DFSR Sysvol invalid msDFSR-Subscriber object data


Recommended Posts

Hi All,

I've been scratching my head for the last few hours trying to resolve an issue with a DC.

First a bit of background, I have 3 DCs, all globe catalogues, the server that is having the following problems doesn't have any of the FSMO roles, it doesn't have DHCP or DNS roles although it did a few months ago. All the other servers appear to be working fine. The domain is windows server 2008 R2.

I have the following error in my error log:


The DFS Replication service detected invalid msDFSR-Subscriber object data while polling for configuration information.

Additional Information:
Object DN: CN=Domain System Volume,CN=DFSR-LocalSettings,CN=**DC NAME**,OU=Domain Controllers,DC=**DOMAIN NAME**,DC=local
Attribute Name: msDFSR-MemberReference
Domain Controller: **DC NAME**.**DOMAIN NAME**
Polling Cycle: 60 minutes[/CODE]

AD replication is fine, running REPADMIN /SHOWREPL * /CSV shows no errors and the last success was within the last few minutes and several tests I've done show that replication is fine.

Everything in ASDI looks ok, does anyone have an suggestions on where to look next?

Is this server a Domain Controller? If it is, you really should have dns on it. TCP/IP properties should have the primary pointing to its static IP address, secondary should be pointing to one of the other domain controllers.

as sc302 said, if that's a DC I would strongly suggest you have DNS installed on it as well. Can you even dcpromo without installing the DNS role? :\ Whens the last time DFS worked as it should? Did it recently stop working or has it been done for a month or two?

http://social.technet.microsoft.com/Forums/en/winserverfiles/thread/0f1a131f-d657-4edd-b5d2-6d61f5ccbed1

Thanks for the replies people, looking at the logs it has been doing it for a few months, should probably have realised sooner but hey.

I've reinstalled DNS on the box, DNS is replicating as it should, but I've still got the issue of sysvol not replicating on that machine.

After running dcdiag /q I have the following output:


Some objects relating to the DC **DC NAME** have problems:
[1] Problem: Missing Expected Value
Base Object:
CN=NTDS Settings,CN=**DC NAME**,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=**DC NAME**,DC=local
Base Object Description: "DSA Object"
Value Object Attribute Name: serverReferenceBL
Value Object Description: "SYSVOL FRS Member Object"
Recommended Action: See Knowledge Base Article: Q312862

[1] Problem: Missing Expected Value
Base Object:
CN=**DC NAME**,OU=Domain Controllers,DC=**DC NAME**,DC=local
Base Object Description: "DC Account Object"
Value Object Attribute Name: msDFSR-ComputerReferenceBL
Value Object Description: "SYSVOL FRS Member Object"
Recommended Action: See Knowledge Base Article: Q312862

......................... **DC NAME** failed test VerifyReferences[/CODE]

Are normal AD objects replicating then, I.E. User accounts?

If your sure its just sysvol thats broken you can rebuild it from one of the working DC's. In 2000+2003 this was done with the burflags regsitry keys but in 2008 there is a new method using ADSIEdit.

http://technet.microsoft.com/en-us/library/cc816596(v=ws.10).aspx

  Quote
SK[' timestamp=1356613375' post='595417770]

Are normal AD objects replicating then, I.E. User accounts?

If your sure its just sysvol thats broken you can rebuild it from one of the working DC's. In 2000+2003 this was done with the burflags regsitry keys but in 2008 there is a new method using ADSIEdit.

http://technet.micro...6(v=ws.10).aspx

AD objects are replicating correctly, new users account etc. all replicate as expected.

I'll have a look at that technet article, thanks.

You are having an issue with replication. Just because you see your AD objects doesn't mean your file objects are replicating properly. Your replication logs should have errors and possibly some in your ad event logs...these logs should have a ton of errors in them.

  On 27/12/2012 at 15:14, sc302 said:

You are having an issue with replication. Just because you see your AD objects doesn't mean your file objects are replicating properly. Your replication logs should have errors and possibly some in your ad event logs...these logs should have a ton of errors in them.

I am very well aware I am having a problem with replication, I was only answering ]SK[ question about AD object replication. I didn't dismiss your idea to look at he replication logs did I, I was going to have a look at them once I return home.

I'm probably reading to much into it but your post feels like you where attacking me for not replying to you.

This topic is now closed to further replies.
  • Posts

    • Was taking the side glass panel off because I want to install the AORUS X870E Master GPU holder, and while I had the glass side panel in my hands the front one decided to take a kamikaze dive. Now I hope they sell the glass fronts separately, or I am screwed. I'll probably be finding bits of glass for weeks now  😅
    • Yeh, I think you'll find there wasn't much legit savings from what he did. Any chump can fire a bunch of people indiscriminately from positions and services that don't impact that person. At the end of the day, it just means that services that are essential in any functional democracy, won't be able to operate because there are no people to deliver those services. Sure, it "saves" money on paper, but like most short sighted bean counters, there are very real, and expensive impacts later on down the track. Did you know that by buying 2x toothbrush's and a tube of toothpaste every year, and seeing the dentist every 6 months would cost you about $400 a year? So by the time you're in your 30's that would be $12000 of cost! Now imagine if you didn't spend any of that $12000 on preventative oral health care! Wow, so much more money! But you also needed to have several root canals at $1500 per tooth. Plus the time off work for being unable to function with the pain. So lets face it, that initial cost is worth it!
    • You know, there needs to be some sort of regulatio... oh wait..
    • I mean, it's fairly self explanatory isn't it? It's part of the reason Apple don't include all features on all supported devices with new iOS releases (another reason is probably a subtle nudge to upgrade sooner), but there's a balance between the remaining features that are added and the impact on performance/battery life on those older devices. There certainly have been times when devices have really received a practical (performance/battery life) quality of life improvement via a software update, but like absolutely every damn app update log out there currently, "Performance and Security improvements" basically mean nothing of real world impacts these days. Just what I've seen of this new interface, the rendering of that glass effect would surely be more complex and intensive than the previous transparency effects, there's no way they couldn't be more efficient. It's probably quite a small impact, otherwise they wouldn't be releasing it, but it all has an impact. Even Microsoft backtracked from Acrylic to Mica material, which is prerendered blur of the wallpaper. All the Acrylic material is rendered live, so has a greater impact, hence why Windows 11 use the newer, lower impact Mica material as their base material.
  • Recent Achievements

    • One Month Later
      greege earned a badge
      One Month Later
    • Week One Done
      greege earned a badge
      Week One Done
    • Week One Done
      LagFighterZ earned a badge
      Week One Done
    • First Post
      ThatGuyOnline earned a badge
      First Post
    • One Month Later
      5i3zi1 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      547
    2. 2
      ATLien_0
      230
    3. 3
      +FloatingFatMan
      166
    4. 4
      Michael Scrip
      119
    5. 5
      +Edouard
      91
  • Tell a friend

    Love Neowin? Tell a friend!