Hello Everyone,
I am battling a pair of domain controllers that are not playing nice with each other. They are the only two DCs in the domain and they are separate sites. I am at my wits end. Please help me. I have the two DCs configured as DNS servers as well as two
SOPHOS UTM 9 machines at both ends of the connection that are configured as DNS servers as well. I have some errors that show in DCDIAG and in a couple of tests as well. Below are the results of DCDIAG and REPADMIN /REPLSUM.
THIS is the PDC.
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\nfielding>dcdiag
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = PDC2
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Administration\PDC2
Starting test: Connectivity
......................... PDC2 passed test Connectivity
Doing primary tests
Testing server: Administration\PDC2
Starting test: Advertising
......................... PDC2 passed test Advertising
Starting test: FrsEvent
......................... PDC2 passed test FrsEvent
Starting test: DFSREvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... PDC2 passed test DFSREvent
Starting test: SysVolCheck
......................... PDC2 passed test SysVolCheck
Starting test: KccEvent
A warning event occurred. EventID: 0x8000061E
Time Generated: 08/04/2016 16:15:45
Event String:
All directory servers in the following site that can replicate the d
irectory partition over this transport are currently unavailable.
An error event occurred. EventID: 0xC000051F
Time Generated: 08/04/2016 16:15:45
Event String:
The Knowledge Consistency Checker (KCC) has detected problems with t
he following directory partition.
A warning event occurred. EventID: 0x80000749
Time Generated: 08/04/2016 16:15:45
Event String:
The Knowledge Consistency Checker (KCC) was unable to form a complet
e spanning tree network topology. As a result, the following list of sites canno
t be reached from the local site.
A warning event occurred. EventID: 0x8000061E
Time Generated: 08/04/2016 16:15:45
Event String:
All directory servers in the following site that can replicate the d
irectory partition over this transport are currently unavailable.
An error event occurred. EventID: 0xC000051F
Time Generated: 08/04/2016 16:15:45
Event String:
The Knowledge Consistency Checker (KCC) has detected problems with t
he following directory partition.
A warning event occurred. EventID: 0x80000749
Time Generated: 08/04/2016 16:15:45
Event String:
The Knowledge Consistency Checker (KCC) was unable to form a complet
e spanning tree network topology. As a result, the following list of sites canno
t be reached from the local site.
A warning event occurred. EventID: 0x80000785
Time Generated: 08/04/2016 16:15:45
Event String:
The attempt to establish a replication link for the following writab
le directory partition failed.
A warning event occurred. EventID: 0x80000785
Time Generated: 08/04/2016 16:15:46
Event String:
The attempt to establish a replication link for the following writab
le directory partition failed.
A warning event occurred. EventID: 0x80000785
Time Generated: 08/04/2016 16:15:47
Event String:
The attempt to establish a replication link for the following writab
le directory partition failed.
......................... PDC2 failed test KccEvent
Starting test: KnowsOfRoleHolders
......................... PDC2 passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... PDC2 passed test MachineAccount
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ypt-nsn,DC=gov
......................... PDC2 failed test NCSecDesc
Starting test: NetLogons
......................... PDC2 passed test NetLogons
Starting test: ObjectsReplicated
......................... PDC2 passed test ObjectsReplicated
Starting test: Replications
......................... PDC2 passed test Replications
Starting test: RidManager
......................... PDC2 passed test RidManager
Starting test: Services
......................... PDC2 passed test Services
Starting test: SystemLog
A warning event occurred. EventID: 0x00001695
Time Generated: 08/04/2016 16:10:51
Event String:
Dynamic registration or deletion of one or more DNS records associat
ed with DNS domain 'ypt-nsn.gov.' failed. These records are used by other compu
ters to locate this server as a domain controller (if the specified domain is an
Active Directory domain) or as an LDAP server (if the specified domain is an ap
plication partition).
A warning event occurred. EventID: 0x00001695
Time Generated: 08/04/2016 16:10:51
Event String:
Dynamic registration or deletion of one or more DNS records associat
ed with DNS domain 'ForestDnsZones.ypt-nsn.gov.' failed. These records are used
by other computers to locate this server as a domain controller (if the specifi
ed domain is an Active Directory domain) or as an LDAP server (if the specified
domain is an application partition).
A warning event occurred. EventID: 0x00001695
Time Generated: 08/04/2016 16:10:51
Event String:
Dynamic registration or deletion of one or more DNS records associat
ed with DNS domain 'DomainDnsZones.ypt-nsn.gov.' failed. These records are used
by other computers to locate this server as a domain controller (if the specifi
ed domain is an Active Directory domain) or as an LDAP server (if the specified
domain is an application partition).
......................... PDC2 passed test SystemLog
Starting test: VerifyReferences
......................... PDC2 passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : ypt-nsn
Starting test: CheckSDRefDom
......................... ypt-nsn passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ypt-nsn passed test CrossRefValidation
Running enterprise tests on : ypt-nsn.gov
Starting test: LocatorCheck
......................... ypt-nsn.gov passed test LocatorCheck
Starting test: Intersite
......................... ypt-nsn.gov passed test Intersite
C:\Users\nfielding>
Here is the REPADMIN /REPLSUM for the PDC as well
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\nfielding>repadmin /replsum
Replication Summary Start Time: 2016-08-04 16:27:56
Beginning data collection for replication summary, this may take awhile:
.....
Source DSA largest delta fails/total %% error
Destination DSA largest delta fails/total %% error
Experienced the following operational errors trying to retrieve replication info
rmation:
58 - 3a108ae5-5337-4af9-911a-c04c6e5910e4._msdcs.ypt-nsn.gov
C:\Users\nfielding>
The ID above is the BDC