Sri Lanka IT Pro Forum
Powering-up Enterprises in Sri Lanka

Active Directory 2003

rated by 0 users
This post has 8 Replies | 2 Followers

Top 25 Contributor
Posts 33
pentone Posted: 06-11-2010 11:26 PM

Normal 0 false false false MicrosoftInternetExplorer4

Dear IT Guys,

 

To day I need ur help….

 

I have a windows 2003 Std Edition AD. Later I configured secondary AD for the existing domain.

 

Eg: Primary Domain:      DC1.abc.lk

      Secondary Domain:  DC2.abc.lk

 

It worked successfully and sync with primary AD.

 

After 2 weeks later I used that Secondary AD server for another job (disconnecting from network). 3 months later again I plug it to the network, but now it is not sync with primary AD.  Do u have an idea to solve this issue…?

 

Pls advice.

 

Pemil.

Top 50 Contributor
Posts 11

Hi Pemil,

After you plugging your Secondry DC and use replication monitor (replmon) - Windows 2003 support tool in Primary DC to check the synchronization status and manually sync your DC and record the massage if any errors. Regards on this we can move ahead.

 

Cheers

netpro

Top 50 Contributor
Posts 11

Dear Pemil,

Again when you run the Dcdiag tool on your secondary domain controller, and if you receive the following error message like follows,

"DC Diagnosis
Performing initial setup:
[DC1] LDAP bind failed with error 31"

Or when you run REPADMIN /SHOWREPS utility locally on a domain controller,  following error messages:

[D:\nt\private\ds\src\util\repadmin\repinfo.c, 389] LDAP error 82 (Local Error).
Last attempt @ yyyy-mm-dd hh:mm.ss failed, result 1753: There are no more endpoints available from the endpoint mapper.
Last attempt @ yyyy-mm-dd hh:mm.ss failed, result 5: Access is denied.

Or if you try to use Active Directory Sites and Services to forced replication, if message indicates that "ACCESS IS DENIED".


Or if  you use Netdiag tool and it display the following error message,

DC list test . . . . . . . . . . . : Failed
[WARNING] Cannot call DsBind to <servername>.<fqdn> (<ip address>). [ERROR_DOMAIN_CONTROLLER_NOT_FOUND]
Kerberos test. . . . . . . . . . . : Failed
[FATAL] Kerberos does not have a ticket for krbtgt/<fqdn>.
[FATAL] Kerberos does not have a ticket for <hostname>.
LDAP test. . . . . . . . . . . . . : Passed
[WARNING] Failed to query SPN registration on DC <hostname>\<fqdn>

Please refer to : http://support.microsoft.com/kb/837513



Cheers,
Top 25 Contributor
Posts 33

Dear NetPro,

According to the instructions, I install Support tools to the primary DC and got this report.

 

<<<<<

Active Directory Replication Domain Controller Replication Failure Output
Printed at    6/18/2010 3:26:21 PM

Below are the replication failures detected on Domain Controllers for this domain:

Domain Controller Name:                   DC1
              Directory Partition:        DC=DomainDnsZones,DC=abc,DC=lk
              Replication Partner:        Default-First-Site-Name\DC2
              Failure Code:                1256
              Failure Reason:             The remote system is not available. For information about network troubleshooting, see Windows Help.

Domain Controller Name:                   DC1
              Directory Partition:        DC=ForestDnsZones,DC=abc,DC=lk
              Replication Partner:        Default-First-Site-Name\DC2
              Failure Code:                1256
              Failure Reason:             The remote system is not available. For information about network troubleshooting, see Windows Help.

Domain Controller Name:                   DC2
              Directory Partition:        ERROR reading partition: DC=abc,DC=lk
              Replication Partner:       
              Failure Code:              
              Failure Reason:            

Domain Controller Name:                   DC2
              Directory Partition:        ERROR reading partition: CN=Configuration,DC=abc,DC=lk
              Replication Partner:       
              Failure Code:              
              Failure Reason:            

Domain Controller Name:                   DC2
              Directory Partition:        ERROR reading partition: CN=Schema,CN=Configuration,DC=abc,DC=lk
              Replication Partner:       
              Failure Code:              
              Failure Reason:            

Domain Controller Name:                   DC2
              Directory Partition:        ERROR reading partition: DC=ForestDnsZones,DC=abc,DC=lk
              Replication Partner:       
              Failure Code:              
              Failure Reason:            

Domain Controller Name:                   DC2
              Directory Partition:        ERROR reading partition: DC=DomainDnsZones,DC=abc,DC=lk
              Replication Partner:       
              Failure Code:              
              Failure Reason:

>>>>

Top 50 Contributor
Posts 11

I went through your report and as we discussed toady moring will try the configuration on coming monday.

Top 10 Contributor
Posts 63

Hi Guys,

Please be good enough to update the findings to other members as well. As I can see there are some members are very keen to observer this thread and see the final result. One thing I notice is pentone has clearly mention he has kept the secondary dc away from the network for nearly 3 months which exceed the tombstone date.  This is not a good sign since Primary DC will decide his partner no longer available on the network.

Never the less we all would like to see the end results and what actions has been taken to minimize the damage.

Top 25 Contributor
Posts 33

Hi Guys,

Good day...!

After doing several testings finally I reconfigured my secondary DC server and now it is up n running for 4 days.

NetPro, Thx a lot for the support u gave.

Pemil.

 

 

Top 10 Contributor
Posts 63

Hi Pemil, nice to hear that you managed to solve the problem :) Hope you can let the others know the step you have taken to overcome the issue as well.

 

Cheers,

Susantha

Top 50 Contributor
Posts 11

Hi pemil

Nice to here  :), I am little bit busy theses days and sorry for my late reply, as bubble's comment this will be point for other to post their problems too and help others as well.

Regards

Nawaz

Page 1 of 1 (9 items) | RSS
Powered by Community Server (Commercial Edition), by Telligent Systems