+ Post New Thread
Page 1 of 3 123 LastLast
Results 1 to 15 of 40
Windows Server 2008 R2 Thread, AD replication shafted! in Technical; Hi all, We have a self created problem here and are trying to find a way back! We have 2 ...
  1. #1

    Join Date
    Oct 2006
    Location
    England
    Posts
    86
    Thank Post
    1
    Thanked 1 Time in 1 Post
    Rep Power
    0

    AD replication shafted!

    Hi all,

    We have a self created problem here and are trying to find a way back! We have 2 DCs each hosted on a seperate VM host. Due to problems with (what appears to be iSCSI) losing mapped drives, we decided to take DC2 down and bring it back up on another host. To cut a long story short, we got our knickers in a twist and brought up the wrong snapshot up (about 3 weeks old) which resulted in an older version of AD coming back up. We didn't realise at the time and happily carried on with what we were testing and then brought it back up on the original VM host. Now (obviously) replication is broken, causing all sorts of mayhem with GP not applying correctly etc.

    Is there any way to force DC2 to replicate from DC1 to bring it up to date? or is the only way to Demote DC2 and then Re-Promo it?

    Thanks for any help.

    Manick

  2. #2
    jamesreedersmith's Avatar
    Join Date
    Sep 2009
    Location
    Ruskington
    Posts
    1,104
    Thank Post
    77
    Thanked 242 Times in 216 Posts
    Rep Power
    74
    If its only a DC/DNS server then dump it and build a new one!

  3. #3
    jsnetman's Avatar
    Join Date
    Oct 2007
    Posts
    887
    Thank Post
    23
    Thanked 134 Times in 126 Posts
    Rep Power
    39
    Do you not need to do a Non Authorative Restore on the duff DC, I think that would work.

    http://technet.microsoft.com/en-us/l...83(WS.10).aspx
    Last edited by jsnetman; 13th December 2011 at 03:32 PM.

  4. #4

    3s-gtech's Avatar
    Join Date
    Mar 2009
    Location
    Wales
    Posts
    2,484
    Thank Post
    133
    Thanked 488 Times in 436 Posts
    Rep Power
    138
    Dump it and re-build. Lesson - do not snapshot DCs! System State them, but with the nature of multiple DCs you should not need to have snapshots anyway.

  5. #5

    Join Date
    Oct 2006
    Location
    England
    Posts
    86
    Thank Post
    1
    Thanked 1 Time in 1 Post
    Rep Power
    0
    Thanks for that,

    It provides network shares, DHCP, DNS and is also a print server. I think what I'll do is bring up a DC3 and DCpromo it, attach the shared storage to it and then demote DC2 cleam it up and bring it back up.

    When i say snapshot, I mean a VM snapshot.

    Many thanks

    Manick

  6. #6

    sparkeh's Avatar
    Join Date
    May 2007
    Posts
    6,259
    Thank Post
    1,138
    Thanked 1,463 Times in 980 Posts
    Blog Entries
    22
    Rep Power
    457
    Never snapshot a VM DC, it is not recommended by MS and bad things can come of it.
    I would try the Non Authorative Restore as suggested by @jsnetman as that should bring it in line with the other DC. edit: didn't actually mean this, see below.
    Last edited by sparkeh; 13th December 2011 at 04:33 PM.

  7. #7


    Join Date
    Mar 2009
    Location
    Leeds
    Posts
    6,208
    Thank Post
    218
    Thanked 812 Times in 694 Posts
    Rep Power
    274
    Quote Originally Posted by sparkeh View Post
    Never snapshot a VM DC, it is not recommended by MS and bad things can come of it.
    I would try the Non Authorative Restore as suggested by @jsnetman as that should bring it in line with the other DC.
    i suspect if its the only dc its not that bad but with multi dcs somethings bound to go wrong

  8. #8

    Join Date
    Oct 2006
    Location
    England
    Posts
    86
    Thank Post
    1
    Thanked 1 Time in 1 Post
    Rep Power
    0
    Hi,

    Is it the case that I should be able to just do a Demote and then promote it again? Surely when It's promoted it'll pick up AD from the remaining workable DC1?

    Again, thanks

    manick

  9. #9

    3s-gtech's Avatar
    Join Date
    Mar 2009
    Location
    Wales
    Posts
    2,484
    Thank Post
    133
    Thanked 488 Times in 436 Posts
    Rep Power
    138
    Quote Originally Posted by manick View Post
    When i say snapshot, I mean a VM snapshot.
    I realise, as @sparkeh says you must not snapshot a VM DC.

    In theory, it should pick up again from the remaining DC if you dcpromo. Make sure that has all necessary roles and that AD works okay with just that one online.

  10. #10

    sparkeh's Avatar
    Join Date
    May 2007
    Posts
    6,259
    Thank Post
    1,138
    Thanked 1,463 Times in 980 Posts
    Blog Entries
    22
    Rep Power
    457
    Sorry I didn't actually mean to use the process linked to by @jsnetman but rather the process for Nonauthoritative restore here: Using the BurFlags registry key to reinitialize File Replication Service replica sets
    Read the article and I think it applies to your situation, the process just makes the borked AD reinitialise with the good AD.

  11. #11

    m25man's Avatar
    Join Date
    Oct 2005
    Location
    Romford, Essex
    Posts
    1,608
    Thank Post
    49
    Thanked 444 Times in 330 Posts
    Rep Power
    136
    Does this not underpin the argument about maintaining a dedicated hardware server for the sole purpose of maintaining the AD?

    Thats what we do, we always have a 1u single cpu server with a pair of mirrored (preferably SAS HDD's) and a USB drive attached using the Windows 2008R2 bare metal backup running. It does very little else than maintain a bullet proof copy of the forest.
    Everything else is virtualised.

  12. #12
    ricki's Avatar
    Join Date
    Jul 2005
    Location
    uk
    Posts
    1,466
    Thank Post
    20
    Thanked 164 Times in 157 Posts
    Rep Power
    51
    HI

    If a windows 2008 domain controller that has not spoken to the other domain controller for a bit it will refuse to replicate.

    Now you need to do some reading before doing any of this and make sure you know what the consequences are.

    Event ID 2042: It has been too long since this machine replicated: Active Directory

    Richard

  13. #13

    sparkeh's Avatar
    Join Date
    May 2007
    Posts
    6,259
    Thank Post
    1,138
    Thanked 1,463 Times in 980 Posts
    Blog Entries
    22
    Rep Power
    457
    @ricki from the info given by the OP its does not look like he is in that position, there is no mention of that error and the AD is different by three weeks which is much shorted than the tombstone period.

  14. #14
    HallX's Avatar
    Join Date
    Mar 2007
    Location
    Doncaster
    Posts
    230
    Thank Post
    20
    Thanked 26 Times in 21 Posts
    Rep Power
    20
    Quote Originally Posted by m25man View Post
    Does this not underpin the argument about maintaining a dedicated hardware server for the sole purpose of maintaining the AD?
    I was on a 2008 server course 3 weeks ago, instructor told us in no uncertain terms, NEVER virtualize a live DC, always use a dedicated hardware server. This is MS advise.

  15. #15

    sparkeh's Avatar
    Join Date
    May 2007
    Posts
    6,259
    Thank Post
    1,138
    Thanked 1,463 Times in 980 Posts
    Blog Entries
    22
    Rep Power
    457
    Quote Originally Posted by HallX View Post
    I was on a 2008 server course 3 weeks ago, instructor told us in no uncertain terms, NEVER virtualize a live DC, always use a dedicated hardware server. This is MS advise.
    Can you clarify this? Are you saying you were told never to virtualise a DC?

SHARE:
+ Post New Thread
Page 1 of 3 123 LastLast

Similar Threads

  1. Adding a server to domain and replication
    By marsdenprimary in forum Windows Server 2000/2003
    Replies: 8
    Last Post: 24th July 2011, 09:26 PM
  2. AD replication
    By theeldergeek in forum Windows Server 2008 R2
    Replies: 11
    Last Post: 10th December 2010, 10:43 AM
  3. AD Replication Error
    By kerrymoralee9280 in forum Wireless Networks
    Replies: 3
    Last Post: 12th July 2007, 09:39 AM
  4. Adding shortcuts to Sims.net
    By eejit in forum Windows
    Replies: 26
    Last Post: 22nd June 2005, 03:35 PM
  5. Adding you links to the downloads section.
    By edugeekadmin in forum Downloads
    Replies: 0
    Last Post: 14th June 2005, 07:44 AM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •