?
Solved

USN Rollback

Posted on 2015-02-15
5
Medium Priority
?
118 Views
Last Modified: 2015-03-03
2 domain controllers (2008 R2) were not properly recovered from images as images were taken/recovered in 20 min difference.
repadmin /showutdvec * dc=domain,dc=com does not show any problem.
USN shown on each DC for its partner is the same or higher then partners one for itself.
No errors on both DCs in Directory Service log.

My worry is   "Undetected USN Rollback" which results in undetected divergence where USNs  f.e.  2000 through 2100 are not the same between two domain controllers.

Is any way to determine that?
Thank you.
0
Comment
Question by:D_Batona
  • 4
5 Comments
 
LVL 36

Expert Comment

by:Seth Simmons
ID: 40611549
why did you restore from images to begin with?
not a good idea to do server images of domain controllers for this reason

have you looked at this article?

How to detect and recover from a USN rollback in Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2
https://support.microsoft.com/kb/875495
0
 

Author Comment

by:D_Batona
ID: 40611624
1. I did not
2. It is a good idea when you know how.
3 . I read that article and many others.

What about answering a question?
0
 

Author Comment

by:D_Batona
ID: 40612958
4 days.

So far no errors in logs on both DCs.
repadmin /showutdvec  shows a good picture.

Can admin stop praying?


What else can be used to check that correspondence object-USN are the same on both controllers?
Is any active directory expert here?
0
 

Accepted Solution

by:
D_Batona earned 0 total points
ID: 40633511
Look like no experts on this web site anymore...

For those who are interested here what I did to check if USN issue exist:

1. I applied the image of DC1 to server with identical hardware disconnected from network.
2. I run repadmin /showutdvec * dc=domain,dc=com and make a notice
3. I applied the image of DC2 to server with identical hardware disconnected from network.
4. I run repadmin /showutdvec * dc=domain,dc=com and make a notice
5. Analyzing repadmin /showutdvec showed that domain controllers did not replicate after images were taken

I sent sysadmin to learn something but I doubt it will help..........
0
 

Author Closing Comment

by:D_Batona
ID: 40641296
No one suggested a better way
0

Featured Post

Free tool for managing users' photos in Office 365

Easily upload multiple users’ photos to Office 365. Manage them with an intuitive GUI and use handy built-in cropping and resizing options. Link photos with users based on Azure AD attributes. Free tool!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses
Course of the Month5 days, 7 hours left to enroll

589 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question