Jump to content

Recommended Posts

Posted

Ive just looked in the directory service...

NTDS Replication, NTDS, KCC, NTDS General, NTDS ISAM... there seems to be a load of errors with those sources.

On security we are getting a lot of anonymous logons

Posted
NTDS Replication, NTDS, KCC, NTDS General, NTDS ISAM... there seems to be a load of errors with those sources.

 

What errors? These will all likely be a result of replication faliures.

 

On security we are getting a lot of anonymous logons

 

Anonymous logins wont work with W2k3 server. Whatever's trying to use them is misconfigured/broken. You should have an IP/Hostname listed in each distinct logon/logoff event. You can track down the device/user that way.

Posted

NTDS Replication:

This is the replication status for the following directory partition on the local domain controller.

 

Directory partition:

CN=Schema,CN=Configuration,DC=shs,DC=com

 

The local domain controller has not recently received replication information from a number of domain controllers. The count of domain controllers is shown, divided into the following intervals.

 

More than 24 hours:

1

More than a week:

1

More than one month:

1

More than two months:

1

More than a tombstone lifetime:

1

Tombstone lifetime (days):

60

Domain controllers that do not replicate in a timely manner may encounter errors. It may miss password changes and be unable to authenticate. A DC that has not replicated in a tombstone lifetime may have missed the deletion of some objects, and may be automatically blocked from future replication until it is reconciled.

 

To identify the domain controllers by name, install the support tools included on the installation CD and run dcdiag.exe.

You can also use the support tool repadmin.exe to display the replication latencies of the domain controllers in the forest. The command is "repadmin /showvector /latency ".

 

NTDS KCC

The attempt to establish a replication link for the following writable directory partition failed.

 

Directory partition:

CN=Configuration,DC=shs,DC=com

Source domain controller:

CN=NTDS Settings,CN=ZEUS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=shs,DC=com

Source domain controller address:

552f59d1-eee5-423a-8143-76bb77105d74._msdcs.shs.com

Intersite transport (if any):

 

 

This domain controller will be unable to replicate with the source domain controller until this problem is corrected.

 

User Action

Verify if the source domain controller is accessible or network connectivity is available.

 

Additional Data

Error value:

8524 The DSA operation is unable to proceed because of a DNS lookup failure.

 

NTDS General

Duplicate event log entries were suppressed.

 

See the previous event log entry for details. An entry is considered a duplicate if the event code and all of its insertion parameters are identical. The time period for this run of duplicates is from the time of the previous event to the time of this event.

 

Event Code:

80000785

Number of duplicate entries:

15

 

 

And just keep getting teh SceCli source error on the machine with the main policies on

Posted

If you log onto a DC launch active directory sites and services and drill down into the ntds settings for your DC's you can then right click and click on replicate now.

 

What result does that give you?

 

Ben

Posted
Ben... ive just been on that, and found that the guy before me who was lookin after the servers hadnt cleaned that up.. Also i found that some servers werent talking to others and that the machine (hades) with the replication problem was only talking to one of the 3 DCs, so ive tidied it up and made sure that all the dcs are talking to each other.. hope that is right anyway
Posted

Just an update on this topic... ive sorted out the things with dns.. the dns server was not talking to the main policy machine.

Now getting back to the title of this topic... the frs is not syncing with the other DCs and im just running sonar on the policy machine and it is telling me that the datacollectionstate on 2 of the 4 dcs has failed hence the policy not been updated to the other servers.

Anyone know how to get round this problem

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...