مشکل در Replication بین دامین کنترلرها
با سلام ، متاسفانه دومین کنترلرها با هم Replicate نمیکنن و نتیجه دستور Dcdiag به شکل زیر هست :
Directory Server Diagnosis Performing initial setup: Trying to find home server... Home Server = sdc * Identified AD Forest. Done gathering initial info. Doing initial required tests Testing server: Default-First-Site-Name\SDC Starting test: Connectivity ......................... SDC passed test Connectivity Doing primary tests Testing server: Default-First-Site-Name\SDC Starting test: Advertising ......................... SDC passed test Advertising Starting test: FrsEvent ......................... SDC passed test FrsEvent Starting test: DFSREvent There are warning or error events within the last 24 hours after th SYSVOL has been shared. Failing SYSVOL replication problems may ca Group Policy problems. ......................... SDC failed test DFSREvent Starting test: SysVolCheck ......................... SDC passed test SysVolCheck Starting test: KccEvent ......................... SDC passed test KccEvent Starting test: KnowsOfRoleHolders ......................... SDC passed test KnowsOfRoleHolders Starting test: MachineAccount ......................... SDC passed test MachineAccount Starting test: NCSecDesc ......................... SDC passed test NCSecDesc Starting test: NetLogons ......................... SDC passed test NetLogons Starting test: ObjectsReplicated ......................... SDC passed test ObjectsReplicated Starting test: Replications [Replications Check,SDC] A recent replication attempt failed: From PDC to SDC Naming Context: DC=ForestDnsZones,DC=padisarco,DC=local The replication generated an error (8456): The source server is currently rejecting replication requests. The failure occurred at 2013-11-16 04:26:18. The last success occurred at 2013-11-15 19:47:14. 30 failures have occurred since the last success. Replication has been explicitly disabled through the server options. [Replications Check,SDC] A recent replication attempt failed: From PDC to SDC Naming Context: DC=DomainDnsZones,DC=padisarco,DC=local The replication generated an error (8456): The source server is currently rejecting replication requests. The failure occurred at 2013-11-16 04:26:36. The last success occurred at 2013-11-15 19:52:21. 29 failures have occurred since the last success. Replication has been explicitly disabled through the server options. [Replications Check,SDC] A recent replication attempt failed: From PDC to SDC Naming Context: CN=Schema,CN=Configuration,DC=padisarco,DC=local The replication generated an error (8456): The source server is currently rejecting replication requests. The failure occurred at 2013-11-16 03:58:02. The last success occurred at 2013-11-15 19:47:14. 9 failures have occurred since the last success. Replication has been explicitly disabled through the server options. [Replications Check,SDC] A recent replication attempt failed: From PDC to SDC Naming Context: CN=Configuration,DC=padisarco,DC=local The replication generated an error (8456): The source server is currently rejecting replication requests. The failure occurred at 2013-11-16 04:29:15. The last success occurred at 2013-11-15 19:47:14. 23 failures have occurred since the last success. Replication has been explicitly disabled through the server options. [Replications Check,SDC] A recent replication attempt failed: From PDC to SDC Naming Context: DC=padisarco,DC=local The replication generated an error (8456): The source server is currently rejecting replication requests. The failure occurred at 2013-11-16 04:29:08. The last success occurred at 2013-11-15 19:50:18. 52 failures have occurred since the last success. Replication has been explicitly disabled through the server options. ......................... SDC failed test Replications Starting test: RidManager ......................... SDC passed test RidManager Starting test: Services ......................... SDC passed test Services Starting test: SystemLog An error event occurred. EventID: 0x00000457 Time Generated: 11/16/2013 03:54:46 Event String: Driver Send To Microsoft OneNote Driver required for printer Sen OneNote 2007 is unknown. Contact the administrator to install the driver be you log in again. An error event occurred. EventID: 0x0000165B Time Generated: 11/16/2013 04:26:34 Event String: The session setup from computer 'ACS' failed because the securit tabase does not contain a trust account 'ACS$' referenced by the specified c ter. An error event occurred. EventID: 0x00000457 Time Generated: 11/16/2013 04:27:23 Event String: Driver Send To Microsoft OneNote Driver required for printer Sen OneNote 2007 is unknown. Contact the administrator to install the driver be you log in again. An error event occurred. EventID: 0x000016AD Time Generated: 11/16/2013 04:28:41 Event String: The session setup from the computer ACS failed to authenticate. following error occurred: ......................... SDC failed test SystemLog Starting test: VerifyReferences ......................... SDC passed test VerifyReferences Running partition tests on : ForestDnsZones Starting test: CheckSDRefDom ......................... ForestDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... ForestDnsZones passed test CrossRefValidation Running partition tests on : DomainDnsZones Starting test: CheckSDRefDom ......................... DomainDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... DomainDnsZones passed test CrossRefValidation Running partition tests on : Schema Starting test: CheckSDRefDom ......................... Schema passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Schema passed test CrossRefValidation Running partition tests on : Configuration Starting test: CheckSDRefDom ......................... Configuration passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Configuration passed test CrossRefValidat Running partition tests on : padisarco Starting test: CheckSDRefDom ......................... padisarco passed test CheckSDRefDom Starting test: CrossRefValidation ......................... padisarco passed test CrossRefValidation Running enterprise tests on : padisarco.local Starting test: LocatorCheck ......................... padisarco.local passed test LocatorCheck Starting test: Intersite ......................... padisarco.local passed test Intersite
6 پاسخ
- بررسی کنید که بر روی هر دو سرور Share های SYSVOL و Netlogon وجود دارن و غیرفعال نیستن.
- بررسی کنید که بر روی هر دو سرور سرویس Netlogon فعال هست و در حالت Automatic قرار داره.
تمام سرویس ها در حالت automatic start قرار دارند
2 دستور net shrae , dcdiag /test:netlogons چک گردید . هیچ مشکلی مشاهده نگردید . ولی لشکال فوق به قوت خود باقی است .
در لینک دانلود hotfix فایل اجرایی موجود نیست
توی خطاهایی که نتیجه دستور dcdiag اولتون هست نشون میده که سیستم عامل سرور شما به دلایلی incoming و outgoing رو برای replication اکتیودایرکتوری بصورت خودکار غیرفعال کرده این مشکل حاد هست و دلایل مختلفی می تونه داشته باشه :
- USN Rollback اتفاق افتاده ، مشکلی که معمولا برای دامین کنترلرهایی که در محیط مجازی هستند رخ میده.
- هارد دیسک سرور شما به ویژه درایو سیستم عامل شما تا حد زیادی پر شده.
- و البته بسیاری از مسائل دیگه ...
خوب در حالت اول شما احتمالش هست که اکتیودایرکتوری رو با استفاده از Snapshot به حالت قبلی در آورده باشید که می تونید با استفاده از این Hotfix و نصب اون بر روی domain Controller مشکل دار مشکل USN Rollback رو حل کنید. برای رفع مشکل دوم می تونید نرم افزار Ccleaner رو دانلود کنید و نصب کنید و تمامی موارد رو چک بزنید تا یک Cleanup خوب از سیستم شما داشته باشه ، فایل های اضافه رو هم حذف کنید. اما برخی اوقات مشکل حاد تر میشه شما می تونید تمامی FSMO ها رو به یکی از DC ها منتقل کنید ، بر روی DC مشکل دار DCPromo رو انجام بدید و حذفش کنید ، یک Metadata cleanup بر روی Domain Controller موجود انجام بدید و مجددا یک Additional ایجاد کنید.
در همون لینک در بالای مطلب به این قسمت مراجعه کنید :
در فولدر دانلود شده فایل اجرایی وجود ندارد