Jump to content

Recommended Posts

Posted

Hello forum,

 

So after a minor disaster last week and finally restoring my to DCs I now have a replication problem. The servers in question sit in different towns connected through a VPN. Both of these I had to do a System State recover to get back online. Of course now I discover I cannot really do anything new on the head server (create accounts, connect new machines to the domain, etc(error: windows cannot create the object because the directory service was unable to allocate a relative identifier)), and additionally it is no longer replicating AD or files as it was prior to the restore point.

 

My research tells me that this is common from a system state restore and it basically kills the RID? Articles I have found reference Server 2000 and 2003 (including this thread: http://www.edugeek.net/forums/windows/10186-cannot-create-users-active-directory.html), I presume the resolutions are much the same. However everything does seem to indicate that the DC is effectively useless as a DC now and that roles should be seized by another and then this one replaced/rebuilt.

 

The question to the floor, is there anyway I can get this DC replicating again, be it with or without the FSMO roles?

 

Is this worth a go: https://support.microsoft.com/en-us/help/839879/event-id-16650-the-account-identifier-allocator-failed-to-initialize-i

 

One thought I have had is to create a new DC as a VM on the effected server as I need a DC on this site, seize the roles with the physical server at the other location and then demote the crippled DC. My concern is that I need files to replicate again.

 

I am currently apprehensive to try anything without a little feedback from yourselves as I'd rather not be put into a position of having to do yet another system state recovery.

 

Many thanks in advance.

Posted

Ther servers are on seperate VLANS, but I presume that isn't a concern. I'm not sure you want the full 40 - 50 pages so I've cut it down, but it's very much a repeat of Error 1722 with difference ID's:

 

PS C:\Users\Administrator> dcdiag /v

 

Directory Server Diagnosis

 

Performing initial setup:

Trying to find home server...

* Verifying that the local machine SERVER-01, is a Directory Server.

Home Server = SERVER-01

* Connecting to directory service on server SERVER-01.

* Identified AD Forest.

Collecting AD specific global data

* Collecting site info.

Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=domain,DC=local,LDAP_SCOPE_SUBTREE,(objectCategory=

ntDSSiteSettings),.......

The previous call succeeded

Iterating through the sites

Looking at base site object: CN=NTDS Site Settings,CN=Longborough,CN=Sites,CN=Configuration,DC=domain,DC=local

Getting ISTG and options for the site

Looking at base site object: CN=NTDS Site Settings,CN=Swell,CN=Sites,CN=Configuration,DC=domain,DC=local

Getting ISTG and options for the site

* Identifying all servers.

Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=domain,DC=local,LDAP_SCOPE_SUBTREE,(objectClass=ntD

SDsa),.......

The previous call succeeded....

The previous call succeeded

Iterating through the list of servers

Getting information for the server CN=NTDS Settings,CN=SERVER-01,CN=Servers,CN=Longborough,CN=Sites,CN=Configuration,

DC=domain,DC=local

objectGuid obtained

InvocationID obtained

dnsHostname obtained

site info obtained

All the info for the server collected

Getting information for the server CN=NTDS Settings,CN=SERVER-02,CN=Servers,CN=Swell,CN=Sites,CN=Configuration,DC=lsp

rimary,DC=local

objectGuid obtained

InvocationID obtained

dnsHostname obtained

site info obtained

All the info for the server collected

* Identifying all NC cross-refs.

* Found 2 DC(s). Testing 1 of them.

Done gathering initial info.

 

Doing initial required tests

 

Testing server: Longborough\SERVER-01

Starting test: Connectivity

* Active Directory LDAP Services Check

Determining IP4 connectivity

* Active Directory RPC Services Check

......................... SERVER-01 passed test Connectivity

 

Doing primary tests

 

Testing server: Longborough\SERVER-01

Starting test: Advertising

The DC SERVER-01 is advertising itself as a DC and having a DS.

The DC SERVER-01 is advertising as an LDAP server

The DC SERVER-01 is advertising as having a writeable directory

The DC SERVER-01 is advertising as a Key Distribution Center

The DC SERVER-01 is advertising as a time server

The DS SERVER-01 is advertising as a GC.

......................... SERVER-01 passed test Advertising

Test omitted by user request: CheckSecurityError

Test omitted by user request: CutoffServers

Starting test: FrsEvent

* The File Replication Service Event log test

Skip the test because the server is running DFSR.

......................... SERVER-01 passed test FrsEvent

Starting test: DFSREvent

The DFS Replication Event Log.

There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL

replication problems may cause Group Policy problems.

An error event occurred. EventID: 0xC0001390

Time Generated: 02/19/2018 15:17:55

Event String:

The DFS Replication service failed to communicate with partner SERVER-02 for replication group domain.loc

al\domain\resources. This error can occur if the host is unreachable, or if the DFS Replication service is not runnin

g on the server.

 

Partner DNS Address: SERVER-02.domain.local

 

Optional data if available:

Partner WINS Address: SERVER-02

Partner IP Address: 10.*.*.1

 

The service will retry the connection periodically.

 

Additional Information:

Error: 1722 (The RPC server is unavailable.)

Connection ID: DE15BE87-21A8-42A7-AA8E-238DAAE3F750

Replication Group ID: 228A018C-F886-4906-8C87-C88A70B280B5

An error event occurred. EventID: 0xC0001390

Time Generated: 02/19/2018 15:17:56

Event String:

The DFS Replication service failed to communicate with partner SERVER-02 for replication group Domain System

Volume. This error can occur if the host is unreachable, or if the DFS Replication service is not running on the server

.

 

Partner DNS Address: SERVER-02.domain.local

 

Optional data if available:

Partner WINS Address: SERVER-02

Partner IP Address: 10.*.*.1

 

The service will retry the connection periodically.

 

Additional Information:

Error: 1722 (The RPC server is unavailable.)

Connection ID: BE81E0A6-FDCB-4702-B429-250B63864465

Replication Group ID: 40559CDE-E388-4514-BF49-C0A287B33135

An error event occurred. EventID: 0xC0001390

Time Generated: 02/19/2018 15:18:36

Event String:

The DFS Replication service failed to communicate with partner SERVER-02 for replication group domain.loc

al\domain\drive_g. This error can occur if the host is unreachable, or if the DFS Replication service is not running

on the server.

 

Partner DNS Address: SERVER-02.domain.local

 

Optional data if available:

Partner WINS Address: SERVER-02

Partner IP Address: 10.*.*.1

 

The service will retry the connection periodically.

 

Additional Information:

Error: 1722 (The RPC server is unavailable.)

Connection ID: 32A71FB1-0E2F-4DCC-90E5-C3F0136EAD1B

Replication Group ID: E53241D2-3011-4D21-A318-F51F2183F3B0

An error event occurred. EventID: 0xC0001390

Time Generated: 02/19/2018 15:19:15

Event String:

The DFS Replication service failed to communicate with partner SERVER-02 for replication group domain.loc

al\domain\teachers. This error can occur if the host is unreachable, or if the DFS Replication service is not running

on the server.

 

Partner DNS Address: SERVER-02.domain.local

 

Optional data if available:

Partner WINS Address: SERVER-02

Partner IP Address: 10.*.*.1

 

The service will retry the connection periodically.

 

Additional Information:

Error: 1722 (The RPC server is unavailable.)

Connection ID: 4A6BD96C-FE07-497D-A0E3-E2F6179FD683

Replication Group ID: C7D3A332-4D2D-47A6-AEB9-C8AEB39C3DC8

An error event occurred. EventID: 0xC0001390

Time Generated: 02/19/2018 15:20:42

Event String:

The DFS Replication service failed to communicate with partner SERVER-02 for replication group domain.loc

al\domain\sophosupdate. This error can occur if the host is unreachable, or if the DFS Replication service is not run

ning on the server.

 

Partner DNS Address: SERVER-02.domain.local

 

Optional data if available:

Partner WINS Address: SERVER-02

Partner IP Address: 10.*.*.1

 

The service will retry the connection periodically.

 

Additional Information:

Error: 1722 (The RPC server is unavailable.)

Connection ID: 4D797635-6AC9-468E-B66C-017CACCC30C3

Replication Group ID: 22FB5FFE-55A8-4BDF-9A26-289B109AE21F

An error event occurred. EventID: 0xC0001390

Time Generated: 02/19/2018 15:23:38

Event String:

The DFS Replication service failed to communicate with partner SERVER-02 for replication group domain.loc

al\domain\users. This error can occur if the host is unreachable, or if the DFS Replication service is not running on

the server.

 

Partner DNS Address: SERVER-02.domain.local

 

Optional data if available:

Partner WINS Address: SERVER-02

Partner IP Address: 10.*.*.1

 

The service will retry the connection periodically.

Posted

Is RPC service running on both servers?

System state recovery is not ideal for DCs, anyway to do a baremetal restore from a recent backup?

Can the servers talk to each other?

Posted

I wasn't able to do a bare metal because I couldn't get the tape to detect in system restore. I think this is because of the third party software someone setup on the server. And with the pressure to get them back in situe for yesterday, I resorted to what would work to get them online for use. Of course the replication was an unforseen result.

 

RPC Enpoint Mapper? This is running.

Posted (edited)

Remote Procedure Call (RPC) should be running on both servers.

Confirm that it's running on both, start it if its not.

Does server01 have roles, is it a GC?

 

What about server02?

Edited by roc1479
Posted

In that case, I would setup the VM setup as a temp solution to server 01.

You would have to promote it, seize the roles, make it a gc and setup any necessary services (dhcp, dnc).

Make sure the VM is replicating and all is well with clients.

 

Demote server 01 and remove it completely from the domain and also remove any active directory services from it.

Remove any traces of server01 from AD, Sites and services etc..

From there, you can either rebuild server01 from scratch, which i would do, or promote it again and pretty do the above to reclaim roles and services.

Posted

The server is currently a physical, and after last weeks faff, if I have to have a new DC, it will be a VM! But will have to be on the physical that is currently the broken DC.

 

In summary what I have read is pretty much what I'm left with. The DC is dead. Long live the new DC?

Posted

Yes its a shame you couldn't get it to read the tapes.

 

I don't like it myself when problems like this happens, but the reality is that they do from time to time.

 

The VM route is the way to go, you should be fine.

Posted

Get-ADForest | select ForestMode,SchemaMaster | FL

Get-ADDomain | select DomainMode,InfrastructureMaster,PDCEmulator,RIDMaster | FL

 

Get-ADObject (Get-ADRootDSE).schemaNamingContext -Property objectVersion

 

from one of the DC's if possible.

Posted (edited)
Just a side note before trying to stand up a new DC, As you have no RID at the min you are going to find it hard to add a DC and all the relevant AD information due to not having a RID. The first thing you are going to need is a RID for the new computer account in AD..... you get the picture. Edited by HPlum78
Posted
From what I gather I can user Server 2 to seize the roles from Server 1...? Then adding the new DC to that network. I don't mind who has the FSMO, as long as they replicate. I don't want to seize and break both servers though.
Posted
The issue here is the DC's will know that they have issued RID's beyond what they now know about due to being restored. Need to kill the RID pool and then start it beyond the point of the last known issued RID.....
Posted (edited)
I confess you're losing me a little there with the last one. So I can't just seize with server 2? Edited by Trenton_Lister
Posted

Its not as simple as just transferring the RID FSMO role now, when you restore AD you have some options around if its an Authoritative restore or a none Authoritative restore. The issue with using a system state restore is you do not get the option of specifying what type of restore you are doing. The second DC (server 2) is now irrelevant (if I am reading what you have done right) as you cannot restore 2 DC's from any backup like this. So back to the issue in hand your RID and this will be one of a few issues that are going to be needing fixing (so strap yourself in here) the DC that holds the RID FSMO role gets blocks of RID's assigned to it at various points in its life. What you have done by restoring the DC the way you have had to is thrown this out of sync, when a DC attempts to start Active Directory one of the checks is around the RID allocation and what will be happening at the min is that the pool will be conflicting with what is the last known RID allocated to an AD object and the RID's that the DC is allocating itself from what it thinks is a valid range of RID's for your Domain.

 

This is a simplistic overview of how this works - I am not about to drill into the depths of how a DC ends up being a valid domain controller in the limited space I have here.... :-P

Posted
That part makes sense now, and yes I'm pretty sure that's what I've done. But is there a good way to go about fixing the damage without either rebuilding the DCs and network? Can I seize with server 2 and put a new server 1 in place? This last option was the implication I got from roc1479?
Posted
riDPreviousAllocationPool need to do something with this attrib in the schema from memory, you guys could look into that. Also could do with digging out the Powershell to find the highest RID allocated to an AD object. I will pick this back up when I get home unless you guys fix in the meantime.
Posted (edited)
The issue is here (and I am not sat in front of your domain) is that you will not have replication between the two DC's and by seizing the role you are essentially writing off the server you seize the role from. What happens when forcibly seizing a FSMO role I think varies based on underlying OS and functional levels. I think that in your current state even trying to seize the role will do one of two things 1. Fail out right as the underlying moving parts of Active Directory are just not in a state that will allow this to happen 2. Corrupt the AD dit / underlying files. Edited by HPlum78
Posted (edited)
What also happens is that the RID attrb will be updated but this will just be based on the next available RID pool increment and this could still be in the range of the highest RID already in use in your domain. Edited by HPlum78

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...