On Fri, Oct 9, 2009 at 12:00 PM, Coleman, Hunter <[email protected]> wrote:
> As a point of clarification, the replication is always going to be a pull 
> process. It's probably worth testing to see if MJRSWDC001 can pull changes 
> that you make on WDC001/002, and vice-versa. It's entirely possible that 
> MJRSWDC001 inbound replication is fine, but MJRSWDC001 outbound replication 
> is broken or not consistently successful.

That, I can do. I just added a new member server to the site that
WDC001 is in. When I connect to MJRSWDC001, I do see it listed in it's
proper OU. So I am getting some communication between the DCs ...

I made a change to the description of that computer account (and
another) while connected to MJRSWDC001. I will see if I can then see
those changes on WDC001 in a few minutes (I could try and force
replication, but I want to see if it works on the normal schedule).

It must have *somewhat* worked - REPLMON is showing me only 2
consecutive failures between WDC001 and MJRSWDC001.

> If you are putting in another DC in the remote site, you can look at 
> replication between the new DC and MJRSWDC001 and see if the new DC gets the 
> same "RPC server is unavailable on MJRSWDC001".

A good point. I will look at that, too.

> It's fine to reuse the MDRSWDC001 name if you rebuild that DC. Make sure that 
> the DC demotion process completes "cleanly," and give this demotion time to 
> replicate to all of the other DCs. Not a bad idea to look at the metadata 
> cleanup process that you would use in an unsuccessful demotion and verify 
> that everything did in fact get removed.

I am familar with it; I had to do it recently in my "virtual" domain
that I maintain on ESX (a copy of my production domains, used for
testing). I had to remove all references to non-virtual DCs in the
virtual domain.

>
> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Michael Leone
> Sent: Friday, October 09, 2009 8:49 AM
> To: [email protected]; NT Admin Mailing List
> Subject: Re: [ActiveDir] Fwd: REPLMON shows errors, but only in 1 direction 
> ...
>
> On Fri, Oct 9, 2009 at 9:48 AM, Coleman, Hunter <[email protected]> wrote:
>> Who does MJRSWDC001 point to for its primary DNS server?
>
> It points to WDC001 (even though it is also a DNS server, it does not
> point to itself for DNS or WINS). WDC001 is the primary DNS in use by
> all servers and workstations.
>
>>If it's pointing to one of the other DCs, and you stop and restart the 
>>netlogon service, that will make sure that all of the necessary DNS records 
>>get updated on the other DCs. If it's pointed to itself, then switch it to 
>>one of the other DCs for the time being.
>
> I don't think I can bounce the NETLOGON service during working hours,
> but I should be able to do that this evening.
>
>> In changing the IP address on MJRSWDC001, did this also change its site 
>> affiliation?
>
> No. Site affiliation stayed the same. The only change for this DC was
> in IP address.
>
> More info - we also have WDC002 as a DC. We added this as a
> replication partner for MJRSWDC001. And now WDC002 is showing the same
> error during replication, as WDC001 does.  ("RPC server is unavailable
> on MJRSWDC001")
>
> So it looks like I've narrowed it down to none of the DCs being able
> to push replication into MJRSWDC001, although I still don't know why
> ..... I have IP connectivity; replication does *sometimes* work.
>
> I am considering temporarily putting in another DC at that site;
> demoting MJRSWDC001 back to a member server; rebuilding it from
> scratch; and then DCPROMO it again. (and gracefully retire the temp
> DC). Theoretically, that should resolve that part of the problem. Only
> question is - do I continue to use the name MJRSWDC001 after
> rebuilding, for fear of some leftover references in AD that might
> screw things up ?
>
>>
>> -----Original Message-----
>> From: [email protected] 
>> [mailto:[email protected]] On Behalf Of Michael Leone
>> Sent: Thursday, October 08, 2009 5:10 PM
>> To: [email protected]; NT Admin Mailing List
>> Subject: Re: [ActiveDir] Fwd: REPLMON shows errors, but only in 1 direction 
>> ...
>>
>> A thought occurred to us - the server MJRSWDC001 recently had it's IP
>> addresses changed (we moved it from one building to another, so it had
>> to changed subnets). I'm wondering if somehow the replication is
>> confused, and is trying to contact MJRSWDC001 using it's old IP
>> address. It shouldn't - I did check forward and reverse DNS, and that
>> server does show it's proper (new) address.
>>
>> Farfetched?
>>
>>
>>
>>
>
>
>
>

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to