still trying to fix my AD issues (mainly FRS)
so, start off: did not set network/these systems , came in major issue, realizing needed fixed.
for whatever reason our main dc (which assigned of roles) dropped , dc available domain controllers performingsome functions. noticed symptoms first when gpos weren't correctly synced, noticed dns mishaps. make long story short: had manually add using adsiedit (under system->frs->domainsysvol readded missing server object , under domaincontrollers->dc->ntfrssubscriber added missing attributes)
i ended demoting second dc had these issues , stopped dns (removed referneces remained) , it's out of equation.
dcdiag reports cleaned , not showing original errors relating 2 problematic domain controllers.
i have 3 local dc's (i'll call site1), 2 dcs in each of own sites respectively.
all dcs 2003r2, exception of 1 being 2008r2 (which not original main dc, in site1)
frs events on dcs show error:
the file replication service having trouble enabling replication anyotherdc thisdc c:\windows\sysvol\domain using dns name anyotherdc.domain.com. frs keep retrying.
following of reasons see warning.
[1] frs can not correctly resolve dns name anyotherdc.domain.com computer.
[2] frs not running on anyotherdc.domain.com.
[3] topology information in active directory replica has not yet replicated domain controllers.
this event log message appear once per connection, after problem fixed see event log message indicating connection has been established.
it's funny because dcs can ping eachother using dns, , seem replicate else these shared folders. went adsites&services , removed links , had rebuild them automatically (which worked) , servers seem point eachother.
so sum up: dcdiag looks ok, repadmin seems fine. dns looks good. eveything syncronizing frs volumes. have been using tools in kit see issues nothing sticks out.
any advice appreciated.
i managed squelch machineaccount issue attribute change, went aduc , changed domain controller object's useraccountcontrol match main dc 0x82000, or actual value of 532480. found information @ below website, mentioned in dcdiag error report didn't pay attention suppose:
Windows Server > Directory Services
Comments
Post a Comment