?
Solved

Active Directory - Error 8614 - Do all DC's need to replicate

Posted on 2016-10-11
5
Medium Priority
?
171 Views
Last Modified: 2016-10-27
We have a domain with 10 sites.
We have noticed after running a "repadmin /replsummary" that not all of our DC's are communicating and that we are getting a

 "(8614) The directory service cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime."

We are not experiencing issues with replication but we think that at least one of the DC's should be able to replicate with all of the DC's.

Is this fine to leave this as everything is working or should we look at resolving this problem?
0
Comment
Question by:Pmb2000
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 6

Expert Comment

by:Deepin
ID: 41838308
How many are not syncing?

you are going to have to kill those DC's and then clean the rest of your AD.....and then rebuild them and bring them back in...
1
 

Author Comment

by:Pmb2000
ID: 41838354
Half of them are giving the error - (8614) The directory service cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime.

But we are having no issues with AD objects being replicated.

What is the best method for the cleaning up of the AD?

Are we best to demote and then bring them back on. or what would you suggest?
0
 
LVL 6

Assisted Solution

by:Deepin
Deepin earned 1000 total points
ID: 41838411
1
 
LVL 6

Accepted Solution

by:
Niten Kumar earned 1000 total points
ID: 41839277
Best would be to demote the non-replicating DC's one at a time.  Demote one, rebuild and promote.  Make sure sites and inter-site links are defined properly.  Test the replication using:

1.   repadmin /replsum
2.   repadmin /showrepl

If all is good then do the same with problematic dc's in other sites.

If in case demotion fails then metadata cleanup will be required which will be best cleaned up through the command line utility ntdsutil.

For help you check out this video which thoroughly explains its usage.  You will find the metadata cleanup part at the second half of the video.

https://www.youtube.com/watch?v=DzJTCYtp7XI
1
 

Author Closing Comment

by:Pmb2000
ID: 41862018
Great Guys.

Thanks!!
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question