Solved

SYSVOL file replication failing and RSOP failures

Posted on 2014-10-29
4
174 Views
Last Modified: 2014-11-06
We noticed that a few newly imaged workstations were failing to pull logon scripts from group policy, and confirmed that RSOP failed to execute.  File replication also appears to be an issue on the DCs.

  The customer has two domain controllers, with FRS setup between.

We've already run the following on BOTH servers:
  > net share ... displays shares for NETLOGON and SYSVOL
  > ran dcdiag /test:replications , dcdiag /test:netlogins, repadmin /showrepl *see attached .txts*
    - no replication or DNS errors
 > ensured that site link is online in AD Sites & Services ; replicating every 15 mins @ 100 cost

- if I place a .txt file in the sysvol dir, it fails to replicate even after a manual force replication
- this doesn't explain the RSOP failure on the new machine though, or does it?
 - several Event ID [13508] errors --- 'FRS was unable to create an RPC connection to a replication partnet'
   • NOT followed by an Event ID [13509] --- FRS was able to create an RPC connection → verifies that NO CONNECTION OCCURS between DCs for replication
MET-197---repadmin.txt
MET-197---dcdiag-testreplications.txt
MET-197---dcdiag-testnetlogons.txt
0
Comment
Question by:msCCare
  • 2
4 Comments
 
LVL 32

Expert Comment

by:Rodney Barnhardt
ID: 40413865
Did you try the command: ntfrsutl version <FQDN of remote domain controller>

If that fails, there is a connectivity problem such as a blocked port.
0
 
LVL 32

Expert Comment

by:Rodney Barnhardt
ID: 40413875
I have also seen this after a DC has had a hard shutdown. Have you tried to a clean reboot on the server? Also, does you system have enough free space.
0
 
LVL 36

Accepted Solution

by:
Mahesh earned 500 total points
ID: 40414000
Check if on any DC FRS event ID 13568 (Journal Wrap) is there

download frsdiag GUI tool from MS and run on Domain controller, within that tool you will find file propagation test where tool will check if sysvol is working on both DCs
http://blogs.technet.com/b/askds/archive/2008/05/22/verifying-file-replication-during-the-windows-server-2008-dfsr-sysvol-migration-down-and-dirty-style.aspx

If its get failed, you can non authoritatively restore sysvol on DC other than PDC by following below link
http://support.microsoft.com/kb/290762

Once that issue resolved, again run file propogation test with Frsdiag tool

Also ensure that scripts are copied directly into netlogon share and script path in GPO should not be starting with %logonserver% , this path never works correctly, don't know why

Keep script path with \\server1\netlogon\script.vbs ------------
0
 
LVL 1

Author Comment

by:msCCare
ID: 40426112
Problem ending up being faulty shared folders.  We rebuilt the shared folder structure this morning (with the registry edits), and replication is functional.  FRSDiag returns results 'passed' for the canary .txt.  Essentially completed the 'authoritative restore' from above.  Thank you everyone for your assistance.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question