On Fri, Oct 9, 2009 at 12:00 PM, Coleman, Hunter <[email protected]> wrote: > As a point of clarification, the replication is always going to be a pull > process. It's probably worth testing to see if MJRSWDC001 can pull changes > that you make on WDC001/002, and vice-versa. It's entirely possible that > MJRSWDC001 inbound replication is fine, but MJRSWDC001 outbound replication > is broken or not consistently successful.
That, I can do. I just added a new member server to the site that WDC001 is in. When I connect to MJRSWDC001, I do see it listed in it's proper OU. So I am getting some communication between the DCs ... I made a change to the description of that computer account (and another) while connected to MJRSWDC001. I will see if I can then see those changes on WDC001 in a few minutes (I could try and force replication, but I want to see if it works on the normal schedule). It must have *somewhat* worked - REPLMON is showing me only 2 consecutive failures between WDC001 and MJRSWDC001. > If you are putting in another DC in the remote site, you can look at > replication between the new DC and MJRSWDC001 and see if the new DC gets the > same "RPC server is unavailable on MJRSWDC001". A good point. I will look at that, too. > It's fine to reuse the MDRSWDC001 name if you rebuild that DC. Make sure that > the DC demotion process completes "cleanly," and give this demotion time to > replicate to all of the other DCs. Not a bad idea to look at the metadata > cleanup process that you would use in an unsuccessful demotion and verify > that everything did in fact get removed. I am familar with it; I had to do it recently in my "virtual" domain that I maintain on ESX (a copy of my production domains, used for testing). I had to remove all references to non-virtual DCs in the virtual domain. > > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Michael Leone > Sent: Friday, October 09, 2009 8:49 AM > To: [email protected]; NT Admin Mailing List > Subject: Re: [ActiveDir] Fwd: REPLMON shows errors, but only in 1 direction > ... > > On Fri, Oct 9, 2009 at 9:48 AM, Coleman, Hunter <[email protected]> wrote: >> Who does MJRSWDC001 point to for its primary DNS server? > > It points to WDC001 (even though it is also a DNS server, it does not > point to itself for DNS or WINS). WDC001 is the primary DNS in use by > all servers and workstations. > >>If it's pointing to one of the other DCs, and you stop and restart the >>netlogon service, that will make sure that all of the necessary DNS records >>get updated on the other DCs. If it's pointed to itself, then switch it to >>one of the other DCs for the time being. > > I don't think I can bounce the NETLOGON service during working hours, > but I should be able to do that this evening. > >> In changing the IP address on MJRSWDC001, did this also change its site >> affiliation? > > No. Site affiliation stayed the same. The only change for this DC was > in IP address. > > More info - we also have WDC002 as a DC. We added this as a > replication partner for MJRSWDC001. And now WDC002 is showing the same > error during replication, as WDC001 does. ("RPC server is unavailable > on MJRSWDC001") > > So it looks like I've narrowed it down to none of the DCs being able > to push replication into MJRSWDC001, although I still don't know why > ..... I have IP connectivity; replication does *sometimes* work. > > I am considering temporarily putting in another DC at that site; > demoting MJRSWDC001 back to a member server; rebuilding it from > scratch; and then DCPROMO it again. (and gracefully retire the temp > DC). Theoretically, that should resolve that part of the problem. Only > question is - do I continue to use the name MJRSWDC001 after > rebuilding, for fear of some leftover references in AD that might > screw things up ? > >> >> -----Original Message----- >> From: [email protected] >> [mailto:[email protected]] On Behalf Of Michael Leone >> Sent: Thursday, October 08, 2009 5:10 PM >> To: [email protected]; NT Admin Mailing List >> Subject: Re: [ActiveDir] Fwd: REPLMON shows errors, but only in 1 direction >> ... >> >> A thought occurred to us - the server MJRSWDC001 recently had it's IP >> addresses changed (we moved it from one building to another, so it had >> to changed subnets). I'm wondering if somehow the replication is >> confused, and is trying to contact MJRSWDC001 using it's old IP >> address. It shouldn't - I did check forward and reverse DNS, and that >> server does show it's proper (new) address. >> >> Farfetched? >> >> >> >> > > > > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
