Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Active Directory problem after System State restore

Posted on 2016-07-26
9
Medium Priority
?
92 Views
Last Modified: 2016-08-05
After performing a system state restore on a different hyper V hardware, Active directory seems to run on for a little bit then we lose it. When opening Active directory we get a message ad  I restarted the active directory service and it looks like it started workign again after about 10 minutes. The event log points towards the global catalogue missing, but im not sure why this would be after a system state restore ScreenHunter_21-Jul.-26-22.51.jpg
Advise would be very helpful
ScreenHunter_21-Jul.-26-22.51.jpg
0
Comment
Question by:David
  • 6
  • 3
9 Comments
 

Author Comment

by:David
ID: 41730278
to add this is the only DC which runs active directory and exchange on server 2008 R2
0
 

Author Comment

by:David
ID: 41730311
running dcdiag i see the follow fails
dcdiag.txt
0
 

Author Comment

by:David
ID: 41730353
nltest /dsgetdc:domainaname.co.uk /gc

gives error

getting DC name failed: Status = 1355 0x54b ERROR_NO_SUCH_DOMAIN
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 24

Expert Comment

by:Mohammed Hamada
ID: 41731033
Seems like your DNS is not updated or have some staled records. you'll need to enable scavenging on it. make sure that all your domains are replicating properly.

use repadmin /showrepl and repadmin /replsum to see the replication.  you can add /e parameter to include all DCs in the forest.

make sure all firewalls are disabled.
0
 
LVL 24

Expert Comment

by:Mohammed Hamada
ID: 41731034
I would also highly recommend that you install an additional new DC as soon as possible and demote this one that you got from a recovery. it's not recommended to work on recovered DC in production environment.
0
 

Author Comment

by:David
ID: 41732178
Early this morning I made the call to Microsoft and it was an issue with the file replication service
And the netlogon and sysvol were no longer shared causing the issue.

Yes we are planning to migrate the email off to office365
And then will make a decision on the rest

The reason for recovery was because of a crypto virus that got onto the c drive
0
 
LVL 24

Expert Comment

by:Mohammed Hamada
ID: 41732485
Great. so your problem got solved?
0
 

Accepted Solution

by:
David earned 0 total points
ID: 41736765
Yes thanks


The resolution for the issue, Server 2008R2 , system state restore, global catalog missing;
 
You had opened the case with us for issue, Domain Controller 'SERVER.domain.co.uk' is failing test advertising in dcdiag.
We found that, DC was in Journal Wrap
1.) DC was not advertising as GC.

2.) Checked DCDIAG, it was failing connectivity test.

3.) Checked using net share command and the sysvol and netlogon shares were not shared.

4.) In the events found that the DC was in Journal Wrap.

5.) Performed authoritative restore for sysvol as follows;
---------------------------------------------------------------------------------------------------------------------------------
i. Click Start, and then click Run.
ii. In the Open box, type cmd and then press ENTER.
iii. In the Command box, type net stop ntfrs.
iv. Click Start, and then click Run.
v. In the Open box, type regedit and then press ENTER.
vi. Locate the following key in the registry:
-- KEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NtFrs\Parameters\Cumulative Replica Sets
vii. Below the Cumulative Replica Sets subkey, locate the GUID.
viii. In the right pane, double click BurFlags.
ix. In the Edit DWORD Value dialog box, type D4 to complete an authoritative restore, and then click OK.
x. Quit Registry Editor, and then switch to the Command box.
xi. In the Command box, type net start ntfrs.
xii. Quit the Command box.
---------------------------------------------------------------------------------------------------------------------------------

6.) Got the event 13516 for sysvol. Issue resolved.
0
 

Author Closing Comment

by:David
ID: 41743966
spoke with MS support
0

Featured Post

Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scripts are great for performing batch jobs against users, however sometimes the GUI is all you need.
You finally migrated Public Folders to Office 365, decommissioned the Public Folder mailbox database and since then, when you send an email from on-premise to mail-enabled Public Folders, you get the following error: "Misconfigured public folder mai…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Whether it be Exchange Server Crash Issues, Dirty Shutdown Errors or Failed to mount error, Stellar Phoenix Mailbox Exchange Recovery has always got your back. With the help of its easy to understand user interface and 3 simple steps recovery proced…
Suggested Courses

578 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question