مشکل در Replication بین دامین کنترلرها
با سلام ، متاسفانه دومین کنترلرها با هم Replicate نمیکنن و نتیجه دستور Dcdiag به شکل زیر هست :
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = sdc
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\SDC
Starting test: Connectivity
......................... SDC passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\SDC
Starting test: Advertising
......................... SDC passed test Advertising
Starting test: FrsEvent
......................... SDC passed test FrsEvent
Starting test: DFSREvent
There are warning or error events within the last 24 hours after th
SYSVOL has been shared. Failing SYSVOL replication problems may ca
Group Policy problems.
......................... SDC failed test DFSREvent
Starting test: SysVolCheck
......................... SDC passed test SysVolCheck
Starting test: KccEvent
......................... SDC passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... SDC passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... SDC passed test MachineAccount
Starting test: NCSecDesc
......................... SDC passed test NCSecDesc
Starting test: NetLogons
......................... SDC passed test NetLogons
Starting test: ObjectsReplicated
......................... SDC passed test ObjectsReplicated
Starting test: Replications
[Replications Check,SDC] A recent replication attempt failed:
From PDC to SDC
Naming Context: DC=ForestDnsZones,DC=padisarco,DC=local
The replication generated an error (8456):
The source server is currently rejecting replication requests.
The failure occurred at 2013-11-16 04:26:18.
The last success occurred at 2013-11-15 19:47:14.
30 failures have occurred since the last success.
Replication has been explicitly disabled through the server
options.
[Replications Check,SDC] A recent replication attempt failed:
From PDC to SDC
Naming Context: DC=DomainDnsZones,DC=padisarco,DC=local
The replication generated an error (8456):
The source server is currently rejecting replication requests.
The failure occurred at 2013-11-16 04:26:36.
The last success occurred at 2013-11-15 19:52:21.
29 failures have occurred since the last success.
Replication has been explicitly disabled through the server
options.
[Replications Check,SDC] A recent replication attempt failed:
From PDC to SDC
Naming Context: CN=Schema,CN=Configuration,DC=padisarco,DC=local
The replication generated an error (8456):
The source server is currently rejecting replication requests.
The failure occurred at 2013-11-16 03:58:02.
The last success occurred at 2013-11-15 19:47:14.
9 failures have occurred since the last success.
Replication has been explicitly disabled through the server
options.
[Replications Check,SDC] A recent replication attempt failed:
From PDC to SDC
Naming Context: CN=Configuration,DC=padisarco,DC=local
The replication generated an error (8456):
The source server is currently rejecting replication requests.
The failure occurred at 2013-11-16 04:29:15.
The last success occurred at 2013-11-15 19:47:14.
23 failures have occurred since the last success.
Replication has been explicitly disabled through the server
options.
[Replications Check,SDC] A recent replication attempt failed:
From PDC to SDC
Naming Context: DC=padisarco,DC=local
The replication generated an error (8456):
The source server is currently rejecting replication requests.
The failure occurred at 2013-11-16 04:29:08.
The last success occurred at 2013-11-15 19:50:18.
52 failures have occurred since the last success.
Replication has been explicitly disabled through the server
options.
......................... SDC failed test Replications
Starting test: RidManager
......................... SDC passed test RidManager
Starting test: Services
......................... SDC passed test Services
Starting test: SystemLog
An error event occurred. EventID: 0x00000457
Time Generated: 11/16/2013 03:54:46
Event String:
Driver Send To Microsoft OneNote Driver required for printer Sen
OneNote 2007 is unknown. Contact the administrator to install the driver be
you log in again.
An error event occurred. EventID: 0x0000165B
Time Generated: 11/16/2013 04:26:34
Event String:
The session setup from computer 'ACS' failed because the securit
tabase does not contain a trust account 'ACS$' referenced by the specified c
ter.
An error event occurred. EventID: 0x00000457
Time Generated: 11/16/2013 04:27:23
Event String:
Driver Send To Microsoft OneNote Driver required for printer Sen
OneNote 2007 is unknown. Contact the administrator to install the driver be
you log in again.
An error event occurred. EventID: 0x000016AD
Time Generated: 11/16/2013 04:28:41
Event String:
The session setup from the computer ACS failed to authenticate.
following error occurred:
......................... SDC failed test SystemLog
Starting test: VerifyReferences
......................... SDC passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidat
Running partition tests on : padisarco
Starting test: CheckSDRefDom
......................... padisarco passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... padisarco passed test CrossRefValidation
Running enterprise tests on : padisarco.local
Starting test: LocatorCheck
......................... padisarco.local passed test LocatorCheck
Starting test: Intersite
......................... padisarco.local passed test Intersite
6 پاسخ
- بررسی کنید که بر روی هر دو سرور Share های SYSVOL و Netlogon وجود دارن و غیرفعال نیستن.
- بررسی کنید که بر روی هر دو سرور سرویس Netlogon فعال هست و در حالت Automatic قرار داره.
تمام سرویس ها در حالت automatic start قرار دارند
2 دستور net shrae , dcdiag /test:netlogons چک گردید . هیچ مشکلی مشاهده نگردید . ولی لشکال فوق به قوت خود باقی است .
در لینک دانلود hotfix فایل اجرایی موجود نیست
توی خطاهایی که نتیجه دستور dcdiag اولتون هست نشون میده که سیستم عامل سرور شما به دلایلی incoming و outgoing رو برای replication اکتیودایرکتوری بصورت خودکار غیرفعال کرده این مشکل حاد هست و دلایل مختلفی می تونه داشته باشه :
- USN Rollback اتفاق افتاده ، مشکلی که معمولا برای دامین کنترلرهایی که در محیط مجازی هستند رخ میده.
- هارد دیسک سرور شما به ویژه درایو سیستم عامل شما تا حد زیادی پر شده.
- و البته بسیاری از مسائل دیگه ...
خوب در حالت اول شما احتمالش هست که اکتیودایرکتوری رو با استفاده از Snapshot به حالت قبلی در آورده باشید که می تونید با استفاده از این Hotfix و نصب اون بر روی domain Controller مشکل دار مشکل USN Rollback رو حل کنید. برای رفع مشکل دوم می تونید نرم افزار Ccleaner رو دانلود کنید و نصب کنید و تمامی موارد رو چک بزنید تا یک Cleanup خوب از سیستم شما داشته باشه ، فایل های اضافه رو هم حذف کنید. اما برخی اوقات مشکل حاد تر میشه شما می تونید تمامی FSMO ها رو به یکی از DC ها منتقل کنید ، بر روی DC مشکل دار DCPromo رو انجام بدید و حذفش کنید ، یک Metadata cleanup بر روی Domain Controller موجود انجام بدید و مجددا یک Additional ایجاد کنید.
در همون لینک در بالای مطلب به این قسمت مراجعه کنید :
در فولدر دانلود شده فایل اجرایی وجود ندارد