Solved

USN Rollback

Posted on 2015-02-15
5
62 Views
Last Modified: 2015-03-03
2 domain controllers (2008 R2) were not properly recovered from images as images were taken/recovered in 20 min difference.
repadmin /showutdvec * dc=domain,dc=com does not show any problem.
USN shown on each DC for its partner is the same or higher then partners one for itself.
No errors on both DCs in Directory Service log.

My worry is   "Undetected USN Rollback" which results in undetected divergence where USNs  f.e.  2000 through 2100 are not the same between two domain controllers.

Is any way to determine that?
Thank you.
0
Comment
Question by:D_Batona
  • 4
5 Comments
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40611549
why did you restore from images to begin with?
not a good idea to do server images of domain controllers for this reason

have you looked at this article?

How to detect and recover from a USN rollback in Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2
https://support.microsoft.com/kb/875495
0
 

Author Comment

by:D_Batona
ID: 40611624
1. I did not
2. It is a good idea when you know how.
3 . I read that article and many others.

What about answering a question?
0
 

Author Comment

by:D_Batona
ID: 40612958
4 days.

So far no errors in logs on both DCs.
repadmin /showutdvec  shows a good picture.

Can admin stop praying?


What else can be used to check that correspondence object-USN are the same on both controllers?
Is any active directory expert here?
0
 

Accepted Solution

by:
D_Batona earned 0 total points
ID: 40633511
Look like no experts on this web site anymore...

For those who are interested here what I did to check if USN issue exist:

1. I applied the image of DC1 to server with identical hardware disconnected from network.
2. I run repadmin /showutdvec * dc=domain,dc=com and make a notice
3. I applied the image of DC2 to server with identical hardware disconnected from network.
4. I run repadmin /showutdvec * dc=domain,dc=com and make a notice
5. Analyzing repadmin /showutdvec showed that domain controllers did not replicate after images were taken

I sent sysadmin to learn something but I doubt it will help..........
0
 

Author Closing Comment

by:D_Batona
ID: 40641296
No one suggested a better way
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article runs through the process of deploying a single EXE application selectively to a group of user.
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question