Replication from Primary DC

HI Guys,

At one of our clients we have following setup:

City A :  DC1  ( Primary holding FSMO roles )
City B:   DC2 ( Server 2008 R2  in a process of decommissioning )
              DC-NEW  ( Server 2012 R2 is in process of becoming the only DC for City B  after DC2 shuts down. DC roles are installed  )

Currently facing two issues which may be related ( not sure ) and may be simple but not sure what is wrong:

First:

I wanted to make sure the replication for DC-NEW is working fine so I did following:
Ran repadmin /showrepl command which showed no errors. So that's good.
Under group Policy management tried created test GPO and showed up on the other dc with no errors.
Checked by creating a new user and no errors.

Under Group Policy Management Clicked on domain.com and under Status tab after clicking detect now on the DC-NEW and it shows:

DC1 is the baseline domain controller for this domain

2 domain controller with replication in progress:
DC2   AD - ACLs and SysVol inaccessible
DC-NEW  AD - ACLs and SysVol inaccessible

When I click on inaccessible it shows me list of all GPOs but doesn't pin point whats happening.
Why is it showing in inaccessible on both secondary DCs ? should I be worried ?


SECOND:

Under AD site and services I checked Servers DC2 and DC-New NTDS settings
DC2 is showing  replicating from DC1 and DC-New
This is ideal

But the new DC-NEW  is showing only DC2 ( automatically generated ) and not DC1. Why ?
Specially because I am going to take DC1 down. Shouldn't there be DC1 automatically generated as well ? Am I missing any step here ?
I can manually add  DC1 by clicking New and add a new connection but I am curious why is it not automatically getting generated ?

Thank you all.
jeremy22Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Mr TorturSystem EngineerCommented:
Hi,

well about that FIRST :
When I click on inaccessible it shows me list of all GPOs but doesn't pin point whats happening.
Why is it showing in inaccessible on both secondary DCs ? should I be worried ?

Is there any firewall between DC1 (city A) and other DC (City B), which could be blocking gpo replications?
But I don't know this error.
Check this if by chance this is related :
https://social.technet.microsoft.com/Forums/en-US/f8287c6c-a8a4-4b06-97ed-c4cdeec84493/gpo-replication-sysvol-inaccessible?forum=winserverGP


SECOND :
But the new DC-NEW  is showing only DC2 ( automatically generated ) and not DC1. Why ?
It is normal as you have 2 sites, so there should be 2 sites configured in you AD too, and as a result AD will replicate only one DC per site with the main DC at main site. In order to not generate lot of WAN traffic.
So I think, if there is no replication between DC1 and DC new, if you check there must be one AD replication between DC1 and DC2.
If you delete DC2 one day, then an AD replication will be created between DC1 and DC new.

Shouldn't there be DC1 automatically generated as well ? Am I missing any step here ?
No, this is normal IMHO.

I can manually add  DC1 by clicking New and add a new connection but I am curious why is it not automatically getting generated ?
No you should not.

Specially because I am going to take DC1 down
Not sure if that was a typo, but you want to delete DC1 too? If so, don't forget to transfer fsmo roles properly to one remaining DC.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Sudeep SharmaTechnical DesignerCommented:
Is there any error when you run dcdiag from DC-NEW  or DC2 or DC1?

What are the IP addresses on each of the DC?

Sudeep
Aaron TomoskyDirector of Solutions ConsultingCommented:
Before demoting a DC I like to uncheck GC and set a different one as bridgehead.  That way it's being used as little as possible before decom.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hyper-V

From novice to tech pro — start learning today.