?
Solved

Active Directory Domain Controller

Posted on 2014-09-17
3
Medium Priority
?
109 Views
Last Modified: 2015-01-26
I found the following errors on our monitoring software zenos this morning, and am wondering how this issue could have occurred as well as best practice for correcting them.

"This is the replication status for the following directory partition on this directory server. Directory partition: DC=ForestDnsZones,DC=,DC=com This directory server has not recently received replication information from a number of directory servers. The count of directory servers is shown, divided into the following intervals. More than 24 hours: 3 More than a week: 3 More than one month: 3 More than two months: 2 More than a tombstone lifetime: 2 Tombstone lifetime (days): 60 Directory servers that do not replicate in a timely manner may encounter errors. They may miss password changes and be unable to authenticate. A DC that has not replicated in a tombstone lifetime may have missed the deletion of some objects, and may be automatically blocked from future replication until it is reconciled. To identify the directory servers by name, use the dcdiag.exe tool. You can also use the support tool repadmin.exe to display the replication latencies of the directory servers. The command is "repadmin /showvector /latency ".
0
Comment
Question by:cbarber22
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 16

Expert Comment

by:Syed_M_Usman
ID: 40328437
how many DC's you have in your Forest? how many sites you have?
try repadmin /showrepl in any Dc and check replication ststus.
0
 

Author Comment

by:cbarber22
ID: 40328457
I just started at this business they have 5 DC/ with 3 sites.
0
 
LVL 35

Accepted Solution

by:
Seth Simmons earned 2000 total points
ID: 40328777
did you run dcdiag and repadmin as stated in your first post?
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Here's a look at newsworthy articles and community happenings during the last month.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses
Course of the Month11 days, 18 hours left to enroll

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question