Solved

2003 + 2008R2 DC FSMO Transfer and Replication Issues

Posted on 2014-09-30
6
501 Views
Last Modified: 2014-10-02
Hello,

We seem to be experiencing issues with AD replication after adding two Server 2008 R2 servers to a 2003 domain with existing Server 2003 DCs.  I'm not sure where to continue troubleshooting at this point.

We have 3 existing Server 2003 DCs, and are adding 2 new Server 2008R2 DCs.  So far, what I've done is moved the Schema Master, Domain Naming Master, and PDC roles over to one of the 2008 R2 servers.  This doesn't seem to cause any issues, and I can see from several machines that the roles have transferred (through 'netdom query fsmo', or through the GUI).  However, when I attempt to transfer the remaining roles over to the second new DC, the role owner simply shows up as 'ERROR' in the GUI, and doesn't display any owner for those two remaining roles in the command line.

I am noticing some warnings in the Event log, which seem to have something to do with replication.

Event ID 1925 - The attempt to establish a replication link for the following writable directory partition failed.  
(The Source directory service is the 2nd new DC.

Right now, both new DCs are pointed to the same DNS server.  I have tested remote EventViewer between the DCs to ensure that RPC is working.  I am attaching two DCDiags.  DC1 is the original Server 2003 DC which held all of the FSMO roles initially.  DC4 is the new DC, which I have attempted to transfer Infrastructure and RID roles to unsuccessfully.

All suggestions are greatly appreciated.
DC1-Diag.txt
DC3-diag.txt
0
Comment
Question by:ClearBlueTechnologies
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 40353846
What functional level is the domain? Did you get the adprep folder from your 08 install and run these commands?
http://blogs.technet.com/b/omers/archive/2010/06/30/step-by-step-guide-for-upgrading-active-directory-from-microsoft-windows-2003-to-microsoft-windows-server-2008.aspx
0
 
LVL 1

Author Comment

by:ClearBlueTechnologies
ID: 40354428
Aaron, the functional level is 2003.  Yes, I went through the adprep using adprep from the Server 2008R2 installation CD.  At first, I only did adprep /forestprep and adprep /domainprep /gpprep.  I did adprep /rodcprep after I noticed we were having some issues.
0
 
LVL 39

Accepted Solution

by:
Aaron Tomosky earned 500 total points
ID: 40355154
1. did you run those commands on the schema master? If not, run them again on the 2008 server now that it's the schema master
2. is sites and services showing your DCs in the right locations?
3. does adrepstatus show errors? http://www.microsoft.com/en-us/download/details.aspx?id=30005
4. also check your dns settings, what I have done in the past is set all dcs to the new dc with only one dns entry, I also force replication through sites and services between each change in roles.

Even though it's for 2012, this site has some good commands to check the health of the domain and the schema level
http://blogs.msmvps.com/mweber/2012/07/27/upgrading-an-active-directory-domain-from-windows-server-2008-or-windows-server-2008-r2-to-windows-server-2012/
0
Free Webinar: AWS Backup & DR

Join our upcoming webinar with experts from AWS, CloudBerry Lab, and the Town of Edgartown IT to discuss best practices for simplifying online backup management and cutting costs.

 
LVL 37

Expert Comment

by:Mahesh
ID: 40355283
There must be some DNS and replication issues, as a fact DCs are unable to find server holding FSMO roles correctly
On all domain controllers run netdom query fsmo and ensure that all output is showing same results
Check DNS records [CNAME, NS and Host(A)] are correct on all domain controllers
Check under _msdcs.domain.com zone if there are CNAME records are available for each DC and it resolves to correct domain controllers IP and host name
If any CNAME record is not resolved, just navigate to AD sites \ sitename \ server \servername \ntds seting properties and from general tab copy CNAME and make new record
once your DNS issues get resolved and replication gets restored correctly you will get correct picture of FSMO roles

Also ensure that no lingering objects exists on any DCs
http://technet.microsoft.com/en-us/library/cc949124(v=ws.10).aspx
http://technet.microsoft.com/en-us/library/cc949134(v=ws.10).aspx
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 40355335
was this an upgrade of a 2000 ad? if so, you may be missing the top level _msdcs.domain.com folder in dns.
http://support2.microsoft.com/kb/817470/en-us
0
 
LVL 1

Author Closing Comment

by:ClearBlueTechnologies
ID: 40357018
It turned out to be an RPC issue caused by our firewalls on the new servers.  I wasn't aware of the ADRepstatus tool suggested by Aaron Tomosky, which revealed the issue pretty clearly.  I used ADRepstatus in combination with Portqry.exe to verify that the necessary ports were not open, which was causing all kinds of replication issues.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question