Unable to Sync SYSVOL Folder between Domain Controllers
Good Afternoon All,
I have the following issue on my current domain configuration, I say current as we are seeking to go to Server 2012 R2 within the next few months, but for now, we are at the 2008 R2 functional level.
We have three Domain Controllers namely Server-001 to 3, with Server-002 holding the PDC Emulator Role. Now when policies are created or updated through GP Management, I have noticed that they sync without issue between Server-002 and Server-003, but not
Server-001. In the SYSVOL Folder in each DC, the folder totals in policies are as follows:
Server-001 - 72 Folders
Server-002 - 96 Folders
Server-003 - 96 Folders
So here, it can be clearly seen that there is some sort of replication issue between Server-001 and the other controllers. I have researched and read several articles and opinions regarding the same issue and have ran many of the commands outlined including
repadmin, dnslint, gposync, etc. with the only output displaying errors being gposync. I have checked all the event logs for each DC with added focus on the DFS Replication Logs and have seen no errors regarding replication on Server-001 which is the server
at fault, but have noted that it appears that Server-001 is only replicating to itself, while Servers -002 and -003 are syncing/replicating between each other. I created a text document in Server-002's SYSVOL Folder and checked in Server-003's and verified
that the document successfully synced across, but on Server-001 nothing happened. I did some research on the issue and came across non-authoritative sysvol restore as an option, but when I tried this on Server-001 via ADSI Edit, I noticed that the following
path:
OU=Domain Controllers>CN=Server-001>CN=DSFR-LocalSettings>CN=Domain System Volume
is missing. Initially, DSFR-LocalSettings was missing as well, but I re-created it. I then attempted to re-create Domain System Volume, but when I tried entering the Replication Group GUID, I got an error that "one or more of the values are not in the
correct format", even though this is the same GUID used on the other two DCs. I tried changing the value to octet, hexadecimal, etc. but nothing worked. i still got the same error. I am convinced that this is where the disconnect lies, but with no possible
idea how to fix this broken section, I am unsure how to further proceed. We were going to demote the server, bring up a 2012 R2 unit and have it seize the roles, but I convinced my Systems Administrator for us to try and see if there is a fix available before
commissioning a new server. As is, group policy is somewhat broken as policies either do no get applied at all, or, get applied to certain groups or OUs.
If you are interested I can forward you our DFSR Logs from each server, along with any other reports that I have run in the hopes that someone will be able to assist. I hope that I have been as clear as possible and have provided as much information as is
possibly required.
Thank you all in advance.
Hi,
To perform non-authoritative synchronization for DFSR-replicated SYSVOL, the following article can be referred to for more information.
How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)
http://support.microsoft.com/kb/2218556/en-us
Besides, we can use dcdiag command to check the health of the DC.
Dcdiag
http://technet.microsoft.com/en-us/library/cc731968.aspx
TechNet Subscriber Support
If you are TechNet Subscription user and have any feedback on our support quality, please send your feedback here.
Best regards,
Frank Shen
Similar Messages
-
Sync a folder between two users on the same computer.
I would like to sync a folder between two users on the same computer so that they are always the same when I access them from either user.
then place this folder somewhere where both users have access to like in /Users/Shared. then there is only one folder to deal with and you don't need to sync anything.
-
Communication issues between domain controllers
Hi everyone,
I am experiencing some problems in communication between domain controllers in our organization
We have three domain controllers, one of them is a Windows 2003 server service pack 2 which is physical (controller A), another which is Windows 2008 Service Pack 2 (controller B), also physical, and a third one (controller C) which is a Windows 2008
service pack 1 and is virtual.
I have problems with this last DC, it won't respond to pings, or DNS query. I can't Access it by remote desktop client even when it is enabled. I cannot update it, it prompts error messages if I try to do so.
This problems are solved if I reboot it, it will work fine some hours or days, but not much longer. I have checked event viewer and I didn't found any message about this.
I read some time ago it would be great to have a DC in a virtual machine, so I did it, but is it right?
Do you know what might be going on with it? would depromoting it and seting it up again the best solución?
Thank you very much.
Best regards.
David.This sounds like a NIC issue, which is odd since it is a virtual machine. Have you checked the host for any logs about the client?
I think the first thing I would do is destroy the current virtual NIC card and add a new one. Since this has nothing to do with Active Directory I would also suggest you post this in a forum of for the Host (VMWare or Hyper-V).
Paul Bergson
MVP - Directory Services
MCITP: Enterprise Administrator
MCTS, MCT, MCSE, MCSA, Security, BS CSci
2012, 2008, Vista, 2003, 2000 (Early Achiever), NT4
Twitter @pbbergs http://blogs.dirteam.com/blogs/paulbergson
Please no e-mails, any questions should be posted in the NewsGroup.
This posting is provided AS IS with no warranties, and confers no rights. -
DFSR replicaion problem between domain controllers
I have 2 domain controllers running server 2012 and recently noticed a lot of errors about replication between 2 of them
i demoted child controller and promoted it again for DC and issue still occurs
so far i noticed that when browsing network and looking for shares on main DC i can see SYSVOL folder there
but it is missing on the other one - it is present in c \ windows but not visible in shares \
also domain folder is empty on the child DC
when i run dfsrmngr and run the diagnostic it doesn't show errors in status also it says that it is enabled
also when trying to manualy create pair of folders to replicate the contents it says at one of the steps it is already used ....what would be the best
thing to do at this point o have replication issue solved ?
MAciunioC:\Users\Administrator.CON>dfsrdiag dumpadcfg
LDAP Bind : DC-SERVER2.CON.com
SitesDn : cn=sites,cn=configuration,dc=CON,dc=com
ServicesDn : cn=services,cn=configuration,dc=CON,dc=com
SystemDn : cn=system,DC=CON,DC=com
DefaultNcDn : DC=CON,DC=com
ComputersDn : cn=computers,DC=CON,DC=com
DomainCtlDn : ou=domain controllers,DC=CON,DC=com
SchemaDn : CN=Schema,CN=Configuration,DC=CON,DC=com
COMPUTER: DC-SERVER1
DN : cn=dc-server1,ou=domain controllers,dc=CON,dc=com
GUID : 3009B7C3-3316-411E-B4ED-ECEF72114C02
DNS : dc-server1.CON.com
Server BL : cn=dc-server1,cn=servers,cn=default-first-site-name,cn=sites,c
n=configuration,dc=CON,dc=com
Server Ref : (null)
USN Changed : 586839
When Created : Saturday, March 15, 2014 9:24:43 PM
When Changed : Saturday, July 26, 2014 9:16:42 AM
LOCAL SETTINGS: DFSR-LOCALSETTINGS
DN : cn=dfsr-localsettings,cn=dc-server1,ou=domain controllers,dc
=CON,dc=com
GUID : 3CD85D1B-177B-4CA4-BC15-2B9A87850553
Version : 1.0.0.0
USN Changed : 584264
When Created : Saturday, July 26, 2014 2:15:23 AM
When Changed : Saturday, July 26, 2014 2:25:26 AM
SUBSCRIBER: DOMAIN SYSTEM VOLUME
DN : cn=domain system volume,cn=dfsr-localsettings,cn=dc-server
1,ou=domain controllers,dc=CON,dc=com
GUID : 9B8DD38C-26D4-4E78-BC61-6F344C7938B0
Member Ref : cn=dc-server1,cn=topology,cn=domain system volume,cn=dfsr-
globalsettings,cn=system,dc=CON,dc=com
USN Changed : 584238
When Created : Saturday, July 26, 2014 2:15:23 AM
When Changed : Saturday, July 26, 2014 2:25:03 AM
SUBSCRIPTION: SYSVOL SUBSCRIPTION
DN : cn=sysvol subscription,cn=domain system volume,cn=dfsr-l
ocalsettings,cn=dc-server1,ou=domain controllers,dc=CON,dc=com
GUID : 0BC184CA-A02E-40BB-B257-DA32FF86F88A
ContentSetGuid: 342393C4-C03F-44B1-BE9A-8DFE1F906595
Root Path : c:\windows\sysvol\domain
Root Size : (null) (MB)
Staging Path : c:\windows\sysvol\staging areas\CON.com
Staging Size : (null) (MB)
Conflict Path : (null)
Conflict Size : (null) (MB)
USN Changed : 591605
When Created : Saturday, July 26, 2014 2:15:23 AM
When Changed : Saturday, July 26, 2014 9:41:57 PM
GLOBAL SETTINGS: DFSR-GLOBALSETTINGS
DN : cn=dfsr-globalsettings,cn=system,dc=CON,dc=com
GUID : 5708E418-6D80-45BD-AFC1-9135DEE1211A
USN Changed : 8313
When Created : Saturday, March 23, 2013 8:17:18 PM
When Changed : Sunday, March 9, 2014 5:06:58 AM
REPLICATION GROUP: DOMAIN SYSTEM VOLUME
DN : cn=domain system volume,cn=dfsr-globalsettings,cn=system,dc=
CON,dc=com
GUID : 31EFC46F-6D74-48FB-BA52-D6750206975B
Type : 1 (SYSVOL)
USN Changed : 8314
When Created : Saturday, March 23, 2013 8:17:19 PM
When Changed : Sunday, March 9, 2014 5:06:58 AM
CONTENT: CONTENT
DN : cn=content,cn=domain system volume,cn=dfsr-globalsettings,
cn=system,dc=CON,dc=com
GUID : 0DBFFC24-7793-48B4-B21E-49BAD434B8D6
USN Changed : 8315
When Created : Saturday, March 23, 2013 8:17:19 PM
When Changed : Sunday, March 9, 2014 5:06:58 AM
CONTENT SET: SYSVOL SHARE
DN : cn=sysvol share,cn=content,cn=domain system volume,cn=df
sr-globalsettings,cn=system,dc=CON,dc=com
GUID : 342393C4-C03F-44B1-BE9A-8DFE1F906595
File Filter : ~*,*.TMP,*.BAK
Compression Excl : (null)
Dir Filter : DO_NOT_REMOVE_NtFrs_PreInstall_Directory,NtFrs_PreExisti
ng___See_EventLog
USN Changed : 8316
When Created : Saturday, March 23, 2013 8:17:19 PM
When Changed : Sunday, March 9, 2014 5:06:58 AM
TOPOLOGY: TOPOLOGY
DN : cn=topology,cn=domain system volume,cn=dfsr-globalsettings
,cn=system,dc=CON,dc=com
GUID : 637AAE04-0A35-43BA-B6A2-1292049A6617
USN Changed : 8317
When Created : Saturday, March 23, 2013 8:17:19 PM
When Changed : Sunday, March 9, 2014 5:06:58 AM
MEMBER: DC-SERVER1
DN : cn=dc-server1,cn=topology,cn=domain system volume,cn=dfs
r-globalsettings,cn=system,dc=CON,dc=com
GUID : EBCFB268-8F7C-4C90-A49F-1018595A3D2C
Server Ref : cn=ntds settings,cn=dc-server1,cn=servers,cn=default-fir
st-site-name,cn=sites,cn=configuration,dc=CON,dc=com
Computer Ref : cn=dc-server1,ou=domain controllers,dc=CON,dc=com
Keywords : (null)
Computer DNS : dc-server1.CON.com
USN Changed : 584236
When Created : Saturday, July 26, 2014 2:15:23 AM
When Changed : Saturday, July 26, 2014 2:25:03 AM
CXTION: 2452641E-B5E9-4ABD-AA3F-38367137DFD1
DN : cn=2452641e-b5e9-4abd-aa3f-38367137dfd1,cn=ntds settin
gs,cn=dc-server1,cn=servers,cn=default-first-site-name,cn=sites,cn=configuration
,dc=CON,dc=com
GUID : 240A03AF-2CD0-4FBC-A56D-16BB90FE585A
Inbound : true
Partner DN : cn=dc-server2,cn=topology,cn=domain system volume,cn=d
fsr-globalsettings,cn=system,dc=CON,dc=com
USN Changed : 584199
When Created : Saturday, July 26, 2014 2:19:27 AM
When Changed : Saturday, July 26, 2014 2:25:02 AM
CXTION: 2A851034-2EF0-435F-A915-78380D4980EB
DN : cn=2a851034-2ef0-435f-a915-78380d4980eb,cn=ntds settin
gs,cn=dc-server2,cn=servers,cn=default-first-site-name,cn=sites,cn=configuration
,dc=CON,dc=com
GUID : A439D7E8-199F-42C3-854E-339559B5382B
Inbound : false
Partner DN : cn=dc-server2,cn=topology,cn=domain system volume,cn=d
fsr-globalsettings,cn=system,dc=CON,dc=com
USN Changed : 584228
When Created : Saturday, July 26, 2014 2:10:02 AM
When Changed : Saturday, July 26, 2014 2:25:02 AM
MEMBER: DC-SERVER2
DN : cn=dc-server2,cn=topology,cn=domain system volume,cn=dfs
r-globalsettings,cn=system,dc=CON,dc=com
GUID : B8A9BA79-D85E-4DE3-8199-827F356EA9F7
Server Ref : cn=ntds settings,cn=dc-server2,cn=servers,cn=default-fir
st-site-name,cn=sites,cn=configuration,dc=CON,dc=com
Computer Ref : cn=dc-server2,ou=domain controllers,dc=CON,dc=com
Keywords : (null)
Computer DNS : dc-server2.CON.com
USN Changed : 12334
When Created : Sunday, March 9, 2014 5:10:25 AM
When Changed : Sunday, March 9, 2014 5:10:25 AM
Operation Succeeded
MAciunio -
Unable to access sysvol using path \\domain.local\sysvol
Hi,
We found that our newly configured workstations were unable to read/apply GPOs. Upon checking, we are able to access the path \\domain.local. However, when trying to open sysvol folder (or any other shared folder on the domain controller), we receive the
following error:
We cannot also access the folders when using domain netbios name. Strangely enough, when using IP address or DC name, we can successfully map the sysvol folder.
Have also tried running DCdiag and the test
NCSecDesc fails with error:
Hope anyone can shed some light on what went wrong.
Thank you.Hi,
Based on your description, please make sure that TCP/IP NetBIOS Helper, Netlogon, and the Remote Procedure Call (RPC) services are started and set to Automatic.
If the issue persists, we can also try disjoining and rejoining the workstation.
The following thread focused on the similar issue and can be referred as reference.
Cannot access
\\domain\sysvol
http://social.technet.microsoft.com/Forums/windowsserver/en-US/c58600d7-5c7b-4cbb-9da4-4c98e3fa2997/cannot-access-domainsysvol?forum=windowsserver2008r2general
Best regards,
Frank Shen -
Difference between domain controllers and group policy objects in GPMC
Hello,
Am in confusion, someone can tel me the difference between
1.Domain controllers>default domain controller policy and
2.Group policy object>default domain controller policy
In Group policy management console and also i would like know where to define these categories. I normally use second option.
I have attached screenshot for your information.
regards,
Dharanesh,This first/upper item is a link to the GPO, the second/lower item is the actual GPO.
(notice the link, has a shortcut arrow showing)
by default, when you double-click on a link, a message will display which says "you have clicked on a link....." and the messagbox offers a checkbox for "do not display this message again..."
Effectively they are equivalent to a shortcut-to-a-file vs. the actual file.
Don
(Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!) -
Unable to sync Sent Folder for Exchange Account
Hi,
on my MacBook Pro I am using Mail to get my mails from an Exchange account. The problem is that I don't get all Sent messages in the Folder Sent.
On my iMac everything is working fine. When open the dialog "Account Info" on my iMac I see that there are 3000 message in the Sent folder. When I open the same dialog on my MBP I am getting the information that there are just 7 messages in this "Mailbox"
Please, please, help
regards
AndiIs there a folder under the Exchange IMAP mailboxes called Sent or Sent Items?
I'm not talking about at the top of the list where the Inbox, Sent, Junk etc resides, but towards the bottom of the mailbox list where all your IMAP account mailboxes are.
If so, select that folder and slect Use this mailbox for Sent from the Mailbox menu. -
When I upgraded to Leopard iCal worked fine for about 1 week. But since then I am unable to sync my calenders between my different Macs via my .Mac account, while there is no problem syncing the other applications (Contacts, Mail accounts...). Strangely the syncing of iCal works between my Mac and my iPod.
Has anybody an idea why syncing does not work between my Macs ?It seems everyone is having the same problem with Leopard and iCal. First, you probably noticed that the Leopard upgrade screwed up iCal and removed several features. Now you have learned with the rest of us have...iCal won't sync to .Mac so that other computers can be updated with the data.
I tried everything the .Mac support group sent me and more. Just like the others in the forum. Bottom line...the Leopard version of iCal won't sync. My suggestion is to go back to Tiger until that get this bug fixed.
<Edited by Moderator> -
Setting up Time Sync when all domain controllers are virtual machines?
We have 2 existing server 2008 domain controllers on 2008 Hyper-V. We plan to set up a third domain controller in a new AD site at a remote site that will be Server 2012 R2 on 2012R2 Hyper-V.
PDC role DC is on one of the DCs in the original site.
How should time syncing be set?
From what I've read, all Hyper-V time synchronization between the virtual domain controllers and their Hyper-V host should be disabled.
So, do we set up the PDC virtual machine to sync to an external site source and then expect the other 3 domain controllers to automatically sync with the time of the PDC?
What happens with this process during a PDC reboot or if that PDC role domain controller becomes unavailable for any other reason? Does one of the other DCs then take over the role of domain time source even through they don't have access to the external
time source?
Should we also turn off Hyper-V time syncing for every Hyper-V guest that is a member of our domain (since they should also be getting their time from a domain controller) or only turn off the Hyper-V time sync for the domain controllers alone?We have 2 existing server 2008 domain controllers on 2008 Hyper-V. We plan to set up a third domain controller in a new AD site at a remote site that will be Server 2012 R2 on 2012R2 Hyper-V.
PDC role DC is on one of the DCs in the original site.
How should time syncing be set?
Simply make sure that time sync is disabled on your Hyper-V VM. For time configuration in AD domain, I have documented that here: http://social.technet.microsoft.com/wiki/contents/articles/18573.time-synchronization-in-active-directory-forests.aspx
From what I've read, all Hyper-V time synchronization between the virtual domain controllers and their Hyper-V host should be disabled.
So, do we set up the PDC virtual machine to sync to an external site source and then expect the other 3 domain controllers to automatically sync with the time of the PDC?
They don't take over the role of PDC. The downtime of your PDC should not take a long time. That is why it is important to regularly monitor the health status of your DCs using SCOM or third party tools. The one I usually recommend is
Lepide Auditor - Active Directory: http://www.lepide.com/lepideauditor/active-directory.html. The solution allows you also to trackchanges
in your AD domain.
Should we also turn off Hyper-V time syncing for every Hyper-V guest that is a member of our domain
(since they should also be getting their time from a domain controller) or only turn off the Hyper-V time sync for the domain controllers alone?
I would recommend turning off the Hyper-V time sync on all your Hyper-V VMs that are domain-joined.
This posting is provided AS IS with no warranties or guarantees , and confers no rights.
Ahmed MALEK
My Website Link
My Linkedin Profile
My MVP Profile -
Excessive Traffic on Port 445 between 2 Domain Controllers
Hi, my company has over 45 DC's across about 25 sites worldwide. We are noticing a lot of traffic using wireshark and Network Monitor on Microsoft-DS port 445. I have been searching if this is normal and what I see is that it is used for SMB File and
print sharing. Well, I don't have any file shares on these DC's other than the normal admin shares and sysvol share. I don't believe this is replication traffic since these 2 servers are not replication partners. I have checked sites and services to make sure
the intersite and intrasite connections look good. This traffic is constant over weeks and it is about 1 GB an hour between the 2 servers. This would not be a big deal if this was just on the local LAN but it is over the WAN and
that saturates the line. Should 2 DC's be talking that much that are not even replication partners? What type of traffic could it be. I am at a loss for troubleshooting this. I have done packet captures but that really does
not tell me much ( that I can read anyway). Oh, I have run AV scans alos and finding nothing.
Any help would be greatly appreciated.
Steve
SteveActually, DFS/FRS/DFSR replication is not related to NTDS replication. It uses a directory change notification event to trigger replication to a replica, and that is to all DCs in the domain. That's why you can have SYSVOL replication problems but AD replication
of the partitions do not have problems, such as when you create a user on one and it replicates to it's NTDS partner.
Below is a summary. You can read about how the whole process with NTFRS/DFSR works in the links below, if you like:
Introduction to Administering DFS-Replicated SYSVOL
"DFS Replication technology significantly improves replication of SYSVOL. ... When a change to a file occurs, FRS replicates the entire updated file. With DFS Replication, for files larger than 64 KB, only the updated portion of the file is replicated."
"To replicate only updates to files, DFS Replication uses an algorithm called remote differential compression (RDC). RDC detects changes ... without having to replicate the entire file. RDC detects insertions, removals, and rearrangements of data
in files. The DFS Replication service monitors SYSVOL, and, if a change occurs to any file that is stored in SYSVOL, DFS Replication automatically replicates the file updates to the SYSVOL folders on the other domain controllers in the domain. "
http://technet.microsoft.com/en-us/library/cc794837(v=WS.10).aspx
How FRS Works - Windows 2003
http://technet.microsoft.com/en-us/library/cc758169(v=WS.10).aspx
DFS Replication: Frequently Asked Questions (FAQ)
http://technet.microsoft.com/en-us/library/cc773238(v=WS.10).aspx
I think 316 MB in SYSVOL is a good amount of data. What is in there taking up that much space? Is something using SYSVOL to store it's data, such as an app that's constantly changing data?
The reason I'm asking is that this could be the cause of the issue, since if it changes on one DC, then it replicates, then another change occurs, etc., and it keeps going and it appears that a ton of data is being moved back and forth.
Quick story - I remember a customer was using SYSVOL to store data so they can access it across the WAN link. He said he did it because of its "cool" replication features. I said, yea, but it's meant for domain data (GPO policies, templates, etc.)
and not for custom data. Create a DFS share for that so it works independently of SYSVOL.
Ace Fekay
MVP, MCT, MCSE 2012, MCITP EA & MCTS Windows 2008/R2, Exchange 2013, 2010 EA & 2007, MCSE & MCSA 2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer
Microsoft MVP - Directory Services
Complete List of Technical Blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php
This posting is provided AS-IS with no warranties or guarantees and confers no rights. -
Monitor Sysvol and netlogon Share availability on domain controllers
I need to monitor availability of sysvol and Netlogon shares on all our domain controllers around 20 in all.
What is the best way for us to do that.
I have seen scripts that monitor share availability but that would mean i create 40 such 2 times script monitors , that is too much of manual work..
Any advice.I looked into the discovered Inventory (SysVol for windows 2008) I see all theobjects
But the path shows as dc01.domain.com\dc01\sysvol
However we never get notified when the sysvol share is inaccessible.
We have had a number of cases when the DC is online but somehow we cant access the sysvol share
We need a monitor to alert us in such a case;
I modified the our script to include %computername% and targeted it to all dC's group,
Dim oAPI, oBag
Set oAPI = CreateObject("MOM.ScriptAPI")
Set oBag = oAPI.CreatePropertyBag()
Set objFSO = CreateObject("Scripting.FileSystemObject")
strFile = "\\%computername%\sysvol\"
If objFSO.FolderExists(strFile) Then
Call oBag.AddValue("Status","Exist")
Call oAPI.Return(oBag)
Else
Call oBag.AddValue("Status","NotExist")
Call oAPI.Return(oBag)
End If
However the monitor alerted critical immediately.
How should the monitor be.
I though if i put \\%computername%\sysvol\ in the script and send it to all the DC's group then it will start monitoring as \\dc01\sysvol etc -
Replication and AD Domain sevices errors between 2 Domain Controllers
Hi,
I've a 2 Domain Controllers (NJ-DC1-2K8 and NJ-DC2-2K8) setup in VMware Workstation 10. Recently, I've run into different errors in regards to Replication, DNS and AD Domain services. Both of my DC are setup with static IP pointing to each other for fault
tolerance. Initially, One of my DC had a lingering object error which I was able to fix after spending some time. The next day, when I tried to replicate 2 DC, the number of errors grew. Ran dcdiag, it produced a list of crazy errors that I never saw before.
I'm a newbie to the server environment, trying to gain knowledge so I can't get those errors sort out even I tried a lot. I read a lot of online articles on different forums like here Microsoft TechNet trying to overcome this problem but didn't work. I even
removed DNS role and re-added it but same problem. I guess removing the DNS role doesn't remove everything related to DNS. I'm going to upload pictures here of the different errors through the commands I got. I would appreciate if someone can help me to get
it fixed.
Other than that, I also would like to know what is the best way to remove DNS, AD Domain Services and then reinstall them without demoting the server. What are some of the things I would have to keep in mind before doing that. How can I make sure that doing
this wouldn't impact in AD data loss like user account, GP Policies, Computer account and etc....?
Errors are as follows:
1) C:\Users\Administrator>repadmin /syncall
CALLBACK MESSAGE: The following replication is in progress:
From: 66803610-2817-4853-ad3b-70c32a78c04a._msdcs.Fleet.local
To : 9736b2e5-a75e-4991-a481-08c0226ed1c5._msdcs.Fleet.local
CALLBACK MESSAGE: Error issuing replication: 8451 (0x2103):
The replication operation encountered a database error.
From: 66803610-2817-4853-ad3b-70c32a78c04a._msdcs.Fleet.local
To : 9736b2e5-a75e-4991-a481-08c0226ed1c5._msdcs.Fleet.local
CALLBACK MESSAGE: SyncAll Finished.
SyncAll reported the following errors:
Error issuing replication: 8451 (0x2103):
The replication operation encountered a database error.
From: 66803610-2817-4853-ad3b-70c32a78c04a._msdcs.Fleet.local
To : 9736b2e5-a75e-4991-a481-08c0226ed1c5._msdcs.Fleet.local
2) C:\Users\Administrator>repadmin /showrepl
Repadmin: running command /showrepl against full DC localhost
NewJersey\NJ-DC1-2K8
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 9736b2e5-a75e-4991-a481-08c0226ed1c5
DSA invocationID: 9736b2e5-a75e-4991-a481-08c0226ed1c5
==== INBOUND NEIGHBORS ======================================
DC=Fleet,DC=local
NewJersey\NJ-DC2-2K8 via RPC
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
Last attempt @ 2014-07-06 20:49:06 failed, result 8456 (0x2108):
The source server is currently rejecting replication requests.
30 consecutive failure(s).
Last success @ 2014-07-06 16:16:49.
CN=Configuration,DC=Fleet,DC=local
NewJersey\NJ-DC2-2K8 via RPC
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
Last attempt @ 2014-07-06 20:49:06 failed, result 8456 (0x2108):
The source server is currently rejecting replication requests.
29 consecutive failure(s).
Last success @ 2014-07-06 16:06:25.
CN=Schema,CN=Configuration,DC=Fleet,DC=local
NewJersey\NJ-DC2-2K8 via RPC
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
Last attempt @ 2014-07-06 20:49:06 failed, result 8456 (0x2108):
The source server is currently rejecting replication requests.
10 consecutive failure(s).
Last success @ 2014-07-06 15:49:54.
DC=DomainDnsZones,DC=Fleet,DC=local
NewJersey\NJ-DC2-2K8 via RPC
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
Last attempt @ 2014-07-06 20:49:06 failed, result 8456 (0x2108):
The source server is currently rejecting replication requests.
30 consecutive failure(s).
Last success @ 2014-07-06 15:49:54.
DC=ForestDnsZones,DC=Fleet,DC=local
NewJersey\NJ-DC2-2K8 via RPC
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
Last attempt @ 2014-07-06 20:49:06 failed, result 8456 (0x2108):
The source server is currently rejecting replication requests.
19 consecutive failure(s).
Last success @ 2014-07-06 16:10:47.
Source: NewJersey\NJ-DC2-2K8
******* 30 CONSECUTIVE FAILURES since 2014-07-06 16:16:49
Last error: 8456 (0x2108):
The source server is currently rejecting replication requests.
3) C:\Users\Administrator>dcdiag /replsum
Invalid Syntax: Invalid option /replsum. Use dcdiag.exe /h for help.
C:\Users\Administrator>repadmin /replsum
Replication Summary Start Time: 2014-07-06 21:03:28
Beginning data collection for replication summary, this may take awhile:
Source DSA largest delta fails/total %% error
NJ-DC1-2K8 09d.22h:06m:34s 5 / 5 100 (8457) The destination server is currently rejecting replication requests.
NJ-DC2-2K8 05h:13m:34s 5 / 5 100 (8456) The source server is currently rejecting replication requests.
Destination DSA largest delta fails/total %% error
NJ-DC1-2K8 05h:13m:34s 5 / 5 100 (8456) The source server is currently rejecting replication requests.
NJ-DC2-2K8 09d.22h:06m:34s 5 / 5 100 (8457) The destination server is currently rejecting replication requests.
4) C:\Users\Administrator>dcdiag /test:DNS
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = NJ-DC1-2K8
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: NewJersey\NJ-DC1-2K8
Starting test: Connectivity
......................... NJ-DC1-2K8 passed test Connectivity
Doing primary tests
Testing server: NewJersey\NJ-DC1-2K8
Starting test: DNS
DNS Tests are running and not hung. Please wait a few minutes...
......................... NJ-DC1-2K8 passed test DNS
Running partition tests on : ForestDnsZones
Running partition tests on : DomainDnsZones
Running partition tests on : Schema
Running partition tests on : Configuration
Running partition tests on : Fleet
Running enterprise tests on : Fleet.local
Starting test: DNS
Summary of test results for DNS servers used by the above domain controllers:
DNS server: 128.8.10.90 (d.root-servers.net.)
1 test failure on this DNS server
PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 128.8.10.90
......................... Fleet.local passed test DNS
5) C:\Users\Administrator>dcdiag
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = NJ-DC1-2K8
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: NewJersey\NJ-DC1-2K8
Starting test: Connectivity
......................... NJ-DC1-2K8 passed test Connectivity
Doing primary tests
Testing server: NewJersey\NJ-DC1-2K8
Starting test: Advertising
......................... NJ-DC1-2K8 passed test Advertising
Starting test: FrsEvent
......................... NJ-DC1-2K8 passed test FrsEvent
Starting test: DFSREvent
There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... NJ-DC1-2K8 failed test DFSREvent
Starting test: SysVolCheck
......................... NJ-DC1-2K8 passed test SysVolCheck
Starting test: KccEvent
......................... NJ-DC1-2K8 passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... NJ-DC1-2K8 passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... NJ-DC1-2K8 passed test MachineAccount
Starting test: NCSecDesc
......................... NJ-DC1-2K8 passed test NCSecDesc
Starting test: NetLogons
......................... NJ-DC1-2K8 passed test NetLogons
Starting test: ObjectsReplicated
......................... NJ-DC1-2K8 passed test ObjectsReplicated
Starting test: Replications
[Replications Check,NJ-DC1-2K8] A recent replication attempt failed:
From NJ-DC2-2K8 to NJ-DC1-2K8
Naming Context: DC=ForestDnsZones,DC=Fleet,DC=local
The replication generated an error (8456):
The source server is currently rejecting replication requests.
The failure occurred at 2014-07-06 20:49:06.
The last success occurred at 2014-07-06 16:10:47.
19 failures have occurred since the last success.
Replication has been explicitly disabled through the server options.
[Replications Check,NJ-DC1-2K8] A recent replication attempt failed:
From NJ-DC2-2K8 to NJ-DC1-2K8
Naming Context: DC=DomainDnsZones,DC=Fleet,DC=local
The replication generated an error (8456):
The source server is currently rejecting replication requests.
The failure occurred at 2014-07-06 21:04:16.
The last success occurred at 2014-07-06 15:49:54.
31 failures have occurred since the last success.
Replication has been explicitly disabled through the server options.
[Replications Check,NJ-DC1-2K8] A recent replication attempt failed:
From NJ-DC2-2K8 to NJ-DC1-2K8
Naming Context: CN=Schema,CN=Configuration,DC=Fleet,DC=local
The replication generated an error (8456):
The source server is currently rejecting replication requests.
The failure occurred at 2014-07-06 20:49:06.
The last success occurred at 2014-07-06 15:49:54.
10 failures have occurred since the last success.
Replication has been explicitly disabled through the server options.
[Replications Check,NJ-DC1-2K8] A recent replication attempt failed:
From NJ-DC2-2K8 to NJ-DC1-2K8
Naming Context: CN=Configuration,DC=Fleet,DC=local
The replication generated an error (8456):
The source server is currently rejecting replication requests.
The failure occurred at 2014-07-06 20:49:06.
The last success occurred at 2014-07-06 16:06:25.
29 failures have occurred since the last success.
Replication has been explicitly disabled through the server options.
[Replications Check,NJ-DC1-2K8] A recent replication attempt failed:
From NJ-DC2-2K8 to NJ-DC1-2K8
Naming Context: DC=Fleet,DC=local
The replication generated an error (8456):
The source server is currently rejecting replication requests.
The failure occurred at 2014-07-06 20:49:06.
The last success occurred at 2014-07-06 16:16:49.
30 failures have occurred since the last success.
Replication has been explicitly disabled through the server options.
......................... NJ-DC1-2K8 failed test Replications
Starting test: RidManager
......................... NJ-DC1-2K8 passed test RidManager
Starting test: Services
......................... NJ-DC1-2K8 passed test Services
Starting test: SystemLog
A warning event occurred. EventID: 0x000003F6
Time Generated: 07/06/2014 20:17:29
Event String: Name resolution for the name 2.5.16.172.in-addr.arpa timed out after none of the configured DNS servers responded.
An error event occurred. EventID: 0x0000168E
Time Generated: 07/06/2014 20:18:05
Event String:
The dynamic registration of the DNS record '9736b2e5-a75e-4991-a481-08c0226ed1c5._msdcs.Fleet.local. 600 IN CNAME NJ-DC1-2K8.Fleet.local.'
failed on the following DNS server:
A warning event occurred. EventID: 0x000003F6
Time Generated: 07/06/2014 21:04:01
Event String: Name resolution for the name 1.0.0.127.in-addr.arpa timed out after none of the configured DNS servers responded.
......................... NJ-DC1-2K8 failed test SystemLog
Starting test: VerifyReferences
......................... NJ-DC1-2K8 passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : Fleet
Starting test: CheckSDRefDom
......................... Fleet passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Fleet passed test CrossRefValidation
Running enterprise tests on : Fleet.local
Starting test: LocatorCheck
......................... Fleet.local passed test LocatorCheck
Starting test: Intersite
......................... Fleet.local passed test Intersite
6) C:\Users\Administrator>repadmin /showrepl NJ-DC1-2K8
NewJersey\NJ-DC1-2K8
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 9736b2e5-a75e-4991-a481-08c0226ed1c5
DSA invocationID: 9736b2e5-a75e-4991-a481-08c0226ed1c5
==== INBOUND NEIGHBORS ======================================
DC=Fleet,DC=local
NewJersey\NJ-DC2-2K8 via RPC
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
Last attempt @ 2014-07-06 20:49:06 failed, result 8456 (0x2108):
The source server is currently rejecting replication requests.
30 consecutive failure(s).
Last success @ 2014-07-06 16:16:49.
CN=Configuration,DC=Fleet,DC=local
NewJersey\NJ-DC2-2K8 via RPC
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
Last attempt @ 2014-07-06 20:49:06 failed, result 8456 (0x2108):
The source server is currently rejecting replication requests.
29 consecutive failure(s).
Last success @ 2014-07-06 16:06:25.
CN=Schema,CN=Configuration,DC=Fleet,DC=local
NewJersey\NJ-DC2-2K8 via RPC
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
Last attempt @ 2014-07-06 20:49:06 failed, result 8456 (0x2108):
The source server is currently rejecting replication requests.
10 consecutive failure(s).
Last success @ 2014-07-06 15:49:54.
DC=DomainDnsZones,DC=Fleet,DC=local
NewJersey\NJ-DC2-2K8 via RPC
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
Last attempt @ 2014-07-06 21:04:16 failed, result 8456 (0x2108):
The source server is currently rejecting replication requests.
31 consecutive failure(s).
Last success @ 2014-07-06 15:49:54.
DC=ForestDnsZones,DC=Fleet,DC=local
NewJersey\NJ-DC2-2K8 via RPC
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
Last attempt @ 2014-07-06 20:49:06 failed, result 8456 (0x2108):
The source server is currently rejecting replication requests.
19 consecutive failure(s).
Last success @ 2014-07-06 16:10:47.
Source: NewJersey\NJ-DC2-2K8
******* 31 CONSECUTIVE FAILURES since 2014-07-06 16:16:49
Last error: 8456 (0x2108):
The source server is currently rejecting replication requests.
7) C:\Users\Administrator>repadmin /showrepl NJ-DC2-2K8
NewJersey\NJ-DC2-2K8
DSA Options: IS_GC DISABLE_INBOUND_REPL DISABLE_OUTBOUND_REPL
Site Options: (none)
DSA object GUID: 66803610-2817-4853-ad3b-70c32a78c04a
DSA invocationID: 3e8ee380-a165-4cef-b311-dadcf30f8406
==== INBOUND NEIGHBORS ======================================
DC=Fleet,DC=local
NewJersey\NJ-DC1-2K8 via RPC
DSA object GUID: 9736b2e5-a75e-4991-a481-08c0226ed1c5
Last attempt @ 2014-07-06 21:04:22 failed, result 8457 (0x2109):
The destination server is currently rejecting replication requests.
53 consecutive failure(s).
Last success @ 2014-06-26 23:01:29.
CN=Configuration,DC=Fleet,DC=local
NewJersey\NJ-DC1-2K8 via RPC
DSA object GUID: 9736b2e5-a75e-4991-a481-08c0226ed1c5
Last attempt @ 2014-07-06 20:52:11 failed, result 8457 (0x2109):
The destination server is currently rejecting replication requests.
10 consecutive failure(s).
Last success @ 2014-06-26 22:56:54.
CN=Schema,CN=Configuration,DC=Fleet,DC=local
NewJersey\NJ-DC1-2K8 via RPC
DSA object GUID: 9736b2e5-a75e-4991-a481-08c0226ed1c5
Last attempt @ 2014-07-06 20:52:11 failed, result 8457 (0x2109):
The destination server is currently rejecting replication requests.
7 consecutive failure(s).
Last success @ 2014-06-26 22:56:56.
DC=DomainDnsZones,DC=Fleet,DC=local
NewJersey\NJ-DC1-2K8 via RPC
DSA object GUID: 9736b2e5-a75e-4991-a481-08c0226ed1c5
Last attempt @ 2014-07-06 20:52:11 failed, result 8457 (0x2109):
The destination server is currently rejecting replication requests.
7 consecutive failure(s).
Last success @ 2014-06-26 22:57:01.
DC=ForestDnsZones,DC=Fleet,DC=local
NewJersey\NJ-DC1-2K8 via RPC
DSA object GUID: 9736b2e5-a75e-4991-a481-08c0226ed1c5
Last attempt @ 2014-07-06 20:52:11 failed, result 8457 (0x2109):
The destination server is currently rejecting replication requests.
23 consecutive failure(s).
Last success @ 2014-06-26 22:57:03.
Source: NewJersey\NJ-DC1-2K8
******* 53 CONSECUTIVE FAILURES since 2014-06-26 23:01:29
Last error: 8457 (0x2109):
The destination server is currently rejecting replication requests.
Please someone go through these different errors and walk me through exactly what I got to do to fix them.
ThanksHi,
Actually, I made copies of those VMs to my external usb 3.0 hdd, so I can load up some of the VMs from it than from my internal hdd since it would freeze on my internal one sometimes. Copied ones worked fine for few days until recently when I started having
these different issues. I did look at USN rollback and applied the fix, didn't work. For the past few days, I been spending endless hours on fixing them but it doesn't look like they are going to be fixed. It's driving me crazy and the bad news is that I've
no backup of my data. I got 2 DC and both have these issues.
Building new domain controllers in VMs won't be a problem for me but I'm worried about losing my AD database in both DCs which includes user and computer accounts and a bunch GPOs.
I'm a newbie to the server environment. Can you please walk me through on exactly how can I save AD database if possible before I start doing the cleanup process on both of my DCs. I read some articles online which provide instructions on how can I cleanup
the AD with Metadata and take both DCs offline but it's all confusing to me. They don't explain anything about saving AD database rather demoting bad DCs. If you know a fix for my DCs that I can apply, so I won't have do it all over and save time. Please let
me know step by step process or whatever you could help me to bring those 2 DCs backup.
Thanks -
Unable to sync emails between iPhone 5s and I mac
During some messing about with settings, possibly even chain, I've been unable to sync my emails from my mac accounts and cox accounts between my I mac and my IPhone 5s. Help?
Hi connietanms,
Here is an article that will help you back up your iCal data:
How to back up iCal calendar data
http://support.apple.com/kb/HT2966
I would recommend that you back up your iPhone as well:
iOS: Back up and restore your iOS device with iCloud or iTunes
http://support.apple.com/kb/HT1766
Here is one more article that will help you finalize this procedure and will give you the best steps to importing your iCal events into iCloud so they can be synced to both of your devices:
iCloud: Manually importing data from Calendar or iCal to iCloud Calendar
http://support.apple.com/kb/HT4967
Thanks for using the Apple Support Communities. Have a good one!
-Braden -
I get the message "unable to sync ipod. Required folder is missing". Never saw this before, and I have synced hundreds of times before. Does anyone know why?
Try deleting the iPod Photo Cache folder. There may be more than one such folder. For its location see:
iTunes: Photo sync creates iPod Photo Cac -
Unable to sync reminders between devices
hi, why is it that i am unable to sync my reminders app with my imac, iphone and ipad using icloud or itunes?
Hello Melvin,
It is definitely important to have your reminders synced between your devices. I found an article that assists with troubleshooting reminders that are not syncing properly:
iCloud: Troubleshooting iCloud Reminders and Tasks
http://support.apple.com/kb/TS4000
I would pay attention to only the sections that are relevent to your devices: "General Troubleshooting," "Troubleshooting Reminders on OS X Mountain Lion," and "Troubleshooting Reminders on iOS devices."
I hope this helps you get back on track!
Best,
Sheila M.
Maybe you are looking for
-
I'm in CS5.5 . I have no problem placing an Excel spreadsheet with the cell range I want and applying cell formatting in InDesign. I am trying to build eight similar documents that will pull data in several tables from a document specific Excel sprea
-
Photoshop CS4 Extended popup on startup
Hey guys, Recently, I got some help in getting the latest patch for PS and drivers for my graphics card so I could work with 3D modelling etc. Once all that was updated however, I kept getting this dialog box pop up every time I started Photoshop. It
-
Default email address in Ical alarm
Hi all. I am having problems setting the default address in alarms in Ical. The situation is like this: -I had 2 emails, "a" and "b", setup in my address book, both in my account (word "me" overlay on my picture). -When I wanted to configure an email
-
TS2446 how to reactive my apple account
resently i was downloading music on to my ipod touch 4 generation and it asked for my answers to my secret questions and i forgot the answers. then it deactivated my account for to many attempts. how do i get back on?
-
SWF at 100 % width and proportional height
I have a SWF that I would like to use in an XHTML 1.0 Strict document. My need is that the flash must: - Be 100% width - Grow / shrink proportionally in height (depending on width) - The flash may not be cropped or distorted - I must be able to to pu