Solved

Replication from Primary DC

Posted on 2016-07-31
3
90 Views
1 Endorsement
Last Modified: 2016-08-02
HI Guys,

At one of our clients we have following setup:

City A :  DC1  ( Primary holding FSMO roles )
City B:   DC2 ( Server 2008 R2  in a process of decommissioning )
              DC-NEW  ( Server 2012 R2 is in process of becoming the only DC for City B  after DC2 shuts down. DC roles are installed  )

Currently facing two issues which may be related ( not sure ) and may be simple but not sure what is wrong:

First:

I wanted to make sure the replication for DC-NEW is working fine so I did following:
Ran repadmin /showrepl command which showed no errors. So that's good.
Under group Policy management tried created test GPO and showed up on the other dc with no errors.
Checked by creating a new user and no errors.

Under Group Policy Management Clicked on domain.com and under Status tab after clicking detect now on the DC-NEW and it shows:

DC1 is the baseline domain controller for this domain

2 domain controller with replication in progress:
DC2   AD - ACLs and SysVol inaccessible
DC-NEW  AD - ACLs and SysVol inaccessible

When I click on inaccessible it shows me list of all GPOs but doesn't pin point whats happening.
Why is it showing in inaccessible on both secondary DCs ? should I be worried ?


SECOND:

Under AD site and services I checked Servers DC2 and DC-New NTDS settings
DC2 is showing  replicating from DC1 and DC-New
This is ideal

But the new DC-NEW  is showing only DC2 ( automatically generated ) and not DC1. Why ?
Specially because I am going to take DC1 down. Shouldn't there be DC1 automatically generated as well ? Am I missing any step here ?
I can manually add  DC1 by clicking New and add a new connection but I am curious why is it not automatically getting generated ?

Thank you all.
1
Comment
Question by:jeremy22
3 Comments
 
LVL 11

Accepted Solution

by:
Mr Tortur earned 500 total points
ID: 41737226
Hi,

well about that FIRST :
When I click on inaccessible it shows me list of all GPOs but doesn't pin point whats happening.
Why is it showing in inaccessible on both secondary DCs ? should I be worried ?

Is there any firewall between DC1 (city A) and other DC (City B), which could be blocking gpo replications?
But I don't know this error.
Check this if by chance this is related :
https://social.technet.microsoft.com/Forums/en-US/f8287c6c-a8a4-4b06-97ed-c4cdeec84493/gpo-replication-sysvol-inaccessible?forum=winserverGP


SECOND :
But the new DC-NEW  is showing only DC2 ( automatically generated ) and not DC1. Why ?
It is normal as you have 2 sites, so there should be 2 sites configured in you AD too, and as a result AD will replicate only one DC per site with the main DC at main site. In order to not generate lot of WAN traffic.
So I think, if there is no replication between DC1 and DC new, if you check there must be one AD replication between DC1 and DC2.
If you delete DC2 one day, then an AD replication will be created between DC1 and DC new.

Shouldn't there be DC1 automatically generated as well ? Am I missing any step here ?
No, this is normal IMHO.

I can manually add  DC1 by clicking New and add a new connection but I am curious why is it not automatically getting generated ?
No you should not.

Specially because I am going to take DC1 down
Not sure if that was a typo, but you want to delete DC1 too? If so, don't forget to transfer fsmo roles properly to one remaining DC.
0
 
LVL 29

Expert Comment

by:Sudeep Sharma
ID: 41737254
Is there any error when you run dcdiag from DC-NEW  or DC2 or DC1?

What are the IP addresses on each of the DC?

Sudeep
0
 
LVL 38

Expert Comment

by:Aaron Tomosky
ID: 41737428
Before demoting a DC I like to uncheck GC and set a different one as bridgehead.  That way it's being used as little as possible before decom.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
WSUS - Win 2012 6 24
Raid 6 or Raid 10? 19 54
Modify Policy using PowerShell 6 16
Powershell novice. Move user attributes 5 12
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now