Active Directory replication not working ?


Recommended Posts

I did a new deployment of Server 2012 with a high availability TMG Deployment. I created a DC

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Microsoft Hyper-V Network Adapter

DHCP Enabled. . . . . . . . . . . : No

Autoconfiguration Enabled . . . . : Yes

IPv4 Address. . . . . . . . . . . : 10.0.0.2(Preferred)

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 10.0.0.6

DNS Servers . . . . . . . . . . . : 10.0.0.3

10.0.0.2

and then another

Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Microsoft Hyper-V Network Adapter

DHCP Enabled. . . . . . . . . . . : No

Autoconfiguration Enabled . . . . : Yes

IPv4 Address. . . . . . . . . . . : 10.0.0.3(Preferred)

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 10.0.0.6

DNS Servers . . . . . . . . . . . : 10.0.0.2

10.0.0.3

127.0.0.1

NetBIOS over Tcpip. . . . . . . . : Enabled

I used the server manager to join the 10.0.0.3 to the domain and replication appeared to work (I saw it replicating some ous and gpos I made)

Afterwards I continued with my deployment of Central Store,TMG, KMS and WSUS and making group policy objects (nothing special sofar just policys for file explorer and the taskbar) I did however disable the media player, play to and homegroup firewall rules.

I then start to experience issues with gpupdate

The processing of Group Policy failed. Windows attempted to read the file \\ \SysVol\ \Policies\{ }\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:

a) Name Resolution/Network Connectivity to the current domain controller.

b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller).

c) The Distributed File System (DFS) client has been disabled.

With the new gpo's and browse \\Dc2.mydomain.com\SYSVOL\mydomain.com and discover that the scripts folder is empty and that the policys folder only contains the default domain controller policy.

None of the gpos that were replicated by the server manager are there.

After manually copying the gpos to dc2 from dc1 I can access eventlog looking through the logs. The errors I see since deployment are (in order of oldest first)

The server { } did not register with DCOM within the required timeout.

The processing of Group Policy failed. Windows could not locate the directory object OU=Domain Controllers,OU=mynetbiosnameServers,OU=mynetbiosname Computers,DC=mynetbiosname,DC=us. Group Policy settings will not be enforced until this event is resolved. View the event details for more information on this error.

and then The processing of Group Policy failed. Windows attempted to read the file starts again every 15 min multiple times

Moving to the eventlog for dfs replication I see

The DFS Replication service failed to contact domain controller to access configuration information. Replication is stopped. The service will try again during the next configuration polling cycle, which will occur in 60 minutes. This event can be caused by TCP/IP connectivity, firewall, Active Directory Domain Services, or DNS issues.

Additional Information:

Error: 1355 (The specified domain either does not exist or could not be contacted.)

The DFS Replication service failed to contact domain controller to access configuration information. Replication is stopped. The service will try again during the next configuration polling cycle, which will occur in 60 minutes. This event can be caused by TCP/IP connectivity, firewall, Active Directory Domain Services, or DNS issues.

Additional Information:

Error: 160 (One or more arguments are not correct.)

Can anyone suggest what might be the issue ?

I would double check if all is good on the DNS side of things, what's your domain called?

I would get rid of 127.0.0.1 and would point your SDC's 1st DNS to 10.0.0.2

What kind of router R u using?

Ok so I changed the dns with netsh as requested.


C:\Users\Raymond>winrs -r:DC1.mydomain.us ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : DC1
Primary Dns Suffix . . . . . . . : mydomain.us
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : mydomain.us
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Hyper-V Network Adapter
Physical Address. . . . . . . . . : 00-15-5D-00-01-00
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 10.0.0.2(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.0.0.6
DNS Servers . . . . . . . . . . . : 10.0.0.3
10.0.0.2
NetBIOS over Tcpip. . . . . . . . : Enabled
C:\Users\Raymond>winrs -r:DC2.mydomain.us ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : DC2
Primary Dns Suffix . . . . . . . : mydomain.us
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : mydomain.us
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Hyper-V Network Adapter
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 10.0.0.3(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.0.0.6
DNS Servers . . . . . . . . . . . : 10.0.0.2
10.0.0.3
C:\Users\Raymond>
[/CODE]

The router at the moment is just a bog standard Netopia one with practically everything disabled (no rpc filtering) but I will be reverting back to the cisco one after this deployment.

After rebooting first dc2 then dc1 everything seems fine however after I make a new gpo I discover a new

The processing of Group Policy failed. Windows attempted to read the file {gpo path} and it hasn't been replicated to dc2 :wacko:

in the event log for dfs I see

The DFS Replication service stopped replication on volume C:. This occurs when a DFSR JET database is not shut down cleanly and Auto Recovery is disabled. To resolve this issue, back up the files in the affected replicated folders, and then use the ResumeReplication WMI method to resume replication.

which is strange because it was a clean reboot in hyperv. I run ResumeReplication and get the following event log

The DFS Replication service successfully recovered from an unexpected shutdown on volume C:.This can occur if the service terminated abnormally (due to a power loss, for example) or an error occurred on the volume. No user action is required.

but the new gpo still hasn't been replicated. So I copy it manually and make a new gpo.... And im back at square one DFS replication isn't working ?

No the servers are server 2012 which TMG wont install on. They're different vms.

I disabled ip6 on the DC's NIC's as its an ipv4 only network and on all the other servers.

server ip 10.0.0.2

primary dns 10.0.0.2

secondary dns 10.0.0.3

server ip 10.0.0.3

primary dns 10.0.0.3

secondary dns 10.0.0.2

switch it to this....have it look to itself for dns resolution. I have never had an issue with it being itself, but I have had replication issues with the primary pointing to a different server. Let active directory do its thing to replicate dns across to other servers. Don't try to use possibly an outdated dns server to manage dns (outdated could be as little as 10 seconds). Let it reside on itself and talk to itself and replicate to the other servers as needed. Replication by default can happen up to 15 minutes later, but most of the time we see instantaneous replication in small environments. You are better off splitting the fsmo roles than you are trying to force dns lookup on another server....if that other server were to go down, your dns would fail anyway.

also after you have fixed your dns primaries and secondaries, run this command.

Repadmin /replicate /AePdq

This will force a replication. Post any event log entries that occur if there are any failures.

server ip 10.0.0.2

primary dns 10.0.0.2

secondary dns 10.0.0.3

server ip 10.0.0.3

primary dns 10.0.0.3

secondary dns 10.0.0.2

switch it to this....have it look to itself for dns resolution. I have never had an issue with it being itself, but I have had replication issues with the primary pointing to a different server. Let active directory do its thing to replicate dns across to other servers. Don't try to use possibly an outdated dns server to manage dns (outdated could be as little as 10 seconds). Let it reside on itself and talk to itself and replicate to the other servers as needed. Replication by default can happen up to 15 minutes later, but most of the time we see instantaneous replication in small environments. You are better off splitting the fsmo roles than you are trying to force dns lookup on another server....if that other server were to go down, your dns would fail anyway.

also after you have fixed your dns primaries and secondaries, run this command.

Repadmin /replicate /AePdq

This will force a replication. Post any event log entries that occur if there are any failures.

looks good thanks for the help I made a new gpo and it replicated to dc2 ok no gpupdate or eventlog errors.

Note to self used

netsh interface ip set dns "Ethernet" static 10.0.0.x

netsh interface ip add dns "Ethernet" 10.0.0.x index=2

to set the dns in server core

This topic is now closed to further replies.
  • Posts

    • They keep your data encrypted too. Including the calendar.
    • Microsoft makes billions redirecting people to use Bing in Microsoft Edge and selling OneDrive space. All thanks to Windows.
    • Teams is cancer, ebola and aids combined.
    • Claude on Windows is eating up massive amounts of RAM, with no way to stop it by Usama Jawad Anthropic has been in the headlines a lot lately, primarily due to its latest revenue and valuation figures, along with its release of its state-of-the-art (SOTA) Fable model. While its flagship product, Claude, may be very popular among millions of users, a lot of them are now reporting memory issues when using the tool. Over on Claude Code's GitHub repository, an issue raised in February has been gaining traction once again. Basically, Claude Desktop on Windows spins up a 1.8GB Hyper-V virtual machine if you use Claude Cowork or agent mode even once. This happens on each launch of Claude Code even if you plan to use the tool in chat mode only. Several users have upvoted this bug and stated that it's happening on their machine as well. However, it seemingly affects only Claude desktop users on Windows, not customers of the CLI or any other platform. Once the bug is triggered, it also shows a Vmmem process in Task Manager, indicating CPU usage of 0% and RAM utilization of a whopping ~1.8GB. Claude users complain that this process should only spin up when you explicitly launch agent mode or Cowork in Claude, with session files efficiently cleaned up after use. Additionally, they are calling for Claude to gracefully handle the absence of virtual machine-based infrastructure, without compromising on chat performance. It's unclear when this issue originated or what the root cause behind it is, but people are once again actively engaging in the GitHub thread as well as Hacker News. You can also find other technical details and log events over on GitHub. It's unclear if Anthropic will look into this issue, especially since it's already been reported for a few months. However, the bug is also causing major annoyance for users, with many claiming that it has led them to uninstall Claude Code on desktop, as a concrete workaround is not yet known.
    • "The US innovates, China replicates, Europe regulates" -- let's see who makes the cut
  • Recent Achievements

    • One Month Later
      Sopa flores earned a badge
      One Month Later
    • First Post
      StaticMatrix earned a badge
      First Post
    • Week One Done
      StaticMatrix earned a badge
      Week One Done
    • Rookie
      lamborghiniv10 went up a rank
      Rookie
    • One Month Later
      pinnclepd earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      534
    2. 2
      PsYcHoKiLLa
      209
    3. 3
      +Edouard
      154
    4. 4
      Steven P.
      100
    5. 5
      ATLien_0
      84
  • Tell a friend

    Love Neowin? Tell a friend!