contains other members that are not LVR enabled

Check below section in MS article for more information
Recommended Maximum Number of Users in a Group

Mahesh
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I know all systems administrator at some time or another has had to create a script to copy file from a server share to a desktop. Well now there is an easy way to do this in Group Policy. Using Group policy preferences is not hard. The first thing …
Do you have users whose passwords are expiring and they are constantly calling you?  Well I sure did and needed a way to put an end to this.  We have a lot of remote users which would not be notified that their passwords were expiring since they wer…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

26 Experts available now in Live!

Get 1:1 Help Now