Windows 2016 RODC in DMZ KCC Errors

We have a WIndows 2016 server core RODC in our DMZ. The RODC restricted on which DC is can replicate with. REplication is working between the R/W DC and RODC. The event logs on the DC are flood with KCC errors. Some of which are for Site the RODC does not have access to. We have manual connection define but is there any way to stop these warning message like

Event ID 2847 or 2904
LVL 21
compdigit44Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

MaheshArchitectCommented:
you need to ensure that AD ports are opened as appropriate from writable dc to rodc and vice versa
u can use portquerygui tool for same
0
Shaun VermaakTechnical Specialist/DeveloperCommented:
Run this command and post out.txt
repadmin /showrepl * > out.txt

Open in new window

0
compdigit44Author Commented:
repadmin shows that replication is 100% successfull for the DC's the RODC is allowed to replicate with in the firewall. But see errors for other DC which is it blocked from replicating with: "KCC Could not add this replica Link..." I know KCC wants to create links automatically but in our situation with firewall restrictions this will not work. How can we stop KCC from trying to add this links and flooding the event logs
0
Determine the Perfect Price for Your IT Services

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden with our free interactive tool and use it to determine the right price for your IT services. Download your free eBook now!

MaheshArchitectCommented:
this needs to be controlled on site link level
untick bridge all site links in ip site link properties
then ensure that correct sites are added in every site link
this will ensure that replication is happening between only those sites and no unnecessary connection object will be created
0
compdigit44Author Commented:
Just to cofirm I only have the default site link. I should create another one correct
0
MaheshArchitectCommented:
Correct
in that case tick / untick setting won,t help

do you have all DC's in same location?

if not ideally you need to setup sites and site links and then only scenario would work
0
compdigit44Author Commented:
Here is my setup
6 DC's internal
2 RODC DMZ that can only talk to two internal DC
1 DC at remote vendor site that can only talk to two DC

Also my subnet contacts a broad IP range that covers all IP in our organization both internal and external. I know a subnet is assigned to a site but it the broad IP range is assigned to the internal site would the DMZ range which is cover by this IP range get mixed up into the internal site as well
0
MaheshArchitectCommented:
so, all internal dcs are in same location?
if not, being single ad site, user can authenticate to any dc out of six or even with rodc
to stream line , if dcs are separated by wan links, create new ad sites and site links and latch there subnets as well
after that untick site link bridging and add only required sites to site link
OR
U can set new site and site link only for dmz along with disabling site link bridging
OR
manually create connection objects between dcs with required once only and ignore automatically created connection objects
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
MaheshArchitectCommented:
or one more way u can open ports between rodc and all other 6 dcs bi-directionally
0
compdigit44Author Commented:
is there value is change to a hub spoke replication setup???
0
MaheshArchitectCommented:
you are talking about which value?

site link cost or what?

no need to change it
0
compdigit44Author Commented:
in regards to value I am referring to better / more efficient replication
0
MaheshArchitectCommented:
nothing has changed since 2008 server from network port stand point
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2016

From novice to tech pro — start learning today.