New 2012 Child DC added to existing Domain roll out Event ID 1864

It suggests running dcdiag and repadmin /showvector...
When I run repadmin I see the first 5 items are not named.  Are there things that can be removed or should I be concerned?  (see attached)

DCDIAG shows all test pass except one:
               Starting test: KnowsOfRoleHolders
         [BQDC2] DsBindWithSpnEx() failed with error 1722,
         The RPC server is unavailable..
         Warning: BQDC2 is the Schema Owner, but is not responding to DS RPC
         Bind.
         Ldap search capability attribute search failed on server BQDC2, return
         value = 81
         Warning: BQDC2 is the Schema Owner, but is not responding to LDAP
         Bind.
         Warning: BQDC2 is the Domain Owner, but is not responding to DS RPC
         Bind.
         Warning: BQDC2 is the Domain Owner, but is not responding to LDAP
         Bind.
         ......................... NADC1 failed test KnowsOfRoleHolders
Capture.JPG
bergquistcompanyAsked:
Who is Participating?

[Webinar] Streamline your web hosting managementRegister Today

x
 
MaheshConnect With a Mentor ArchitectCommented:
You need to go to Ad sites and services and from there navigate to Site\servers\ntds settings properties and on general tab you will find GUID of affected DC

Mahesh
0
 
Mike KlineCommented:
Is BQDC2 your current FSMO holder and online?   Lets start with the RPC errors and go through the steps outlined here  

http://technet.microsoft.com/library/replication-error-1722-the-rpc-server-is-unavailable(WS.10).aspx

Thanks

Mike
0
 
Will SzymkowskiSenior Solution ArchitectCommented:
It appears that the connection between BQDC2 and NADC1 are not consistent. Can you remove the automatic conneciton in sites and services and manually create a connection so that the DC's can replicate the information (this is only temporary).

Also make sure that your DNS is set correctly as this can be the reason for the error you are encountering.

Take a look at the following KB article as it illustrats a whole host of steps to troubleshoot this issue.

Troubleshooting Steps for Event 1722

Will.
0
SMB Security Just Got a Layer Stronger

WatchGuard acquires Percipient Networks to extend protection to the DNS layer, further increasing the value of Total Security Suite.  Learn more about what this means for you and how you can improve your security with WatchGuard today!

 
bergquistcompanyAuthor Commented:
Services are started/stopped accordingly
HKLM\Software\Microsoft\Rpc - there
DCDIAG /TEST:DNS /V /E /F:<filename.log> - still running
NLTest - completed successfully
no netdiag 2012
Ping - a worked
dnslint /s IP /ad IP - not on 2012
no firewall between
0
 
MaheshArchitectCommented:
From other DCs in child domain and parent check if you are able to resolve FSMO roles ?

netdom query fsmo

Also if this is new child Domain, check if domaindnszones folder is populated or not as it is the culprit who never populated immediately and creates problem.

If this is child DC in existing domain, then manually add NS entry in dns zone and check

Mahesh
0
 
bergquistcompanyAuthor Commented:
it appears under the _.msds one of the DCs didn't populate.  I can add  it but how do I know the GUID?
0
All Courses

From novice to tech pro — start learning today.