AD Replication Errors

G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

Help!!!

I am the following AD replication errors occuring on a weekly basis:

All servers in site
CN=Sheffield,CN=Sites,CN=Configuration,DC=centre,DC=co,DC=ph that can
replicate partition CN=Configuration,DC=centre,DC=co,DC=ph over transport
CN=SMTP,CN=Inter-Site
Transports,CN=Sites,CN=Configuration,DC=centre,DC=co,DC=ph are currently
unavailable.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

and:

The Directory Service consistency checker has determined that either (a)
there is not enough physical connectivity published via the Active Directory
Sites and Services Manager to create a spanning tree connecting all the sites
containing the Partition CN=Configuration,DC=centre,DC=co,DC=ph, or (b)
replication cannot be performed with one or more critical servers in order
for changes to propagate across all sites (most often due to the servers
being unreachable).

For (a), please use the Active Directory Sites and Services Manager to do
one of the following:
1. Publish sufficient site connectivity information such that the system can
infer a route by which this Partition can reach this site. This option is
preferred.
2. Add an ntdsConnection object to a Domain Controller that contains the
Partition CN=Configuration,DC=centre,DC=co,DC=ph in this site from a Domain
Controller that contains the same Partition in another site.

For (b), please see previous events logged by the NTDS KCC source that
identify the servers that could not be contacted.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

When I reboot the DC in the site sheffield all works again for approx 1 week
then it fails again.

Any helpwould be much appreciated.

Richard
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

Install the support tools and run replmon.exe (replication monitor).

This will enable you to see if all is well or not. You need to fix any
replication problems.

However, this looks a little familiar...are you using a somewhat strict
[DNS] scavenging routine by any chance?

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

Hi Paul,

Below is one of the failure messages that I recieve in replmon.exe:

"DateTime","16/05/2005 09:42:51"
"PartnerType",">> Direct Replication Partner Data <<"
"DirectPartnerUSN","Property Update USN: 532702"
"DirectPartnerFailure","Changes have not been successfully replicated from
PH-SHEF-1 for 21 attempt(s)."
"DirectPartnerFailure","The reason is: The remote procedure call failed."
"DirectPartnerFailure","The last replication attempt was: 5/16/2005 9:14:25
AM (local)"
"DateTime","16/05/2005 10:34:13"
"USNData","532704"

If I reboot the server PH-SHEF-1 then replication begins again.

Also we don't have DNS Scavenging turned on.

Many thanks

Richard

"ptwilliams" wrote:

> Install the support tools and run replmon.exe (replication monitor).
>
> This will enable you to see if all is well or not. You need to fix any
> replication problems.
>
> However, this looks a little familiar...are you using a somewhat strict
> [DNS] scavenging routine by any chance?
>
> --
> Paul Williams
> Microsoft MVP - Windows Server - Directory Services
> http://www.msresource.net | http://forums.msresource.net
>
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

Just had a quick look at the replication topology and it looks a bit funny to
me.

We have 4 AD servers in 3 sites, servers 1 & 2 are in site a, server 3 is in
site b and server 4 is in site c. Server 1 is a replication partner to server
2, 3 and 4. Server 2 is a replication partner to server 1. Both server 3 & 4
are replication partners to server 1. These are all automaically created
connections. Does this seen right?

Plus, whenever these problems occur they are followed by failures in the
exchange smtp connectors that i have running between my exchange routing
groups, is the replication issues preventing smtp authentication or is it
coincidence (personaly i don't believe in coincidences)

Also, after looking through messages posted here I have run both dnslint and
a dcdiag reports and there are no errors reported.


"ptwilliams" wrote:

> Install the support tools and run replmon.exe (replication monitor).
>
> This will enable you to see if all is well or not. You need to fix any
> replication problems.
>
> However, this looks a little familiar...are you using a somewhat strict
> [DNS] scavenging routine by any chance?
>
> --
> Paul Williams
> Microsoft MVP - Windows Server - Directory Services
> http://www.msresource.net | http://forums.msresource.net
>
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

Sorry for the delay, I've been on the road with no Internet access!!!


> We have 4 AD servers in 3 sites, servers 1 & 2 are in site a, server 3 is
> in site b and server 4 is in site c. Server 1 is a replication partner to
> server 2, 3 and 4. Server 2 is a replication partner to server 1. Both
> server 3 & 4 are replication partners to server 1. These are all
> automaically created connections. Does this seen right?

Yes, server 1 is the bridgehead server. That 'looks' fine.


> Plus, whenever these problems occur they are followed by failures in the
> exchange smtp connectors that i have running between my exchange routing
> groups, is the replication issues preventing smtp authentication or is it
> coincidence (personaly i don't believe in coincidences)

Sounds like whatever is affecting your replication is also affecting your
exchange. We need to find out what is causing the loss of service...


> Also, after looking through messages posted here I have run both dnslint
> and a dcdiag reports and there are no errors reported.

This is a good sign. Perhaps the problem is network connectivty? Does this
happen around the same time? Or is the server leaking memory and processes
are dying after a certain amount of time?

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.active_directory (More info?)

Paul,

Yes, the problems do occur at the same time, normally the AD errors start
then after approx 12 - 24 hours the exchange problems occur.

Richard

"Paul Williams [MVP]" wrote:

> Sorry for the delay, I've been on the road with no Internet access!!!
>
>
> > We have 4 AD servers in 3 sites, servers 1 & 2 are in site a, server 3 is
> > in site b and server 4 is in site c. Server 1 is a replication partner to
> > server 2, 3 and 4. Server 2 is a replication partner to server 1. Both
> > server 3 & 4 are replication partners to server 1. These are all
> > automaically created connections. Does this seen right?
>
> Yes, server 1 is the bridgehead server. That 'looks' fine.
>
>
> > Plus, whenever these problems occur they are followed by failures in the
> > exchange smtp connectors that i have running between my exchange routing
> > groups, is the replication issues preventing smtp authentication or is it
> > coincidence (personaly i don't believe in coincidences)
>
> Sounds like whatever is affecting your replication is also affecting your
> exchange. We need to find out what is causing the loss of service...
>
>
> > Also, after looking through messages posted here I have run both dnslint
> > and a dcdiag reports and there are no errors reported.
>
> This is a good sign. Perhaps the problem is network connectivty? Does this
> happen around the same time? Or is the server leaking memory and processes
> are dying after a certain amount of time?
>
> --
> Paul Williams
> Microsoft MVP - Windows Server - Directory Services
> http://www.msresource.net | http://forums.msresource.net
>
>
>