У меня есть 2 домена на ос win 2000 Aadvanced server
1- глобальный каталог мастер
2- дочерний домен слейв
приблизительно с 2006 года с июня прекратилась репликация между двумя контроллерами домена.
в 2007 февраль, поднял связь между 2 офисами при помощи по Kerio Winoute
Репликация с дочернего домена на глобалный каталог прошла успешна
при попытке реплицировать с данные с глобального каталога на дочерний домен произошла ошибка.
ошибка 13508
Служба репликации файлов столкнулась с проблемами при включении репликации с "FILIAL1" на "INTEL" для "c:\winnt\sysvol\domain", использующего DNS-имя "Filial1.vinoonline.ru". Служба репликации файлов (FRS) продолжит повторные попытки.
Ниже указаны причины, по которым может выдаваться это предупреждение.
[1] FRS не может разрешить DNS-имя "Filial1.vinoonline.ru" с этого компьютера.
[2] FRS не запущена на "Filial1.vinoonline.ru".
[3] Сведения в Active Directory о топологии для этой реплики реплицированы еще не на все контроллеры домена.
Это сообщение об ошибке записывается в журнал для каждого подключения один раз. После исправления ошибки в журнал будет записано другое сообщение, означающее, что соединение установлено.
Утилитами Resource Kit провел диагностику:
читать дальшеМастер:
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\INTEL
Starting test: Connectivity
......................... INTEL passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\INTEL
Starting test: Replications
......................... INTEL passed test Replications
Starting test: NCSecDesc
......................... INTEL passed test NCSecDesc
Starting test: NetLogons
......................... INTEL passed test NetLogons
Starting test: Advertising
......................... INTEL passed test Advertising
Starting test: KnowsOfRoleHolders
......................... INTEL passed test KnowsOfRoleHolders
Starting test: RidManager
......................... INTEL passed test RidManager
Starting test: MachineAccount
......................... INTEL passed test MachineAccount
Starting test: Services
......................... INTEL passed test Services
Starting test: ObjectsReplicated
......................... INTEL passed test ObjectsReplicated
Starting test: frssysvol
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
......................... INTEL passed test frssysvol
Starting test: kccevent
......................... INTEL passed test kccevent
Starting test: systemlog
......................... INTEL passed test systemlog
Running enterprise tests on : vinoonline.ru
Starting test: Intersite
......................... vinoonline.ru passed test Intersite
Starting test: FsmoCheck
......................... vinoonline.ru passed test FsmoCheck
________________________________________________________________________________
netdiag.exe
.......................................
Computer Name: INTEL
DNS Host Name: Intel.vinoonline.ru
System info : Windows 2000 Server (Build 2195)
Processor : x86 Family 15 Model 2 Stepping 7, GenuineIntel
List of installed hotfixes :
KB329115
KB822343
KB823182
KB823559
KB823980
KB824105
KB825119
KB826232
KB828035
KB828749
KB832353
KB832359
KB835732
KB841356
KB842773
KB883935
KB885836
KB893756
KB893803v2
KB896358
KB896422
KB896423
KB896424
KB899587
KB899589
KB899591
KB900725
KB901017
KB901214
KB904706
KB905414
KB905495-IE6SP1-20050805.184113
KB905749
KB908519
KB908531
KB911280
KB911564
KB912919
KB913580
KB914388
KB914389
KB917008
KB917422
KB917736
KB917953
KB918118
KB920213
KB920670
KB920683
KB920685
KB920958
KB921398
KB922582
KB922616
KB923191
KB923414
KB923694-OE6SP1-20061106.120000
KB923980
KB924191
KB924270
KB924667
KB925398_WMP64
KB925454-IE6SP1-20061116.120000
KB925486-IE6SP1-20060918.120000
KB926436
KB928090-IE6SP1-20070125.120000
KB928843
KB929969-IE6SP1-20061220.120000
Q147222
Q816093
Q828026
Update Rollup 1
Netcard queries test . . . . . . . : Passed
GetStats failed for '¦Ё ьющ ярЁрыыхы№эvщ яюЁЄ'. [ERROR_NOT_SUPPORTED]
GetStats failed for '¦шэшяюЁЄ WAN (PPTP)'. [ERROR_GEN_FAILURE]
[WARNING] The net card '¦шэшяюЁЄ WAN (IP)' may not be working because it has
not received any packets.
GetStats failed for '¦шэшяюЁЄ WAN (L2TP)'. [ERROR_NOT_SUPPORTED]
Per interface results:
Adapter : ¦юфъы¦ўхэшх яю ыюъры№эющ ёхЄш
Netcard queries test . . . : Passed
Host Name. . . . . . . . . : Intel
IP Address . . . . . . . . : 192.168.0.254
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.0.15
Primary WINS Server. . . . : 192.168.0.254
Dns Servers. . . . . . . . : 192.168.0.254
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Passed
NetBT name test. . . . . . : Passed
WINS service test. . . . . : Passed
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{78818434-586A-4EDB-AA0D-7FF85A35206F}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Passed
NetBT name test. . . . . . . . . . : Passed
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server '192.168.0.25
4' and other DCs also have some of the names registered.
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{78818434-586A-4EDB-AA0D-7FF85A35206F}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{78818434-586A-4EDB-AA0D-7FF85A35206F}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Skipped
Kerberos test. . . . . . . . . . . : Passed
LDAP test. . . . . . . . . . . . . : Passed
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Passed
IPSec policy service is active, but no policy is assigned.
The command completed successfully
Слейв
DC Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial non skippeable tests
Testing server: Default-First-Site-Name\FILIAL1
Starting test: Connectivity
......................... FILIAL1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\FILIAL1
Starting test: Replications
[Replications Check,FILIAL1] A recent replication attempt failed:
From INTEL to FILIAL1
Naming Context: CN=Schema,CN=Configuration,DC=vinoonline,DC=ru
The replication generated an error (5):
Win32 Error 5
The failure occurred at 2007-03-04 14:59.04.
The last success occurred at 2006-06-02 11:54.33.
8458 failures have occurred since the last success.
[INTEL] DsBind() failed with error -2146893022,
Win32 Error -2146893022.
[Replications Check,FILIAL1] A recent replication attempt failed:
From INTEL to FILIAL1
Naming Context: CN=Configuration,DC=vinoonline,DC=ru
The replication generated an error (5):
Win32 Error 5
The failure occurred at 2007-03-04 14:59.04.
The last success occurred at 2006-06-02 11:54.33.
14484 failures have occurred since the last success.
[Replications Check,FILIAL1] A recent replication attempt failed:
From INTEL to FILIAL1
Naming Context: DC=vinoonline,DC=ru
The replication generated an error (5):
Win32 Error 5
The failure occurred at 2007-03-04 14:59.03.
The last success occurred at 2006-06-02 11:54.33.
21518 failures have occurred since the last success.
......................... FILIAL1 passed test Replications
Starting test: NCSecDesc
......................... FILIAL1 passed test NCSecDesc
Starting test: NetLogons
......................... FILIAL1 passed test NetLogons
Starting test: Advertising
......................... FILIAL1 passed test Advertising
Starting test: KnowsOfRoleHolders
Warning: INTEL is the Schema Owner, but is not responding to DS RPC Bin
d.
[INTEL] LDAP bind failed with error 31,
Win32 Error 31.
Warning: INTEL is the Schema Owner, but is not responding to LDAP Bind.
Warning: INTEL is the Domain Owner, but is not responding to DS RPC Bin
d.
Warning: INTEL is the Domain Owner, but is not responding to LDAP Bind.
Warning: INTEL is the Rid Owner, but is not responding to DS RPC Bind.
Warning: INTEL is the Rid Owner, but is not responding to LDAP Bind.
Warning: INTEL is the Infrastructure Update Owner, but is not respondin
g to DS RPC Bind.
Warning: INTEL is the Infrastructure Update Owner, but is not respondin
g to LDAP Bind.
......................... FILIAL1 failed test KnowsOfRoleHolders
Starting test: RidManager
[FILIAL1] DsBindWithCred() failed with error -2146893022. Win32 Error -
2146893022
......................... FILIAL1 failed test RidManager
Starting test: MachineAccount
......................... FILIAL1 passed test MachineAccount
Starting test: Services
Could not open SMTPSVC Service on [FILIAL1]:failed with 1060: Win32
Error 1060
......................... FILIAL1 failed test Services
Starting test: ObjectsReplicated
......................... FILIAL1 passed test ObjectsReplicated
Starting test: frssysvol
Error: No record of File Replication System, SYSVOL started.
The Active Directory may be prevented from starting.
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
......................... FILIAL1 passed test frssysvol
Starting test: kccevent
......................... FILIAL1 passed test kccevent
Starting test: systemlog
......................... FILIAL1 passed test systemlog
Running enterprise tests on : vinoonline.ru
Starting test: Intersite
......................... vinoonline.ru passed test Intersite
Starting test: FsmoCheck
......................... vinoonline.ru passed test FsmoCheck
________________________________________________________________
netdiag
.......................................
Computer Name: FILIAL1
DNS Host Name: Filial1.vinoonline.ru
System info : Windows 2000 Server (Build 2195)
Processor : x86 Family 15 Model 2 Stepping 7, GenuineIntel
List of installed hotfixes :
KB823980
KB835732
Q147222
Netcard queries test . . . . . . . : Passed
Per interface results:
Adapter : Local Area Connection
Netcard queries test . . . : Passed
Host Name. . . . . . . . . : Filial1
IP Address . . . . . . . . : 192.168.1.2
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.1.19
Primary WINS Server. . . . : 192.168.0.254
Dns Servers. . . . . . . . : 192.168.1.2
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Passed
NetBT name test. . . . . . : Passed
WINS service test. . . . . : Passed
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{998A0224-F39E-4F25-88D8-C5CA49EA183B}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Passed
NetBT name test. . . . . . . . . . : Passed
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server '192.168.1.2'
and other DCs also have some of the names registered.
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{998A0224-F39E-4F25-88D8-C5CA49EA183B}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{998A0224-F39E-4F25-88D8-C5CA49EA183B}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Failed
[WARNING] Cannot call DsBind to Intel.vinoonline.ru (192.168.0.254). [SEC_E_
WRONG_PRINCIPAL]
Trust relationship test. . . . . . : Skipped
Kerberos test. . . . . . . . . . . : Passed
LDAP test. . . . . . . . . . . . . : Passed
[WARNING] Failed to query SPN registration on DC 'Intel.vinoonline.ru'.
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Passed
IPSec policy service is active, but no policy is assigned.
The command completed successfully
_________________________________________________________________
вероятно произошла рассинхронизация доменов в связи с длительным отсутствием связи.
предположительным метод решения netdom.exe resetpwd
При помощи утилиты netdom сбросить пароль и попробовать произвести репликацию.
1.
а) если сбрасывать пароль, то это необходимо делать на сервере глобального каталога и дочернего домена
или достаточно ограничиться проблемной машиной?
б) попробовать пересоздать канал, но хотелось бы понять не приведет ли это к созданию 2 схем?
2. не уверен, что причина только в этом, просьба подсказать какие ошибки могли привести к дисфункции репликации доменов и методы их решения.
3. I need help
по каким-то причина дочерний домен назначил себя мастером PDC o_O
и машины из первого сегмента пытаются авторизоваться на дочернем домене, находящемся во втором сегменте.
может ли это быть связано с зоной обратных адресов в днс?
сейчас на обоих контроллерах домена в днс зоной обратного просмотра назначено 192.168.1.X
должна ли присутствовать обратная зона 192.168.0.x хотя бы на одном из контроллеров домена?
-
-
04.03.2007 в 15:43