Active Directory - Error 8614 - Do all DC's need to replicate

We have a domain with 10 sites.
We have noticed after running a "repadmin /replsummary" that not all of our DC's are communicating and that we are getting a

 "(8614) The directory service cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime."

We are not experiencing issues with replication but we think that at least one of the DC's should be able to replicate with all of the DC's.

Is this fine to leave this as everything is working or should we look at resolving this problem?
Pmb2000Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

DeepinInfrastructure Engineer Commented:
How many are not syncing?

you are going to have to kill those DC's and then clean the rest of your AD.....and then rebuild them and bring them back in...
Pmb2000Author Commented:
Half of them are giving the error - (8614) The directory service cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime.

But we are having no issues with AD objects being replicated.

What is the best method for the cleaning up of the AD?

Are we best to demote and then bring them back on. or what would you suggest?
Niten KumarPrincipal Systems AdministratorCommented:
Best would be to demote the non-replicating DC's one at a time.  Demote one, rebuild and promote.  Make sure sites and inter-site links are defined properly.  Test the replication using:

1.   repadmin /replsum
2.   repadmin /showrepl

If all is good then do the same with problematic dc's in other sites.

If in case demotion fails then metadata cleanup will be required which will be best cleaned up through the command line utility ntdsutil.

For help you check out this video which thoroughly explains its usage.  You will find the metadata cleanup part at the second half of the video.

https://www.youtube.com/watch?v=DzJTCYtp7XI

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Pmb2000Author Commented:
Great Guys.

Thanks!!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.