Michael
08-28-2008, 05:29 AM
I have been experiencing problems with Acctive Directory between sites. I would appreciate if someone can help.
Site Layout: 1 Domain wgl.local with 2 sites.
Site 1: Ip Subnet 192.168.50.0
Dc1 (Windows Server 2003 Enterprise Edition 32 Bit. Global Catalogue Server and Bridgehead Server. Active Directory Domain Controller with AD Integrated DNS )
Dc2 (Windows Server 2003 Enterprise Edition 32 Bit. Active Directory Domain Controller with AD Integrated DNS)
Site 2: Ip Subnet 172.21.78.0
Dc3 (Windows Server 2003 R2 Enterprise Edition 64 Bit. Global Catalogue Server and Bridgehead Server. Active Directory Domain Controller with AD Integrated DNS)
We have 2 netscreen firewall connecting both sites via a static route based VPN. I have opened up all ports on each side of the firewall to ensure that no traffic is being blocked. I can ping to and from between both sites and regulary use RDP to connect to the Servers in site 1 with no problems whatsoever.
I understand that I had to ADPREP the forest of the 32bit domain controllers and that is what I did so that I could attempt the initial install of DC3. I did the ADPREP/forestprep via the use of the schema update from Microsoft (KB Article Number(s): 919151) on Dc1. Also, as I am already running the latest Service Packs on Dc1 there was no need to run adprep /domainprep well this is according to Microsoft's website (http://technet.microsoft.com/en-us/library/cc773360.aspx). I have also verified that the Schema was updated to R2.
With regards to my DC3 server in site 2. I ran Dcpromo and got the error message at the end of install ""Replication of the domain information was not completed due to an error, but will be completed after the computer is restarted"
I checked and noticed nothing was replicated between sites. I then did another attempt. I demoted the server via the force procedure as I was unable to demote it via the normal dcpromo procedure. I then via Ntdsutil did the metadata cleanup of that server from the main Dc1. I also ensured no old DNS records were left.
Once DC3 was fully demoted and a standard Server 2003. I renamed the server to a different name now called "server3". Restarted the server. I then changed its IP Address also and restarted the server once again and was no just a member of the "WORKGROUP" group. I checked the Event logs to ensure no errors were in place on the server. All OK.
I then did a windows server update to see if any newly released updates were available from MS. None required.
I then joined server3 to the domain to make it a member server. All Okay. I made it a secondary DNS server, all OK. The DNS zone transfer from DC1 took less than a few seconds to copy over. All well so far. From Server3, did an Nslookup of the Servers and even workstations in Site 1 via the Netbios names. All working fine. Even did reverse lookups to lookup an ip address so that it can resolve it to a name. All fine.
Likewise from Site 1, from Dc1, Dc2 and some workstations I did Forward and Reverse lookups for server3 situated in site 2. No problems.
I have checked the event logs on server3 and all is okay. No problems.
I then pinged the servers to and from site 1 and also from site 2. No problems.
Its now where I dread the problems to happen again.
I run Dcpromo from server3 in site 2.
At the end prompt after completing the process the same prompt comes up saying "Replication of the domain information was not completed due to an error, but will be completed after the computer is restarted".
On restart of server3, it is now an AD doman controller but no information was replicated from dc1!
If I go to the DNS MMC from Server3. It shows "X it cannot contact the DNS Server". If you look at the DNS Events it has an event id 4013. (The DNS Server was unable to open the Active Directory...)
If I go to Active Directory Users and computers MMC and connect to server 3 domain controller I can see no users or OU objects was replicated. I can not understand why not!!. I can connect to Dc1 and Dc2 Domain controllers from the MMC from Server 3 and see all the OU and containers.
I have run out of ideas and hope you can please help.
Is there any setting that you need to define under global policy to allow replication of AD between sites.
I can see that AD Replication is working fine between dc1 and dc2 in site 1 so was wondering is there anything that you need to set to permit replication or other between sites?
Your help would be much appreciated.
Michael
Site Layout: 1 Domain wgl.local with 2 sites.
Site 1: Ip Subnet 192.168.50.0
Dc1 (Windows Server 2003 Enterprise Edition 32 Bit. Global Catalogue Server and Bridgehead Server. Active Directory Domain Controller with AD Integrated DNS )
Dc2 (Windows Server 2003 Enterprise Edition 32 Bit. Active Directory Domain Controller with AD Integrated DNS)
Site 2: Ip Subnet 172.21.78.0
Dc3 (Windows Server 2003 R2 Enterprise Edition 64 Bit. Global Catalogue Server and Bridgehead Server. Active Directory Domain Controller with AD Integrated DNS)
We have 2 netscreen firewall connecting both sites via a static route based VPN. I have opened up all ports on each side of the firewall to ensure that no traffic is being blocked. I can ping to and from between both sites and regulary use RDP to connect to the Servers in site 1 with no problems whatsoever.
I understand that I had to ADPREP the forest of the 32bit domain controllers and that is what I did so that I could attempt the initial install of DC3. I did the ADPREP/forestprep via the use of the schema update from Microsoft (KB Article Number(s): 919151) on Dc1. Also, as I am already running the latest Service Packs on Dc1 there was no need to run adprep /domainprep well this is according to Microsoft's website (http://technet.microsoft.com/en-us/library/cc773360.aspx). I have also verified that the Schema was updated to R2.
With regards to my DC3 server in site 2. I ran Dcpromo and got the error message at the end of install ""Replication of the domain information was not completed due to an error, but will be completed after the computer is restarted"
I checked and noticed nothing was replicated between sites. I then did another attempt. I demoted the server via the force procedure as I was unable to demote it via the normal dcpromo procedure. I then via Ntdsutil did the metadata cleanup of that server from the main Dc1. I also ensured no old DNS records were left.
Once DC3 was fully demoted and a standard Server 2003. I renamed the server to a different name now called "server3". Restarted the server. I then changed its IP Address also and restarted the server once again and was no just a member of the "WORKGROUP" group. I checked the Event logs to ensure no errors were in place on the server. All OK.
I then did a windows server update to see if any newly released updates were available from MS. None required.
I then joined server3 to the domain to make it a member server. All Okay. I made it a secondary DNS server, all OK. The DNS zone transfer from DC1 took less than a few seconds to copy over. All well so far. From Server3, did an Nslookup of the Servers and even workstations in Site 1 via the Netbios names. All working fine. Even did reverse lookups to lookup an ip address so that it can resolve it to a name. All fine.
Likewise from Site 1, from Dc1, Dc2 and some workstations I did Forward and Reverse lookups for server3 situated in site 2. No problems.
I have checked the event logs on server3 and all is okay. No problems.
I then pinged the servers to and from site 1 and also from site 2. No problems.
Its now where I dread the problems to happen again.
I run Dcpromo from server3 in site 2.
At the end prompt after completing the process the same prompt comes up saying "Replication of the domain information was not completed due to an error, but will be completed after the computer is restarted".
On restart of server3, it is now an AD doman controller but no information was replicated from dc1!
If I go to the DNS MMC from Server3. It shows "X it cannot contact the DNS Server". If you look at the DNS Events it has an event id 4013. (The DNS Server was unable to open the Active Directory...)
If I go to Active Directory Users and computers MMC and connect to server 3 domain controller I can see no users or OU objects was replicated. I can not understand why not!!. I can connect to Dc1 and Dc2 Domain controllers from the MMC from Server 3 and see all the OU and containers.
I have run out of ideas and hope you can please help.
Is there any setting that you need to define under global policy to allow replication of AD between sites.
I can see that AD Replication is working fine between dc1 and dc2 in site 1 so was wondering is there anything that you need to set to permit replication or other between sites?
Your help would be much appreciated.
Michael