Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
Hallo allemaal,

Ik zit met het volgende issue.
De PDC02 is niet reachable volgens de ADAccess, in het logboek van onze HUBCAS servers.
Hoop het gelijk te trekken met de PDC01, maar krijg het niet voor elkaar.

Er word gedraait op een Exchange 2010 omgeving van 2 DC's, 2 DB's en 2 HUB/CAS servers.

Event ID 2080 Information
Process MSEXCHANGEADTOPOLOGYSERVICE.EXE (PID=1300). Exchange Active Directory Provider has discovered the following servers with the following characteristics:
(Server name | Roles | Enabled | Reachability | Synchronized | GC capable | PDC | SACL right | Critical Data | Netlogon | OS Version)
In-site:
PDC02.**.local CDG 1 0 0 1 0 0 0 0 0
PDC01.**.local CDG 1 7 7 1 0 1 1 7 1
Out-of-site:


Heb het internet aardig afgespeurt, maar ik kom er niet uit.
Zijn mensen met soortgelijke issues, maar de oplossing staat er vaak niet bij.
Kan overigens ook zijn dat ik niet goed zoek, maar dat ter zijde.

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • Question Mark
  • Registratie: Mei 2003
  • Laatst online: 09-07 16:17

Question Mark

Moderator SSC/WOS

F7 - Nee - Ja

Begin met het troubleshooten van je AD. Volgens bovenstaande error is binnen je AD niet eens een PDC actief (PDC emulator role). Het lijkt me dat je op AD-gebied wel wat issue's hebt.

Draai als eerste stap DCDiag eens op je beide DC's en post de output hier eens?

[ Voor 15% gewijzigd door Question Mark op 09-01-2015 14:05 ]

MCSE NT4/2K/2K3, MCTS, MCITP, CCA, CCEA, CCEE, CCIA, CCNA, CCDA, CCNP, CCDP, VCP, CEH + zwemdiploma A & B


Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
Question Mark schreef op vrijdag 09 januari 2015 @ 14:04:
Begin met het troubleshooten van je AD. Volgens bovenstaande error is binnen je AD niet eens een PDC actief (PDC emulator role). Het lijkt me dat je op AD-gebied wel wat issue's hebt.

Draai als eerste stap DCDiag eens op je beide DC's en post de output hier eens?
Heeft dit enige impact op de draaiende omgeving? Anders doe ik het vanavond even namelijk.
Dan zal ik even een dcdiag /v draaien, zodat alles meekomt.

Bedankt tot zover

[ Voor 50% gewijzigd door JustinoFTW op 09-01-2015 15:30 ]

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • Question Mark
  • Registratie: Mei 2003
  • Laatst online: 09-07 16:17

Question Mark

Moderator SSC/WOS

F7 - Nee - Ja

Neehoor, kun je gewoon op elk moment draaien.

MCSE NT4/2K/2K3, MCTS, MCITP, CCA, CCEA, CCEE, CCIA, CCNA, CCDA, CCNP, CCDP, VCP, CEH + zwemdiploma A & B


Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
Question Mark schreef op vrijdag 09 januari 2015 @ 15:17:
Neehoor, kun je gewoon op elk moment draaien.
Bij deze van de PDC02:


Directory Server Diagnosis
Performing initial setup: Trying to find home server... * Verifying that the local machine PDC02, is a Directory Server.
Home Server = PDC02 * Connecting to directory service on server PDC02. * Identified AD Forest.
Collecting AD specific global data
* Collecting site info. Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=****,DC=local,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
The previous call succeeded
Iterating through the sites
Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
Getting ISTG and options for the site
* Identifying all servers. Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=****,DC=local,LDAP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
The previous call succeeded....
The previous call succeeded
Iterating through the list of servers
Getting information for the server CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
objectGuid obtained
InvocationID obtained
dnsHostname obtained
site info obtained
All the info for the server collected
Getting information for the server CN=NTDS Settings,CN=PDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
objectGuid obtained
InvocationID obtained
dnsHostname obtained
site info obtained
All the info for the server collected
* Identifying all NC cross-refs. * Found 2 DC(s). Testing 1 of them. Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\PDC02 Starting test: Connectivity * Active Directory LDAP Services Check
Determining IP4 connectivity
* Active Directory RPC Services Check
......................... PDC02 passed test Connectivity Doing primary tests
Testing server: Default-First-Site-Name\PDC02 Starting test: Advertising The DC PDC02 is advertising itself as a DC and having a DS.
The DC PDC02 is advertising as an LDAP server
The DC PDC02 is advertising as having a writeable directory
The DC PDC02 is advertising as a Key Distribution Center
The DC PDC02 is advertising as a time server
The DS PDC02 is advertising as a GC.
......................... PDC02 passed test Advertising Test omitted by user request: CheckSecurityError Test omitted by user request: CutoffServers Starting test: FrsEvent * The File Replication Service Event log test
Skip the test because the server is running DFSR. ......................... PDC02 passed test FrsEvent Starting test: DFSREvent The DFS Replication Event Log.
There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems.
A warning event occurred. EventID: 0x80001396 Time Generated: 01/09/2015 02:30:28 Event String: The DFS Replication service is stopping communication with partner PDC01 for replication group Domain System Volume due to an error. The service will retry the connection periodically. Additional Information: Error: 9036 (Paused for backup or restore) Connection ID: 4DBD5806-0F75-4FEB-9E4F-04F7565351D5 Replication Group ID: 956DC852-676D-4B9E-B182-859C8EC70696 ......................... PDC02 passed test DFSREvent Starting test: SysVolCheck * The File Replication Service SYSVOL ready test
File Replication Service's SYSVOL is ready
......................... PDC02 passed test SysVolCheck Starting test: KccEvent * The KCC Event log test
Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
......................... PDC02 passed test KccEvent Starting test: KnowsOfRoleHolders Role Schema Owner = CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
Role Domain Owner = CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
Role PDC Owner = CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
Role Rid Owner = CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
Role Infrastructure Update Owner = CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
......................... PDC02 passed test KnowsOfRoleHolders Starting test: MachineAccount Checking machine account for DC PDC02 on DC PDC02.
* SPN found :LDAP/PDC02.****.local/****.local
* SPN found :LDAP/PDC02.****.local
* SPN found :LDAP/PDC02
* SPN found :LDAP/PDC02.****.local/****
* SPN found :LDAP/001cc040-db2e-4ede-9345-acdf85302b67._msdcs.****.local
* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/001cc040-db2e-4ede-9345-acdf85302b67/****.local
* SPN found :HOST/PDC02.****.local/****.local
* SPN found :HOST/PDC02.****.local
* SPN found :HOST/PDC02
* SPN found :HOST/PDC02.****.local/****
* SPN found :GC/PDC02.****.local/****.local
......................... PDC02 passed test MachineAccount Starting test: NCSecDesc * Security Permissions check for all NC's on DC PDC02.
* Security Permissions Check for DC=ForestDnsZones,DC=****,DC=local
(NDNC,Version 3)
* Security Permissions Check for DC=DomainDnsZones,DC=****,DC=local
(NDNC,Version 3)
* Security Permissions Check for CN=Schema,CN=Configuration,DC=****,DC=local
(Schema,Version 3)
* Security Permissions Check for CN=Configuration,DC=****,DC=local
(Configuration,Version 3)
* Security Permissions Check for DC=****,DC=local
(Domain,Version 3)
......................... PDC02 passed test NCSecDesc Starting test: NetLogons * Network Logons Privileges Check
Verified share \\PDC02\netlogon
Verified share \\PDC02\sysvol
......................... PDC02 passed test NetLogons Starting test: ObjectsReplicated PDC02 is in domain DC=****,DC=local
Checking for CN=PDC02,OU=Domain Controllers,DC=****,DC=local in domain DC=****,DC=local on 1 servers
Object is up-to-date on all servers.
Checking for CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local in domain CN=Configuration,DC=****,DC=local on 1 servers
Object is up-to-date on all servers.
......................... PDC02 passed test ObjectsReplicated Test omitted by user request: OutboundSecureChannels Starting test: Replications * Replications Check
* Replication Latency Check
DC=ForestDnsZones,DC=****,DC=local
Latency information for 1 entries in the vector were ignored.
1 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=DomainDnsZones,DC=****,DC=local
Latency information for 1 entries in the vector were ignored.
1 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Schema,CN=Configuration,DC=****,DC=local
Latency information for 1 entries in the vector were ignored.
1 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Configuration,DC=****,DC=local
Latency information for 1 entries in the vector were ignored.
1 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=****,DC=local
Latency information for 1 entries in the vector were ignored.
1 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
......................... PDC02 passed test Replications Starting test: RidManager * Available RID Pool for the Domain is 2600 to 1073741823
* PDC02.****.local is the RID Master
* DsBind with RID Master was successful
* rIDAllocationPool is 1600 to 2099
* rIDPreviousAllocationPool is 1600 to 2099
* rIDNextRID: 1616
......................... PDC02 passed test RidManager Starting test: Services * Checking Service: EventSystem
* Checking Service: RpcSs
* Checking Service: NTDS
* Checking Service: DnsCache
* Checking Service: DFSR
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: w32time
* Checking Service: NETLOGON
......................... PDC02 passed test Services Starting test: SystemLog * The System Event log test
Found no errors in "System" Event log in the last 60 minutes.
......................... PDC02 passed test SystemLog Test omitted by user request: Topology Test omitted by user request: VerifyEnterpriseReferences Starting test: VerifyReferences The system object reference (serverReference) CN=PDC02,OU=Domain Controllers,DC=****,DC=local and backlink on CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local are correct.
The system object reference (serverReferenceBL) CN=PDC02,CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=****,DC=local and backlink on CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local are correct.
The system object reference (msDFSR-ComputerReferenceBL) CN=PDC02,CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=****,DC=local and backlink on CN=PDC02,OU=Domain Controllers,DC=****,DC=local are correct.
......................... PDC02 passed test VerifyReferences Test omitted by user request: VerifyReplicas
Test omitted by user request: DNS Test omitted by user request: DNS
Running partition tests on : ForestDnsZones Starting test: CheckSDRefDom ......................... ForestDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... ForestDnsZones passed test CrossRefValidation
Running partition tests on : DomainDnsZones Starting test: CheckSDRefDom ......................... DomainDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... DomainDnsZones passed test CrossRefValidation
Running partition tests on : Schema Starting test: CheckSDRefDom ......................... Schema passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration Starting test: CheckSDRefDom ......................... Configuration passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Configuration passed test CrossRefValidation
Running partition tests on : **** Starting test: CheckSDRefDom ......................... **** passed test CheckSDRefDom Starting test: CrossRefValidation ......................... **** passed test CrossRefValidation
Running enterprise tests on : ****.local Test omitted by user request: DNS Test omitted by user request: DNS Starting test: LocatorCheck GC Name: \\PDC02.****.local Locator Flags: 0xe00031fd
PDC Name: \\PDC02.****.local
Locator Flags: 0xe00031fd
Time Server Name: \\PDC02.****.local
Locator Flags: 0xe00031fd
Preferred Time Server Name: \\PDC02.****.local
Locator Flags: 0xe00031fd
KDC Name: \\PDC02.****.local
Locator Flags: 0xe00031fd
......................... ****.local passed test LocatorCheck Starting test: Intersite Skipping site Default-First-Site-Name, this site is outside the scope provided by the command line arguments provided.
......................... ****.local passed test Intersite


Let niet op de ****

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
PDC01


Directory Server Diagnosis
Performing initial setup: Trying to find home server... * Verifying that the local machine PDC01, is a Directory Server.
Home Server = PDC01 * Connecting to directory service on server PDC01. * Identified AD Forest.
Collecting AD specific global data
* Collecting site info. Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=****,DC=local,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
The previous call succeeded
Iterating through the sites
Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
Getting ISTG and options for the site
* Identifying all servers. Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=****,DC=local,LDAP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
The previous call succeeded....
The previous call succeeded
Iterating through the list of servers
Getting information for the server CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
objectGuid obtained
InvocationID obtained
dnsHostname obtained
site info obtained
All the info for the server collected
Getting information for the server CN=NTDS Settings,CN=PDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
objectGuid obtained
InvocationID obtained
dnsHostname obtained
site info obtained
All the info for the server collected
* Identifying all NC cross-refs. * Found 2 DC(s). Testing 1 of them. Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\PDC01 Starting test: Connectivity * Active Directory LDAP Services Check
Determining IP4 connectivity
* Active Directory RPC Services Check
......................... PDC01 passed test Connectivity Doing primary tests
Testing server: Default-First-Site-Name\PDC01 Starting test: Advertising The DC PDC01 is advertising itself as a DC and having a DS.
The DC PDC01 is advertising as an LDAP server
The DC PDC01 is advertising as having a writeable directory
The DC PDC01 is advertising as a Key Distribution Center
The DC PDC01 is advertising as a time server
The DS PDC01 is advertising as a GC.
......................... PDC01 passed test Advertising Test omitted by user request: CheckSecurityError Test omitted by user request: CutoffServers Starting test: FrsEvent * The File Replication Service Event log test
Skip the test because the server is running DFSR. ......................... PDC01 passed test FrsEvent Starting test: DFSREvent The DFS Replication Event Log.
There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems.
A warning event occurred. EventID: 0x80001396 Time Generated: 01/09/2015 02:30:42 Event String: The DFS Replication service is stopping communication with partner PDC02 for replication group Domain System Volume due to an error. The service will retry the connection periodically. Additional Information: Error: 9036 (Paused for backup or restore) Connection ID: 86C3FEA0-BDA6-4422-B98F-0E86858AD659 Replication Group ID: 956DC852-676D-4B9E-B182-859C8EC70696 ......................... PDC01 passed test DFSREvent Starting test: SysVolCheck * The File Replication Service SYSVOL ready test
File Replication Service's SYSVOL is ready
......................... PDC01 passed test SysVolCheck Starting test: KccEvent * The KCC Event log test
Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
......................... PDC01 passed test KccEvent Starting test: KnowsOfRoleHolders Role Schema Owner = CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
Role Domain Owner = CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
Role PDC Owner = CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
Role Rid Owner = CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
Role Infrastructure Update Owner = CN=NTDS Settings,CN=PDC02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local
......................... PDC01 passed test KnowsOfRoleHolders Starting test: MachineAccount Checking machine account for DC PDC01 on DC PDC01.
* SPN found :LDAP/PDC01.****.local/****.local
* SPN found :LDAP/PDC01.****.local
* SPN found :LDAP/PDC01
* SPN found :LDAP/PDC01.****.local/****
* SPN found :LDAP/64568a46-2242-423c-bb66-04d31a6a8f91._msdcs.****.local
* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/64568a46-2242-423c-bb66-04d31a6a8f91/****.local
* SPN found :HOST/PDC01.****.local/****.local
* SPN found :HOST/PDC01.****.local
* SPN found :HOST/PDC01
* SPN found :HOST/PDC01.****.local/****
* SPN found :GC/PDC01.****.local/****.local
......................... PDC01 passed test MachineAccount Starting test: NCSecDesc * Security Permissions check for all NC's on DC PDC01.
* Security Permissions Check for DC=DomainDnsZones,DC=****,DC=local
(NDNC,Version 3)
* Security Permissions Check for DC=ForestDnsZones,DC=****,DC=local
(NDNC,Version 3)
* Security Permissions Check for CN=Schema,CN=Configuration,DC=****,DC=local
(Schema,Version 3)
* Security Permissions Check for CN=Configuration,DC=****,DC=local
(Configuration,Version 3)
* Security Permissions Check for DC=****,DC=local
(Domain,Version 3)
......................... PDC01 passed test NCSecDesc Starting test: NetLogons * Network Logons Privileges Check
Verified share \\PDC01\netlogon
Verified share \\PDC01\sysvol
......................... PDC01 passed test NetLogons Starting test: ObjectsReplicated PDC01 is in domain DC=****,DC=local
Checking for CN=PDC01,OU=Domain Controllers,DC=****,DC=local in domain DC=****,DC=local on 1 servers
Object is up-to-date on all servers.
Checking for CN=NTDS Settings,CN=PDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local in domain CN=Configuration,DC=****,DC=local on 1 servers
Object is up-to-date on all servers.
......................... PDC01 passed test ObjectsReplicated Test omitted by user request: OutboundSecureChannels Starting test: Replications * Replications Check
* Replication Latency Check
DC=DomainDnsZones,DC=****,DC=local
Latency information for 1 entries in the vector were ignored.
1 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=ForestDnsZones,DC=****,DC=local
Latency information for 1 entries in the vector were ignored.
1 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Schema,CN=Configuration,DC=****,DC=local
Latency information for 1 entries in the vector were ignored.
1 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Configuration,DC=****,DC=local
Latency information for 1 entries in the vector were ignored.
1 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=****,DC=local
Latency information for 1 entries in the vector were ignored.
1 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
......................... PDC01 passed test Replications Starting test: RidManager * Available RID Pool for the Domain is 2600 to 1073741823
* PDC02.****.local is the RID Master
* DsBind with RID Master was successful
* rIDAllocationPool is 2100 to 2599
* rIDPreviousAllocationPool is 2100 to 2599
* rIDNextRID: 2123
......................... PDC01 passed test RidManager Starting test: Services * Checking Service: EventSystem
* Checking Service: RpcSs
* Checking Service: NTDS
* Checking Service: DnsCache
* Checking Service: DFSR
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: w32time
* Checking Service: NETLOGON
......................... PDC01 passed test Services Starting test: SystemLog * The System Event log test
Found no errors in "System" Event log in the last 60 minutes.
......................... PDC01 passed test SystemLog Test omitted by user request: Topology Test omitted by user request: VerifyEnterpriseReferences Starting test: VerifyReferences The system object reference (serverReference) CN=PDC01,OU=Domain Controllers,DC=****,DC=local and backlink on CN=PDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local are correct.
The system object reference (serverReferenceBL) CN=PDC01,CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=****,DC=local and backlink on CN=NTDS Settings,CN=PDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=****,DC=local are correct.
The system object reference (msDFSR-ComputerReferenceBL) CN=PDC01,CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=****,DC=local and backlink on CN=PDC01,OU=Domain Controllers,DC=****,DC=local are correct.
......................... PDC01 passed test VerifyReferences Test omitted by user request: VerifyReplicas
Test omitted by user request: DNS Test omitted by user request: DNS
Running partition tests on : DomainDnsZones Starting test: CheckSDRefDom ......................... DomainDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... DomainDnsZones passed test CrossRefValidation
Running partition tests on : ForestDnsZones Starting test: CheckSDRefDom ......................... ForestDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... ForestDnsZones passed test CrossRefValidation
Running partition tests on : Schema Starting test: CheckSDRefDom ......................... Schema passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration Starting test: CheckSDRefDom ......................... Configuration passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Configuration passed test CrossRefValidation
Running partition tests on : **** Starting test: CheckSDRefDom ......................... **** passed test CheckSDRefDom Starting test: CrossRefValidation ......................... **** passed test CrossRefValidation
Running enterprise tests on : ****.local Test omitted by user request: DNS Test omitted by user request: DNS Starting test: LocatorCheck GC Name: \\PDC01.****.local Locator Flags: 0xe00031fc
PDC Name: \\PDC02.****.local
Locator Flags: 0xe00031fd
Time Server Name: \\PDC01.****.local
Locator Flags: 0xe00031fc
Preferred Time Server Name: \\PDC01.****.local
Locator Flags: 0xe00031fc
KDC Name: \\PDC01.****.local
Locator Flags: 0xe00031fc
......................... ****.local passed test LocatorCheck Starting test: Intersite Skipping site Default-First-Site-Name, this site is outside the scope provided by the command line arguments provided.
......................... ****.local passed test Intersite

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • redfoxert
  • Registratie: December 2000
  • Niet online
Je DFS Replication lijkt kapot te zijn. Check de diskspace van je servers eens?

Een google op de error code kwam hier uit: http://www.experts-exchan...rver_2008/Q_24721996.html

Kort maar bondig antwoord:

Run the burflag method to resync the two DCs.

Using the BurFlags registry key to reinitialize File Replication Service replica sets

Make sure the DCs are pointing to each other for DNS as secondary.
Disable IPv6.
Run ipconfig /registerdns, dcdiag /fix on both DCs.

Allow replication to finish before changing any settings.

https://discord.com/invite/tweakers


Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
redfoxert schreef op vrijdag 09 januari 2015 @ 15:41:
Je DFS Replication lijkt kapot te zijn. Check de diskspace van je servers eens?

Een google op de error code kwam hier uit: http://www.experts-exchan...rver_2008/Q_24721996.html

Kort maar bondig antwoord:

Run the burflag method to resync the two DCs.

Using the BurFlags registry key to reinitialize File Replication Service replica sets

Make sure the DCs are pointing to each other for DNS as secondary.
Disable IPv6.
Run ipconfig /registerdns, dcdiag /fix on both DCs.

Allow replication to finish before changing any settings.
Dankje, ga ik even bekijken.
Ik zie wel dat ik op expert-exchange verplicht ben om te registreren wil ik de solution bekijken.

Ik ga even rondneuzen, en meld mij dan hier met goed en/of slecht nieuws _/-\o_

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
Hmm, ben eerst even met het DNS bezig.
De PDC02 staat qua DNS naar ::1 en alleen naar de PDC01 en niet naar zichzelf.
De PDC01 staat qua DNS naar ::1 dan naar de PDC02 en dan naar zichzelf

Dus dat is een flinke zooi zover ik kan zien.

EDIT:
Kom ook het volgende tegen:
De DB01 staat qua DNS naar zichzelf en dan naar de PDC02 (ipv6 staat uit blijkbaar)
De DB02 staat qua DNS naar DB01 en dan naar PDC02.

[ Voor 26% gewijzigd door JustinoFTW op 09-01-2015 16:04 ]

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • redfoxert
  • Registratie: December 2000
  • Niet online
En zijn die DB servers dan ook zelf DNS server? Want dat klopt dan inderdaad ook voor geen meter. Waarom zou je Exchange servers van DNS willen voorzien?

PS: Als je via Google de foutmelding opzoekt en dan vanuit de Google search options een nieuwe tab start met de link dan krijg je ook de oplossing te zien ;) Maar als dat niet lukt dan heb je de oplossing in de post van mij in ieder geval ook.

https://discord.com/invite/tweakers


Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
redfoxert schreef op vrijdag 09 januari 2015 @ 17:01:
En zijn die DB servers dan ook zelf DNS server? Want dat klopt dan inderdaad ook voor geen meter. Waarom zou je Exchange servers van DNS willen voorzien?

PS: Als je via Google de foutmelding opzoekt en dan vanuit de Google search options een nieuwe tab start met de link dan krijg je ook de oplossing te zien ;) Maar als dat niet lukt dan heb je de oplossing in de post van mij in ieder geval ook.
Klopt niet nee, ga ik van het weekend herstellen voor minimale impact.

Thanks voor de tip, had ik natuurlijk zelf kunnen bedenken O+

EDIT: IPv6 uit op beide PDC's?

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • Question Mark
  • Registratie: Mei 2003
  • Laatst online: 09-07 16:17

Question Mark

Moderator SSC/WOS

F7 - Nee - Ja

Met twee DC's die beide DNS-server zijn moet je gewoon deze gewoon kruislings instellen :)

DC01, primair naar DC02 en secundair naar DC01
DC02, primair naar DC01 en secundair naar DC02

MCSE NT4/2K/2K3, MCTS, MCITP, CCA, CCEA, CCEE, CCIA, CCNA, CCDA, CCNP, CCDP, VCP, CEH + zwemdiploma A & B


Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
Question Mark schreef op vrijdag 09 januari 2015 @ 21:02:
Met twee DC's die beide DNS-server zijn moet je gewoon deze gewoon kruislings instellen :)

DC01, primair naar DC02 en secundair naar DC01
DC02, primair naar DC01 en secundair naar DC02
Klopt helemaal.
Is niet mijn configuratie, maar ben nu alles aan het nalopen wegens verschillende issues.

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
Kleine vraag tussendoor. De DC's hebben beide issues met de DFS Replication zoals redfoxert vermeld.
Ik zie op geen van beide de "File Services" Role is geinstalleerd, waar DFS in zit.

Kan dit de fout simpelweg gewoon zijn, of zit er in exchange zelf ook al een DFS

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • Semt-x
  • Registratie: September 2002
  • Laatst online: 21:06
ipv6 = aan.

redfoxert linkt het verkeerde KB artikel, die verwijst naar de oude replicatie methode FRS, terwijl in je log staat te lezen dat DFSR wordt gebruikt:
"Skip the test because the server is running DFSR"

Dus je functional level is 2008 of hoger, beantwoord deels welke versie DCs er worden gebruikt.

Als het probleem inderdaad DFS replicatie is, zou dit een oplossing kunnen zijn. How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)
ik kan niet inschatten of het ook echt zo is.

DFS rol is niet nodig op een DC.

Ik zou in de replicatie log zoeken van PDC01.

h2h
/S

Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
Semt-x schreef op zaterdag 10 januari 2015 @ 00:37:
ipv6 = aan.

redfoxert linkt het verkeerde KB artikel, die verwijst naar de oude replicatie methode FRS, terwijl in je log staat te lezen dat DFSR wordt gebruikt:
"Skip the test because the server is running DFSR"

Dus je functional level is 2008 of hoger, beantwoord deels welke versie DCs er worden gebruikt.

Als het probleem inderdaad DFS replicatie is, zou dit een oplossing kunnen zijn. How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)
ik kan niet inschatten of het ook echt zo is.

DFS rol is niet nodig op een DC.

Ik zou in de replicatie log zoeken van PDC01.

h2h
/S
Oke, duidelijk.
Zodra ik de mogelijkheid heb, zal ik dit toepassen.

Zal daarna terugkoppeling geven.

EDIT: Ik kom dit net ook tegen, maar dat word dan plan B. http://m.windowsitpro.com...tory-replication-problems

[ Voor 8% gewijzigd door JustinoFTW op 10-01-2015 11:38 ]

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • Question Mark
  • Registratie: Mei 2003
  • Laatst online: 09-07 16:17

Question Mark

Moderator SSC/WOS

F7 - Nee - Ja

Begin nu gewoon stap voor stap aanpassingen te doen, je weet al dat je DNS inrichting niet juist is. En dat is toch eigenlijk wel de basisvereiste voor een juiste AD-werking.

Fix die inrichting zoals hierboven vermeld. Herstart de netlogon service op beide DC's en draai DCDiag nogmaals en kijk naar eventuele errors. Ga pas verder troubleshooten of aanpassingen doorvoeren als je weet dat je basis helemaal goed is.

MCSE NT4/2K/2K3, MCTS, MCITP, CCA, CCEA, CCEE, CCIA, CCNA, CCDA, CCNP, CCDP, VCP, CEH + zwemdiploma A & B


Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
Question Mark schreef op zaterdag 10 januari 2015 @ 20:31:
Begin nu gewoon stap voor stap aanpassingen te doen, je weet al dat je DNS inrichting niet juist is. En dat is toch eigenlijk wel de basisvereiste voor een juiste AD-werking.

Fix die inrichting zoals hierboven vermeld. Herstart de netlogon service op beide DC's en draai DCDiag nogmaals en kijk naar eventuele errors. Ga pas verder troubleshooten of aanpassingen doorvoeren als je weet dat je basis helemaal goed is.
Beste Mark,

Dit was ook mijn bedoeling. Staat voor vannacht in de planning samen met Windows Updates, dus zal morgen even terugkoppelen.

Zodra dit gefixt is, zal ik de PDC's stuk voor stuk even herstarten.

En dat het in deze staat verkeerd, daar schrok ik ook even van. Maar we komen er wel.

[ Voor 4% gewijzigd door JustinoFTW op 10-01-2015 23:05 ]

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • JustinoFTW
  • Registratie: Mei 2011
  • Laatst online: 06-07 20:42
Hierbij een voorlopige update.
De PDC's staan weer mooi in sync na alle DNS Settings goed te zetten.

(Server name | Roles | Enabled | Reachability | Synchronized | GC capable | PDC | SACL right | Critical Data | Netlogon | OS Version)
In-site:
PDC02.**.local CDG 1 7 7 1 0 1 1 7 1
PDC01.**.local CDG 1 7 7 1 0 1 1 7 1


Zijn nog wel enkele connectivity issues gaande, maar daar kom ik morgen op terug.
Gaat de goede kant op zo

EDIT: Na wat reboots, en service restart ziet het er momenteel goed uit. Netwerk heeft een performance boost gekregen, en alles is ook weer up-to-date. Zal het nog even een paar daagjes aankijken en dan koppel ik weer even terug.

_/-\o_ _/-\o_

[ Voor 61% gewijzigd door JustinoFTW op 11-01-2015 15:13 ]

5120Wp Oost/West - PV Output


Acties:
  • 0 Henk 'm!

  • CMD-Snake
  • Registratie: Oktober 2011
  • Laatst online: 13-11-2022
JustinoFTW schreef op vrijdag 09 januari 2015 @ 15:52:
Ik zie wel dat ik op expert-exchange verplicht ben om te registreren wil ik de solution bekijken.
Beetje OT, maar als je op Expert Exchange naar beneden scrolt zie je ook in de comments de juiste oplossing aangevinkt staan. :+ Abo is totaal niet nodig, je moet alleen bereid zijn om de reacties te doorzoeken. ;)
Pagina: 1