Adding a 3rd 2012 DC to 2 working DCs fails to populate SYSVOL and NETLOGON on the new DC
hello technet,
have read every thread deals issue technet guys blog in japanese , on ... each instance little different, of them contain lot more errors, , none of them feel right in terms of resolution.
short story, installed 3rd dc , it’s sysvol , netlogon did not populate. demoted it, created new vm new name , different ip , same result. before demote 1 , burn office ground… bottom of issue.
steps let moment:
i had s2008 based network 2 dcs since 2009. in last 3 months have replaced all servers s2012. first s2012 dc , went well. then second s2012 dc , went well. after time, took 2008 dcs off line , good. upgraded exchange /lync 2007/2010 2013 , smooth.
all of new servers gen 2 s2012 vms on hyper-v 2012 r2
last week, setup second hyper-v host replication , host 3rd dc.
by way, did not clone vms.
the new dc promotes ahem, notice sysvol , netlogon did not populate. now before promoted, ran dnslint on both dcs , passed 100%, ran dcdiag on both dcs , passed. i ran every possible dcdiag test on new member server before promoting , passed. so why dfsr fail fly?
ad objects seem populate onto new dc. can delete ad object on 1 or add , populates new dc. but sysvol , netlogon not populating
repadmin
replication summary start time: 2014-01-07 08:50:17
beginning data collection replication summary, may take awhile:
......
source dsa largest delta fails/total %% error
jefferson 59m:04s 0 / 10 0
reagan 56m:18s 0 / 10 0
roosevelt 59m:04s 0 / 10 0
destination dsa largest delta fails/total %% error
jefferson 01m:18s 0 / 10 0
reagan 59m:05s 0 / 10 0
roosevelt 56m:19s 0 / 10 0
(one warning here, got bored planets , opted presidents time, no political preference here =))
roosevelt pdc
jefferson second dc working “ok”
reagan new dc
c:\users\darthvader>domain query fsmo
schema master jefferson.domain.com
domain naming master jefferson.domain.com
pdc roosevelt.domain.com
rid pool manager roosevelt.domain.com
infrastructure master jefferson.domain.com
what setting missing here? short of setting 4th dc on same hyper-v host… prefer resolve issue because can’t find communication issues between 2 hosts. both plugged same switch, latest drivers, both have intel quad port nics, , other forms of communication ok between...and other 25 hosts plugged switch communicate ok. i ran ping , file transfer test , no dropped packets.
would appreciate before open case msft. below info want see, sorry if i’m leaving out details or assuming know something, have not slept in few days.
here link dcdiag ipconfig , dnslint reports: reports
thank you.
success guys,
here other thread on spiceworks
success!!! , boy, hope helps else out. know i'm not first 1 go thru this, have replication netlogon issues different underlying reasons... hope you!
bottom line there corrupted folder under c:\windows\sysvol\domain\policies\ preventing replication happening correctly.
past part here...first, went jefferson , test deleted corrupted object taking ownership of it. before did that, checked inheritance properties of subfolders. subfolders set inherit go.
ran situation, file loaded , being used "system" , not kill process... not take ownership of 100% did on jefferson.
do...in middle of d4 , need reboot! pdc?! had no choice, have backups... go it. rebooted , came code dreaming of step 9: dfsr 4604! proceeded rest of steps , jefferson replicated, , .... 4604 on reagan , net share revealed have been after, sysvol , netlogon shared!
not fixed this, found underlying issue causing problem start with.
if reading or in x years, before go d4/d2 restore:
- check dns inside , out, following great advise in thread semicolon recommend leaving ipv6 on... pretty part of our lives these days
- check sites , services
- check nslookup , if see unknown ??? need go ipv6 , set dns automatically. if server unknown - go dns , setup ptr records dcs
- in group policy management click on domain , status tab, click detect @ bottom right , see if have servers replication in progress. if have underlying issue, have gpo out of sync.
- recreated gpo , deleted corrupt 1 synced gpo before able perform authoritative restore. problem folder still there , messed me during restore can see previous post
- go gp , document gpos. uid , cross reference against folders under c:\windows\sysvol\domain\policies\ , if find orphaned one.. rid of taking ownership of , deleted moon.
- go ahead , follow this http:/
/ carefully.support.microsoft.com/ kb/ 2218556 - should it... , luck!
Windows Server > Directory Services
Comments
Post a Comment