Na een succesvolle installatie en opname in het domein is het ineens niet meer mogelijk om te repliceren in mijn opgezette domein.
Ik heb het volgende: 2 DC's met beiden windows server 2003 enterprise, die eerst op 2 verschillende sites zaten maar nu om maar het probleem van replicatie te tackelen, heb ik ze beiden in site 1 staan. ip adressen zijn 192.168.2.2 em 192.168.2.22, DNS werkt goed, ze weten elkaar te vinden met ping, ook op FQDN adressen. Eusterie01 is DC waarna ik een 2e, primaire DC Eusterie02 heb opgezet, dit zijn dus de namen.
De laatste replicatie is meer dan 24 uur geleden geweest en in een van de error messages staat het volgende:
Hierna heb ik dcdiag gedraaid en dat gaf het volgende:
Het is een opdracht van mijn opleiding waar ik hopeloos in vast zit, vandaag bij mijn docent langs geweest maar ook hij heeft het nog niet kunnen oplossen. Vandaar dat ik het ook niet in professionele networking vraag maar hier.
Ik heb het volgende: 2 DC's met beiden windows server 2003 enterprise, die eerst op 2 verschillende sites zaten maar nu om maar het probleem van replicatie te tackelen, heb ik ze beiden in site 1 staan. ip adressen zijn 192.168.2.2 em 192.168.2.22, DNS werkt goed, ze weten elkaar te vinden met ping, ook op FQDN adressen. Eusterie01 is DC waarna ik een 2e, primaire DC Eusterie02 heb opgezet, dit zijn dus de namen.
De laatste replicatie is meer dan 24 uur geleden geweest en in een van de error messages staat het volgende:
Dit doet me denken dat er een van de domein controllers is weggevallen.Event Type: Error
Event Source: NTDS Replication
Event Category: Replication
Event ID: 1863
Date: 16-12-2008
Time: 20:30:07
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: EUSTERIE01
Description:
This is the replication status for the following directory partition on the local domain controller.
Directory partition:
DC=eusterie,DC=eu
The local domain controller has not received replication information from a number of domain controllers within the configured latency interval.
Latency Interval (Hours):
24
Number of domain controllers in all sites:
1
Number of domain controllers in this site:
1
The latency interval can be modified with the following registry key.
Registry Key:
HKLM\System\CurrentControlSet\Services\NTDS\Parameters\Replicator latency error interval (hours)
To identify the domain controllers by name, install the support tools included on the installation CD and run dcdiag.exe.
You can also use the support tool repadmin.exe to display the replication latencies of the domain controllers in the forest. The command is "repadmin /showvector /latency <partition-dn>".
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Hierna heb ik dcdiag gedraaid en dat gaf het volgende:
Daarnaast heb ik ook deze foutmelding in mijn event list staan met enige regelmaat ...:Testing server: site1\EUSTERIE02
Starting test: Replications
[Replications Check,EUSTERIE02] A recent replication attempt failed:
From EUSTERIE01 to EUSTERIE02
Naming Context: DC=DomainDnsZones,DC=eusterie,DC=eu
The replication generated an error (1908):
Could not find the domain controller for this domain.
The failure occurred at 2008-12-16 19:08:52.
The last success occurred at 2009-12-12 15:33:20.
40 failures have occurred since the last success.
Kerberos Error.
A KDC was not found to authenticate the call.
Check that sufficient domain controllers are available.
[EUSTERIE01] DsBindWithSpnEx() failed with error -2146893022,
The target principal name is incorrect..
[Replications Check,EUSTERIE02] A recent replication attempt failed:
From EUSTERIE01 to EUSTERIE02
Naming Context: DC=ForestDnsZones,DC=eusterie,DC=eu
The replication generated an error (1908):
Could not find the domain controller for this domain.
The failure occurred at 2008-12-16 19:08:28.
The last success occurred at 2009-12-12 15:30:45.
40 failures have occurred since the last success.
Kerberos Error.
A KDC was not found to authenticate the call.
Check that sufficient domain controllers are available.
[Replications Check,EUSTERIE02] A recent replication attempt failed:
From EUSTERIE01 to EUSTERIE02
Naming Context: CN=Schema,CN=Configuration,DC=eusterie,DC=eu
The replication generated an error (1908):
Could not find the domain controller for this domain.
The failure occurred at 2008-12-16 19:06:28.
The last success occurred at 2009-12-12 15:30:46.
40 failures have occurred since the last success.
Kerberos Error.
A KDC was not found to authenticate the call.
Check that sufficient domain controllers are available.
[Replications Check,EUSTERIE02] A recent replication attempt failed:
From EUSTERIE01 to EUSTERIE02
Naming Context: CN=Configuration,DC=eusterie,DC=eu
The replication generated an error (1908):
Could not find the domain controller for this domain.
The failure occurred at 2008-12-16 19:05:28.
The last success occurred at 2009-12-12 15:34:04.
40 failures have occurred since the last success.
Kerberos Error.
A KDC was not found to authenticate the call.
Check that sufficient domain controllers are available.
[Replications Check,EUSTERIE02] A recent replication attempt failed:
From EUSTERIE01 to EUSTERIE02
Naming Context: DC=eusterie,DC=eu
The replication generated an error (1908):
Could not find the domain controller for this domain.
The failure occurred at 2008-12-16 19:07:28.
The last success occurred at 2009-12-12 15:34:48.
41 failures have occurred since the last success.
Kerberos Error.
A KDC was not found to authenticate the call.
Check that sufficient domain controllers are available.
......................... EUSTERIE02 passed test Replications
Starting test: NCSecDesc
......................... EUSTERIE02 passed test NCSecDesc
Starting test: NetLogons
......................... EUSTERIE02 passed test NetLogons
Starting test: Advertising
Warning: EUSTERIE02 is not advertising as a time server.
......................... EUSTERIE02 failed test Advertising
Starting test: KnowsOfRoleHolders
Warning: EUSTERIE01 is the Schema Owner, but is not responding to DS RP
Bind.
En de volgende over replicatie:Event Type: Error
Event Source: Kerberos
Event Category: None
Event ID: 4
Date: 16-12-2008
Time: 20:51:14
User: N/A
Computer: EUSTERIE01
Description:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/eusterie02.eusterie.eu. The target name used was LDAP/2316bdfc-3973-41c6-99ec-30cbe239d610._msdcs.eusterie.eu. This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named machine accounts in the target realm (EUSTERIE.EU), and the client realm. Please contact your system administrator.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Hier werkt 1 en 2 wel, en de topologie lijkt ook in orde, weet iemand hoe ik de topology kan checken?Event Type: Warning
Event Source: NtFrs
Event Category: None
Event ID: 13508
Date: 16-12-2008
Time: 19:41:00
User: N/A
Computer: EUSTERIE01
Description:
The File Replication Service is having trouble enabling replication from EUSTERIE02 to EUSTERIE01 for c:\windows\sysvol\domain using the DNS name Eusterie02.eusterie.eu. FRS will keep retrying.
Following are some of the reasons you would see this warning.
[1] FRS can not correctly resolve the DNS name Eusterie02.eusterie.eu from this computer.
[2] FRS is not running on Eusterie02.eusterie.eu.
[3] The topology information in the Active Directory for this replica has not yet replicated to all the Domain Controllers.
This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 21 07 00 00 !...
Het is een opdracht van mijn opleiding waar ik hopeloos in vast zit, vandaag bij mijn docent langs geweest maar ook hij heeft het nog niet kunnen oplossen. Vandaar dat ik het ook niet in professionele networking vraag maar hier.