• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 55
  • Last Modified:

AD sync issues

We're currently on exchange 2003 sp2.  Our exchange and ad are on the same server.  We are working with consultants to upgrade but in the meantime we're experiencing problems.  We have not upgraded or implemented anything yet.  Late last week our server rebooted itself 3 times.  FYI, automatic updates is turned off.  It stopped doing that but now we're finding some ldap syncs breaking with 3rd party software.   FYI, we've not changed anything.  We have 3 domain controllers.  They are virtualized.  

I'm seeing a lot of NetBT event ID 4321 errors.   . .  could not be registered on the interface with IP address domain controller.  The machine with the IP address primary domain controller did not allow the name to be claimed by the machine.  And event id 2093 and 1864.  Worried if we're having replication problems.  Don't even know where to start. Any help would be appreciated.
0
GCBIT
Asked:
GCBIT
  • 4
  • 2
1 Solution
 
TORLYSITCommented:
You may want to check and make sure your WINS servers are healthy? Check to see if the IP address(es) of your primary and secondary WINS server(s) on the server's network adapter are correct.

Also, check to see if your WINS servers are reporting any errors of their own?

I would definitely recommend you separate your DC and Exchange servers.
0
 
GCBITAuthor Commented:
Just find out my admin made a snapshot of the server, tried to update the vmware tools.  It didn't work so he went back to the snapshot.  I think this is what caused the problem.  I found this article http://support.microsoft.com/kb/2023007 and trying to figure out what to do.
0
 
GCBITAuthor Commented:
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

 
GCBITAuthor Commented:
i don't think that's it.  We're not getting event id 2095.  Just found out he had installed symantec shortly before the issues starting happening.  So we receive event id 2093 and 1864 every night around 9:58 pm.
0
 
TORLYSITCommented:
Event ID 1864 just advises that the DC has not recieved a replication in 24 hours.

If the second article you posted is correct, you need to resync the DC. There is no real easy way.

1. DCPROMO and demote the DC. (MAKE SURE YOU TRANSFER FSMO ROLES OFF THIS BOX FIRST!)
2. Shut down the demoted server.
3. Log onto another DC on your domain and do a Metadata cleanup. (http://support2.microsoft.com/kb/216498)
4. Restart the demoted DC
5. Promote it back to DC and reconfigure as before.

If the DC was snapshoted and reset, the AD database it came back with was not the one that AD was expecting and caused some sync issues.

Domain Controllers are one of the few servers where a snapshot is not recommended. Backup your LDAP database and restore it onto a fresh Domain Controller in the event of catastrophe. If you have more than one DC, just promote a server to DC and pick up where you left off.
0
 
GCBITAuthor Commented:
looks like we have 3 domain controllers:
server A runs all the FSMO roles & is the GD
server B is the server that was reverted to snapshot and has exchange and ad
server C runs our intranet

Would I just demote server b or server b & c?
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 4
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now