Active Directory unavailable when SBS 2003 server is shutdown with Windows 2008 AD Servers

We have a SBS 2003 that does nothing more than some admin shares and active directory. Our network also consists of 2 other Windows 2008 R2 Active Directory Server with various file server and sql virtual server.

Everything works great until we shutdown the SBS 2003 server. When the server is powered off users cannot authenticate to the domain.
I have tried to transfer the pdc, rid and infrastructure roles to one of the other domain controllers but the same thing happens.  

We would like to decommission the SBS 2003 server but haven't done so because of the authentication problem.
popeyedctsAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

MPCP-BrianCommented:
One common issue that occurs is DNS is not configured correctly. Ensure all three of your servers have DNS Server installed and running - then make sure the client PCs have all three DNS servers configured (usually set on the DHCP server)

Another thing you can do is run dcdiag /v from one of the domain controllers. You may want to actually run: "dcdiag /v >Exportedfile.txt" because the output will be quite long. It is tough to read - but effectively you want all tests to pass. The results of this dcdiag may show the synchronization between the domain controllers is not healthy.

Let me know if this makes sense, or if you have performed these steps already.
FlippCommented:
Have you transferred all 5 fsmo roles to 2008 dc?
popeyedctsAuthor Commented:
I transferred the 5 FSMO roles to the 2008 DC and the SBS 2003 server shutdown due to the EULA. I am going to schedule to transfer the roles to the 2008 DC and then demote the sbs2003 in the next week.
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

FlippCommented:
A little confused to what you have done and what you are going to do. It sounds like you have transferred the FSMO roles, but then you say you are going to schedule to transfer them?
popeyedctsAuthor Commented:
Flipp,

Sorry for the confusion.

1. I transfered the RID, PDC and Infrastructure roles from the SBS2003 server to a 2008R2 DC., once I did that the server would shutdown because of the EULA on the SBS 2003 server... it had to be the primary FSMO role holder.

2. I move the RID, PDC and Infrastructure roles back to the SBS2003 server,... now it doesn't shutdown.

3. Next I will schedule downtime and transfer the RID, PDC, Infrastructure, Schema and Operations Master to the 2008DC and then demote the sbs2003 server.

Does that make sense?
FlippCommented:
Ah yes .... thanks for the reply :)

I have the exact situation where I had to transfer back the FSMO roles as I migrate Exchange Server 2007 to EO.

I would make sure that your new DC (once roles go across) is working with the normal DCDIAG commands as Brian mentioned above. Post whatever results you get if unsure.
popeyedctsAuthor Commented:
I ran dcdiag /v >export.txt and here is the output file:


Directory Server Diagnosis
Performing initial setup:   Trying to find home server...   * Verifying that the local machine SFXDC01, is a Directory Server.
   Home Server = SFXDC01   * Connecting to directory service on server SFXDC01.   * Identified AD Forest.
   Collecting AD specific global data
   * Collecting site info.   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=ShowFX,DC=local,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
   The previous call succeeded
   Iterating through the sites
   Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
   Getting ISTG and options for the site
   * Identifying all servers.   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=ShowFX,DC=local,LDAP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
   The previous call succeeded....
   The previous call succeeded
   Iterating through the list of servers
   Getting information for the server CN=NTDS Settings,CN=SFXSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=SFXSERVER01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   * Identifying all NC cross-refs.   * Found 3 DC(s). Testing 1 of them.   Done gathering initial info.
Doing initial required tests  
   Testing server: Default-First-Site-Name\SFXDC01      Starting test: Connectivity         * Active Directory LDAP Services Check
         Determining IP4 connectivity
         * Active Directory RPC Services Check
         ......................... SFXDC01 passed test ConnectivityDoing primary tests  
   Testing server: Default-First-Site-Name\SFXDC01      Starting test: Advertising         Fatal Error:DsGetDcName (SFXDC01) call failed, error 1355         The Locator could not find the server.         ......................... SFXDC01 failed test Advertising      Test omitted by user request: CheckSecurityError      Test omitted by user request: CutoffServers      Starting test: FrsEvent         * The File Replication Service Event log test
         There are warning or error events within the last 24 hours after the         SYSVOL has been shared.  Failing SYSVOL replication problems may cause         Group Policy problems.
         A warning event occurred.  EventID: 0x800034C4            Time Generated: 11/08/2015   13:32:48            Event String:            The File Replication Service is having trouble enabling replication from SFXSERVER to SFXDC01 for c:\windows\sysvol\domain using the DNS name sfxserver.ShowFX.local. FRS will keep retrying.              Following are some of the reasons you would see this warning.                           [1] FRS can not correctly resolve the DNS name sfxserver.ShowFX.local from this computer.              [2] FRS is not running on sfxserver.ShowFX.local.              [3] The topology information in the Active Directory Domain Services for this replica has not yet replicated to all the Domain Controllers.                           This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.         A warning event occurred.  EventID: 0x800034C4            Time Generated: 11/08/2015   13:32:49            Event String:            The File Replication Service is having trouble enabling replication from sfxserver.ShowFX.local to SFXDC01 for c:\windows\sysvol\domain using the DNS name sfxserver.ShowFX.local. FRS will keep retrying.              Following are some of the reasons you would see this warning.                           [1] FRS can not correctly resolve the DNS name sfxserver.ShowFX.local from this computer.              [2] FRS is not running on sfxserver.ShowFX.local.              [3] The topology information in the Active Directory Domain Services for this replica has not yet replicated to all the Domain Controllers.                           This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.         A warning event occurred.  EventID: 0x800034C4            Time Generated: 11/08/2015   14:32:49            Event String:            The File Replication Service is having trouble enabling replication from SFXSERVER01 to SFXDC01 for c:\windows\sysvol\domain using the DNS name SFXSERVER01.ShowFX.local. FRS will keep retrying.              Following are some of the reasons you would see this warning.                           [1] FRS can not correctly resolve the DNS name SFXSERVER01.ShowFX.local from this computer.              [2] FRS is not running on SFXSERVER01.ShowFX.local.              [3] The topology information in the Active Directory Domain Services for this replica has not yet replicated to all the Domain Controllers.                           This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.         ......................... SFXDC01 passed test FrsEvent      Starting test: DFSREvent         The DFS Replication Event Log.
         Skip the test because the server is running FRS.         ......................... SFXDC01 passed test DFSREvent      Starting test: SysVolCheck         * The File Replication Service SYSVOL ready test
         The registry lookup failed to determine the state of the SYSVOL.  The         error returned  was 0x0 "The operation completed successfully.".         Check the FRS event log to see if the SYSVOL has successfully been         shared.
         ......................... SFXDC01 passed test SysVolCheck      Starting test: KccEvent         * The KCC Event log test
         A warning event occurred.  EventID: 0x80000677            Time Generated: 11/09/2015   08:40:52            Event String:            Active Directory Domain Services attempted to communicate with the following global catalog and the attempts were unsuccessful.                          Global catalog:            \\sfxserver.ShowFX.local                          The operation in progress might be unable to continue. Active Directory Domain Services will use the domain controller locator to try to find an available global catalog server.                          Additional Data             Error value:            1722 The RPC server is unavailable.         Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
         ......................... SFXDC01 passed test KccEvent      Starting test: KnowsOfRoleHolders         Role Schema Owner = CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
         Role Domain Owner = CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
         Role PDC Owner = CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
         Role Rid Owner = CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
         ......................... SFXDC01 passed test KnowsOfRoleHolders      Starting test: MachineAccount         Checking machine account for DC SFXDC01 on DC SFXDC01.
         * SPN found :LDAP/SFXDC01.ShowFX.local/ShowFX.local
         * SPN found :LDAP/SFXDC01.ShowFX.local
         * SPN found :LDAP/SFXDC01
         * SPN found :LDAP/SFXDC01.ShowFX.local/SHOWFX
         * SPN found :LDAP/e080cf07-7be0-4d42-8ee5-3cdc67657955._msdcs.ShowFX.local
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/e080cf07-7be0-4d42-8ee5-3cdc67657955/ShowFX.local
         * SPN found :HOST/SFXDC01.ShowFX.local/ShowFX.local
         * SPN found :HOST/SFXDC01.ShowFX.local
         * SPN found :HOST/SFXDC01
         * SPN found :HOST/SFXDC01.ShowFX.local/SHOWFX
         * SPN found :GC/SFXDC01.ShowFX.local/ShowFX.local
         ......................... SFXDC01 passed test MachineAccount      Starting test: NCSecDesc         * Security Permissions check for all NC's on DC SFXDC01.
         * Security Permissions Check for           DC=ForestDnsZones,DC=ShowFX,DC=local
            (NDNC,Version 3)
         * Security Permissions Check for           DC=DomainDnsZones,DC=ShowFX,DC=local
            (NDNC,Version 3)
         * Security Permissions Check for           CN=Schema,CN=Configuration,DC=ShowFX,DC=local
            (Schema,Version 3)
         * Security Permissions Check for           CN=Configuration,DC=ShowFX,DC=local
            (Configuration,Version 3)
         * Security Permissions Check for           DC=ShowFX,DC=local
            (Domain,Version 3)
         ......................... SFXDC01 passed test NCSecDesc      Starting test: NetLogons         * Network Logons Privileges Check
         Unable to connect to the NETLOGON share! (\\SFXDC01\netlogon)         [SFXDC01] An net use or LsaPolicy operation failed with error 67,         The network name cannot be found..         ......................... SFXDC01 failed test NetLogons      Starting test: ObjectsReplicated         SFXDC01 is in domain DC=ShowFX,DC=local
         Checking for CN=SFXDC01,OU=Domain Controllers,DC=ShowFX,DC=local in domain DC=ShowFX,DC=local on 1 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local in domain CN=Configuration,DC=ShowFX,DC=local on 1 servers
            Object is up-to-date on all servers.
         ......................... SFXDC01 passed test ObjectsReplicated      Test omitted by user request: OutboundSecureChannels      Starting test: Replications         * Replications Check
         [SFXSERVER] DsBindWithSpnEx() failed with error 1722,         The RPC server is unavailable..
         Printing RPC Extended Error Info:         Error Record 1, ProcessID is 3144
          (DcDiag)
         
            System Time is: 11/9/2015 16:41:21:684            Generating component is 2 (RPC runtime)
           
            Status is 1722 The RPC server is unavailable.            
            Detection location is 501            NumberOfParameters is 4            Unicode string: ncacn_ip_tcp            Unicode string:            09a6fc4b-7d94-40a2-a286-4dff90ecda1d._msdcs.ShowFX.local            Long val: -481213899            Long val: 1722         Error Record 2, ProcessID is 3144
          (DcDiag)
         
            System Time is: 11/9/2015 16:41:21:684            Generating component is 18 (unknown)
           
            Status is 1722 The RPC server is unavailable.            
            Detection location is 1442            NumberOfParameters is 1            Unicode string:            09a6fc4b-7d94-40a2-a286-4dff90ecda1d._msdcs.ShowFX.local         Error Record 3, ProcessID is 3144
          (DcDiag)
         
            System Time is: 11/9/2015 16:41:21:684            Generating component is 18 (unknown)
           
            Status is 1722 The RPC server is unavailable.            
            Detection location is 323         Error Record 4, ProcessID is 3144
          (DcDiag)
         
            System Time is: 11/9/2015 16:41:21:684            Generating component is 18 (unknown)
           
            Status is 1237            The operation could not be completed. A retry should be performed.            
            Detection location is 313         Error Record 5, ProcessID is 3144
          (DcDiag)
         
            System Time is: 11/9/2015 16:41:21:684            Generating component is 18 (unknown)
           
            Status is 10060            A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.            
            Detection location is 311            NumberOfParameters is 3            Long val: 135            Pointer val: 0            Pointer val: 0         Error Record 6, ProcessID is 3144
          (DcDiag)
         
            System Time is: 11/9/2015 16:41:21:684            Generating component is 18 (unknown)
           
            Status is 10060            A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.            
            Detection location is 318         ......................... SFXDC01 failed test Replications      Starting test: RidManager         * Available RID Pool for the Domain is 5109 to 1073741823
         * SFXDC01.ShowFX.local is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 3609 to 4108
         * rIDPreviousAllocationPool is 3609 to 4108
         * rIDNextRID: 3610
         ......................... SFXDC01 passed test RidManager      Starting test: Services         * Checking Service: EventSystem
         * Checking Service: RpcSs
         * Checking Service: NTDS
         * Checking Service: DnsCache
         * Checking Service: NtFrs
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: w32time
         * Checking Service: NETLOGON
         ......................... SFXDC01 passed test Services      Starting test: SystemLog         * The System Event log test
         A warning event occurred.  EventID: 0x0000000C            Time Generated: 11/09/2015   08:01:22            Event String:            Time Provider NtpClient: This machine is configured to use the domain hierarchy to determine its time source, but it is the AD PDC emulator for the domain at the root of the forest, so there is no machine above it in the domain hierarchy to use as a time source. It is recommended that you either configure a reliable time service in the root domain, or manually configure the AD PDC to synchronize with an external time source. Otherwise, this machine will function as the authoritative time source in the domain hierarchy. If an external time source is not configured or used for this computer, you may choose to disable the NtpClient.         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   08:08:04            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   08:13:42            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   08:19:19            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         A warning event occurred.  EventID: 0x8000001D            Time Generated: 11/09/2015   08:19:27            Event String:            The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   08:24:56            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   08:30:32            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         A warning event occurred.  EventID: 0x000003F6            Time Generated: 11/09/2015   08:35:02            Event String:            Name resolution for the name ShowFX.local timed out after none of the configured DNS servers responded.         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   08:36:11            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         ......................... SFXDC01 failed test SystemLog      Test omitted by user request: Topology      Test omitted by user request: VerifyEnterpriseReferences      Starting test: VerifyReferences         The system object reference (serverReference)         CN=SFXDC01,OU=Domain Controllers,DC=ShowFX,DC=local and backlink on         CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local         are correct.
         The system object reference (serverReferenceBL)         CN=SFXDC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=ShowFX,DC=local         and backlink on         CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local         are correct.
         The system object reference (frsComputerReferenceBL)         CN=SFXDC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=ShowFX,DC=local         and backlink on CN=SFXDC01,OU=Domain Controllers,DC=ShowFX,DC=local         are correct.
         ......................... SFXDC01 passed test VerifyReferences      Test omitted by user request: VerifyReplicas  
      Test omitted by user request: DNS      Test omitted by user request: DNS  
   Running partition tests on : ForestDnsZones      Starting test: CheckSDRefDom         ......................... ForestDnsZones passed test CheckSDRefDom      Starting test: CrossRefValidation         ......................... ForestDnsZones passed test         CrossRefValidation  
   Running partition tests on : DomainDnsZones      Starting test: CheckSDRefDom         ......................... DomainDnsZones passed test CheckSDRefDom      Starting test: CrossRefValidation         ......................... DomainDnsZones passed test         CrossRefValidation  
   Running partition tests on : Schema      Starting test: CheckSDRefDom         ......................... Schema passed test CheckSDRefDom      Starting test: CrossRefValidation         ......................... Schema passed test CrossRefValidation  
   Running partition tests on : Configuration      Starting test: CheckSDRefDom         ......................... Configuration passed test CheckSDRefDom      Starting test: CrossRefValidation         ......................... Configuration passed test CrossRefValidation  
   Running partition tests on : ShowFX      Starting test: CheckSDRefDom         ......................... ShowFX passed test CheckSDRefDom      Starting test: CrossRefValidation         ......................... ShowFX passed test CrossRefValidation  
   Running enterprise tests on : ShowFX.local      Test omitted by user request: DNS      Test omitted by user request: DNS      Starting test: LocatorCheck         Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355         A Global Catalog Server could not be located - All GC's are down.         PDC Name: \\SFXDC01.ShowFX.local
         Locator Flags: 0xe00031fd
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355         A Time Server could not be located.         The server holding the PDC role is down.         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error         1355         A Good Time Server could not be located.         Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1355         A KDC could not be located - All the KDCs are down.         ......................... ShowFX.local failed test LocatorCheck      Starting test: Intersite         Skipping site Default-First-Site-Name, this site is outside the scope         provided by the command line arguments provided.
         ......................... ShowFX.local passed test Intersite
popeyedctsAuthor Commented:
In the previous post is shows the dcdiag export file with all of the FSMO Roles transferred to sfxdc01 WITH sfxserver.showfx.local powered off....sfxserver.showfx.local is a SBS2003 server.

Below is the dcdiag export file WITH the sfxserver.showfx.local powered on:


Directory Server Diagnosis
Performing initial setup:   Trying to find home server...   * Verifying that the local machine SFXDC01, is a Directory Server.
   Home Server = SFXDC01   * Connecting to directory service on server SFXDC01.   * Identified AD Forest.
   Collecting AD specific global data
   * Collecting site info.   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=ShowFX,DC=local,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
   The previous call succeeded
   Iterating through the sites
   Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
   Getting ISTG and options for the site
   * Identifying all servers.   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=ShowFX,DC=local,LDAP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
   The previous call succeeded....
   The previous call succeeded
   Iterating through the list of servers
   Getting information for the server CN=NTDS Settings,CN=SFXSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=SFXSERVER01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   * Identifying all NC cross-refs.   * Found 3 DC(s). Testing 1 of them.   Done gathering initial info.
Doing initial required tests  
   Testing server: Default-First-Site-Name\SFXDC01      Starting test: Connectivity         * Active Directory LDAP Services Check
         Determining IP4 connectivity
         * Active Directory RPC Services Check
         ......................... SFXDC01 passed test ConnectivityDoing primary tests  
   Testing server: Default-First-Site-Name\SFXDC01      Starting test: Advertising         Warning: DsGetDcName returned information for         \\sfxserver.ShowFX.local, when we were trying to reach SFXDC01.         SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE.         ......................... SFXDC01 failed test Advertising      Test omitted by user request: CheckSecurityError      Test omitted by user request: CutoffServers      Starting test: FrsEvent         * The File Replication Service Event log test
         There are warning or error events within the last 24 hours after the         SYSVOL has been shared.  Failing SYSVOL replication problems may cause         Group Policy problems.
         A warning event occurred.  EventID: 0x800034C4            Time Generated: 11/08/2015   13:32:48            Event String:            The File Replication Service is having trouble enabling replication from SFXSERVER to SFXDC01 for c:\windows\sysvol\domain using the DNS name sfxserver.ShowFX.local. FRS will keep retrying.              Following are some of the reasons you would see this warning.                           [1] FRS can not correctly resolve the DNS name sfxserver.ShowFX.local from this computer.              [2] FRS is not running on sfxserver.ShowFX.local.              [3] The topology information in the Active Directory Domain Services for this replica has not yet replicated to all the Domain Controllers.                           This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.         A warning event occurred.  EventID: 0x800034C4            Time Generated: 11/08/2015   13:32:49            Event String:            The File Replication Service is having trouble enabling replication from sfxserver.ShowFX.local to SFXDC01 for c:\windows\sysvol\domain using the DNS name sfxserver.ShowFX.local. FRS will keep retrying.              Following are some of the reasons you would see this warning.                           [1] FRS can not correctly resolve the DNS name sfxserver.ShowFX.local from this computer.              [2] FRS is not running on sfxserver.ShowFX.local.              [3] The topology information in the Active Directory Domain Services for this replica has not yet replicated to all the Domain Controllers.                           This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.         A warning event occurred.  EventID: 0x800034C4            Time Generated: 11/08/2015   14:32:49            Event String:            The File Replication Service is having trouble enabling replication from SFXSERVER01 to SFXDC01 for c:\windows\sysvol\domain using the DNS name SFXSERVER01.ShowFX.local. FRS will keep retrying.              Following are some of the reasons you would see this warning.                           [1] FRS can not correctly resolve the DNS name SFXSERVER01.ShowFX.local from this computer.              [2] FRS is not running on SFXSERVER01.ShowFX.local.              [3] The topology information in the Active Directory Domain Services for this replica has not yet replicated to all the Domain Controllers.                           This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.         ......................... SFXDC01 passed test FrsEvent      Starting test: DFSREvent         The DFS Replication Event Log.
         Skip the test because the server is running FRS.         ......................... SFXDC01 passed test DFSREvent      Starting test: SysVolCheck         * The File Replication Service SYSVOL ready test
         The registry lookup failed to determine the state of the SYSVOL.  The         error returned  was 0x0 "The operation completed successfully.".         Check the FRS event log to see if the SYSVOL has successfully been         shared.
         ......................... SFXDC01 passed test SysVolCheck      Starting test: KccEvent         * The KCC Event log test
         Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
         ......................... SFXDC01 passed test KccEvent      Starting test: KnowsOfRoleHolders         Role Schema Owner = CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
         Role Domain Owner = CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
         Role PDC Owner = CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
         Role Rid Owner = CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local
         ......................... SFXDC01 passed test KnowsOfRoleHolders      Starting test: MachineAccount         Checking machine account for DC SFXDC01 on DC SFXDC01.
         * SPN found :LDAP/SFXDC01.ShowFX.local/ShowFX.local
         * SPN found :LDAP/SFXDC01.ShowFX.local
         * SPN found :LDAP/SFXDC01
         * SPN found :LDAP/SFXDC01.ShowFX.local/SHOWFX
         * SPN found :LDAP/e080cf07-7be0-4d42-8ee5-3cdc67657955._msdcs.ShowFX.local
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/e080cf07-7be0-4d42-8ee5-3cdc67657955/ShowFX.local
         * SPN found :HOST/SFXDC01.ShowFX.local/ShowFX.local
         * SPN found :HOST/SFXDC01.ShowFX.local
         * SPN found :HOST/SFXDC01
         * SPN found :HOST/SFXDC01.ShowFX.local/SHOWFX
         * SPN found :GC/SFXDC01.ShowFX.local/ShowFX.local
         ......................... SFXDC01 passed test MachineAccount      Starting test: NCSecDesc         * Security Permissions check for all NC's on DC SFXDC01.
         * Security Permissions Check for           DC=ForestDnsZones,DC=ShowFX,DC=local
            (NDNC,Version 3)
         * Security Permissions Check for           DC=DomainDnsZones,DC=ShowFX,DC=local
            (NDNC,Version 3)
         * Security Permissions Check for           CN=Schema,CN=Configuration,DC=ShowFX,DC=local
            (Schema,Version 3)
         * Security Permissions Check for           CN=Configuration,DC=ShowFX,DC=local
            (Configuration,Version 3)
         * Security Permissions Check for           DC=ShowFX,DC=local
            (Domain,Version 3)
         ......................... SFXDC01 passed test NCSecDesc      Starting test: NetLogons         * Network Logons Privileges Check
         Unable to connect to the NETLOGON share! (\\SFXDC01\netlogon)         [SFXDC01] An net use or LsaPolicy operation failed with error 67,         The network name cannot be found..         ......................... SFXDC01 failed test NetLogons      Starting test: ObjectsReplicated         SFXDC01 is in domain DC=ShowFX,DC=local
         Checking for CN=SFXDC01,OU=Domain Controllers,DC=ShowFX,DC=local in domain DC=ShowFX,DC=local on 1 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local in domain CN=Configuration,DC=ShowFX,DC=local on 1 servers
            Object is up-to-date on all servers.
         ......................... SFXDC01 passed test ObjectsReplicated      Test omitted by user request: OutboundSecureChannels      Starting test: Replications         * Replications Check
         [Replications Check,SFXDC01] A recent replication attempt failed:            From SFXSERVER to SFXDC01            Naming Context: CN=Schema,CN=Configuration,DC=ShowFX,DC=local            The replication generated an error (1722):            The RPC server is unavailable.            The failure occurred at 2015-11-09 08:50:34.            The last success occurred at 2015-11-09 07:58:05.            1 failures have occurred since the last success.            The source SFXSERVER is responding now.         [Replications Check,SFXDC01] A recent replication attempt failed:            From SFXSERVER to SFXDC01            Naming Context: CN=Configuration,DC=ShowFX,DC=local            The replication generated an error (1722):            The RPC server is unavailable.            The failure occurred at 2015-11-09 08:50:13.            The last success occurred at 2015-11-09 07:59:56.            1 failures have occurred since the last success.            The source SFXSERVER is responding now.         ......................... SFXDC01 failed test Replications      Starting test: RidManager         * Available RID Pool for the Domain is 5109 to 1073741823
         * SFXDC01.ShowFX.local is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 3609 to 4108
         * rIDPreviousAllocationPool is 3609 to 4108
         * rIDNextRID: 3610
         ......................... SFXDC01 passed test RidManager      Starting test: Services         * Checking Service: EventSystem
         * Checking Service: RpcSs
         * Checking Service: NTDS
         * Checking Service: DnsCache
         * Checking Service: NtFrs
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: w32time
         * Checking Service: NETLOGON
         ......................... SFXDC01 passed test Services      Starting test: SystemLog         * The System Event log test
         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   08:47:26            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   08:53:03            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   08:58:40            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   09:04:20            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         An error event occurred.  EventID: 0x0000041E            Time Generated: 11/09/2015   09:10:00            Event String:            The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.         ......................... SFXDC01 failed test SystemLog      Test omitted by user request: Topology      Test omitted by user request: VerifyEnterpriseReferences      Starting test: VerifyReferences         The system object reference (serverReference)         CN=SFXDC01,OU=Domain Controllers,DC=ShowFX,DC=local and backlink on         CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local         are correct.
         The system object reference (serverReferenceBL)         CN=SFXDC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=ShowFX,DC=local         and backlink on         CN=NTDS Settings,CN=SFXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ShowFX,DC=local         are correct.
         The system object reference (frsComputerReferenceBL)         CN=SFXDC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=ShowFX,DC=local         and backlink on CN=SFXDC01,OU=Domain Controllers,DC=ShowFX,DC=local         are correct.
         ......................... SFXDC01 passed test VerifyReferences      Test omitted by user request: VerifyReplicas  
      Test omitted by user request: DNS      Test omitted by user request: DNS  
   Running partition tests on : ForestDnsZones      Starting test: CheckSDRefDom         ......................... ForestDnsZones passed test CheckSDRefDom      Starting test: CrossRefValidation         ......................... ForestDnsZones passed test         CrossRefValidation  
   Running partition tests on : DomainDnsZones      Starting test: CheckSDRefDom         ......................... DomainDnsZones passed test CheckSDRefDom      Starting test: CrossRefValidation         ......................... DomainDnsZones passed test         CrossRefValidation  
   Running partition tests on : Schema      Starting test: CheckSDRefDom         ......................... Schema passed test CheckSDRefDom      Starting test: CrossRefValidation         ......................... Schema passed test CrossRefValidation  
   Running partition tests on : Configuration      Starting test: CheckSDRefDom         ......................... Configuration passed test CheckSDRefDom      Starting test: CrossRefValidation         ......................... Configuration passed test CrossRefValidation  
   Running partition tests on : ShowFX      Starting test: CheckSDRefDom         ......................... ShowFX passed test CheckSDRefDom      Starting test: CrossRefValidation         ......................... ShowFX passed test CrossRefValidation  
   Running enterprise tests on : ShowFX.local      Test omitted by user request: DNS      Test omitted by user request: DNS      Starting test: LocatorCheck         GC Name: \\sfxserver.ShowFX.local         Locator Flags: 0xe00001bc
         PDC Name: \\SFXDC01.ShowFX.local
         Locator Flags: 0xe00031fd
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355         A Time Server could not be located.         The server holding the PDC role is down.         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error         1355         A Good Time Server could not be located.         KDC Name: \\sfxserver.ShowFX.local
         Locator Flags: 0xe00001bc
         ......................... ShowFX.local failed test LocatorCheck      Starting test: Intersite         Skipping site Default-First-Site-Name, this site is outside the scope         provided by the command line arguments provided.
         ......................... ShowFX.local passed test Intersite
popeyedctsAuthor Commented:
Turns out it was a journal wrap error on the windows 2003 SBS server.

WARNING: During the recovery process data in the replica tree may be unavailable. You should reset the registry parameter described above to 0 to prevent automatic recovery from making the data unexpectedly unavailable if this error condition occurs again.
 
To change this registry parameter, run regedit.
 
Click on Start, Run and type regedit.
 
Expand HKEY_LOCAL_MACHINE.
Click down the key path:
   “System\CurrentControlSet\Services\NtFrs\Parameters”
Double click on the value name
   “Enable Journal Wrap Automatic Restore”
and update the value.
 
If the value name is not present you may add it with the New->DWORD Value function under the Edit Menu item. Type the value name exactly as shown above.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
popeyedctsAuthor Commented:
All the experts were great in help in guiding me to the issue.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.