Forum
Merhabalar arkadaşlar;
ADC ve clientlarım Domain controller a erişemiyor , exchange den clientlarım bir bir düşüyor ve kullanıcı adı & şifre doğrulamalarını geçemiyorlar.Domain controllerımda bir problem var. ADC ile de replikasyonda sağlamadığına eminim. DC üzerinde exchange 2007 var ve serverlarımın 2 side server 2008 eng.
Gpupdate yaptığımda da aşağıdaki hataları veriyor.
C:\Windows\system32>gpupdate /force
Updating Policy...
User policy could not be updated successfully. The following errors were encount
ered:
The processing of Group Policy failed. Windows attempted to read the file .local\sysvol\XXXXX.local\Policies\{31B2F340-016D-11D2-945F-00C04FB98
4F9}\gpt.ini from a domain controller and was not successful. Group Policy setti
ngs may not be applied until this event is resolved. This issue may be transient
and could be caused by one or more of the following:
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller
has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.
Computer policy could not be updated successfully. The following errors were enc
ountered:
The processing of Group Policy failed. Windows attempted to read the file \\XXXXXX
To diagnose the failure, review the event log or invoke gpmc.msc to access infor
mation about Group Policy results.
Merhaba
DC üzerinde problemler var. Herhangi bir değişiklik oldu mu?
dcdiag ve netdiag komutlarını dc üzerinde çalıştırıp çıktısını buraya yazarsanız bi bakalım.
Copyright (c) 2006 Microsoft Corporation. All rights reserved.
C:\Users\Administrator>dcdiag
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = dc
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\DC
Starting test: Connectivity
......................... DC passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\DC
Starting test: Advertising
Warning: DsGetDcName returned information for \\adc.xxxxxx.local,
when we were trying to reach DC.
SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE.
......................... DC failed test Advertising
Starting test: FrsEvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... DC passed test FrsEvent
Starting test: DFSREvent
......................... DC passed test DFSREvent
Starting test: SysVolCheck
......................... DC passed test SysVolCheck
Starting test: KccEvent
......................... DC passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... DC passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... DC passed test MachineAccount
Starting test: NCSecDesc
......................... DC passed test NCSecDesc
Starting test: NetLogons
......................... DC passed test NetLogons
Starting test: ObjectsReplicated
......................... DC passed test ObjectsReplicated
Starting test: Replications
[Replications Check,Replications Check] Inbound replication is
disabled.
To correct, run "repadmin /options DC -DISABLE_INBOUND_REPL"
[Replications Check,DC] Outbound replication is disabled.
To correct, run "repadmin /options DC -DISABLE_OUTBOUND_REPL"
......................... DC failed test Replications
Starting test: RidManager
......................... DC passed test RidManager
Starting test: Services
w32time Service is stopped on [DC]
NETLOGON Service is paused on [DC]
......................... DC failed test Services
Starting test: SystemLog
An Warning Event occurred. EventID: 0x80000008
Time Generated: 09/29/2009 11:12:46
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Warning Event occurred. EventID: 0x80000004
Time Generated: 09/29/2009 11:12:46
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Warning Event occurred. EventID: 0x80000003
Time Generated: 09/29/2009 11:12:46
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Warning Event occurred. EventID: 0x8000001D
Time Generated: 09/29/2009 11:14:46
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Warning Event occurred. EventID: 0x8000A000
Time Generated: 09/29/2009 11:15:12
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Warning Event occurred. EventID: 0x8000A000
Time Generated: 09/29/2009 11:15:14
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Warning Event occurred. EventID: 0x8000A000
Time Generated: 09/29/2009 11:15:15
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Error Event occurred. EventID: 0xC25A002E
Time Generated: 09/29/2009 11:15:18
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Error Event occurred. EventID: 0x00000406
Time Generated: 09/29/2009 11:15:36
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Error Event occurred. EventID: 0xC0001B6F
Time Generated: 09/29/2009 11:16:13
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Error Event occurred. EventID: 0xC0001B70
Time Generated: 09/29/2009 11:16:30
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Error Event occurred. EventID: 0xC25A002E
Time Generated: 09/29/2009 11:30:56
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Error Event occurred. EventID: 0xC0001B6F
Time Generated: 09/29/2009 11:30:56
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Error Event occurred. EventID: 0xC25A002E
Time Generated: 09/29/2009 11:31:42
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
An Error Event occurred. EventID: 0xC0001B6F
Time Generated: 09/29/2009 11:31:42
EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
(Event String (event log = System) could not be retrieved, error
0x3afc)
......................... DC failed test SystemLog
Starting test: VerifyReferences
......................... DC passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : xxxxxx
Starting test: CheckSDRefDom
......................... xxxxxx passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... xxxxxx passed test CrossRefValidation
Running enterprise tests on : xxxxxx.local
Starting test: LocatorCheck
......................... xxxxxx.local passed test LocatorCheck
Starting test: Intersite
......................... xxxxxx.local passed test Intersite
----------------------------------------------------------------------------------------------------------------------------------------------------------------
Ben update aldıktan sonra olduğunu düşünüyorum daha önceden çok sağlıklı çalışıyordu....
C:\>repadmin /showrepl
Repadmin: running command /showrepl against full DC localhost
Default-First-Site-Name\DC
DSA Options: IS_GC DISABLE_INBOUND_REPL DISABLE_OUTBOUND_REPL
Site Options: (none)
DSA object GUID: b618a1ee-0ea8-42ff-a021-fdb810dde86b
DSA invocationID: b618a1ee-0ea8-42ff-a021-fdb810dde86b
==== INBOUND NEIGHBORS ======================================
DC=xxxxxx,DC=local
Default-First-Site-Name\ADC via RPC
DSA object GUID: d6835c36-0c16-4577-a750-a866ddd88193
Last attempt @ 2009-09-29 11:59:44 failed, result 8457 (0x2109):
The destination server is currently rejecting replication requests.
95 consecutive failure(s).
Last success @ 2009-09-07 15:09:44.
CN=Configuration,DC=xxxxxx,DC=local
Default-First-Site-Name\ADC via RPC
DSA object GUID: d6835c36-0c16-4577-a750-a866ddd88193
Last attempt @ 2009-09-29 11:59:44 failed, result 8457 (0x2109):
The destination server is currently rejecting replication requests.
86 consecutive failure(s).
Last success @ 2009-09-07 14:59:29.
CN=Schema,CN=Configuration,DC=xxxxxx,DC=local
Default-First-Site-Name\ADC via RPC
DSA object GUID: d6835c36-0c16-4577-a750-a866ddd88193
Last attempt @ 2009-09-29 11:59:44 failed, result 8457 (0x2109):
The destination server is currently rejecting replication requests.
87 consecutive failure(s).
Last success @ 2009-09-07 14:59:29.
DC=DomainDnsZones,DC=xxxxxx,DC=local
Default-First-Site-Name\ADC via RPC
DSA object GUID: d6835c36-0c16-4577-a750-a866ddd88193
Last attempt @ 2009-09-29 11:59:44 failed, result 8457 (0x2109):
The destination server is currently rejecting replication requests.
89 consecutive failure(s).
Last success @ 2009-09-07 14:59:29.
DC=ForestDnsZones,DC=xxxxxx,DC=local
Default-First-Site-Name\ADC via RPC
DSA object GUID: d6835c36-0c16-4577-a750-a866ddd88193
Last attempt @ 2009-09-29 11:59:44 failed, result 8457 (0x2109):
The destination server is currently rejecting replication requests.
87 consecutive failure(s).
Last success @ 2009-09-07 14:59:29.
Source: Default-First-Site-Name\ADC
******* 95 CONSECUTIVE FAILURES since 2009-09-07 15:09:44
Last error: 8457 (0x2109):
The destination server is currently rejecting replication requests.
Merhaba,
Çıktılardan anladığım kadarıyla SYSVOL klasörünün replikasyonunda sıkıntı var.Dolayısıyla group policy problemi.AD Site and Services'den manuel replication'ı tetiklediğiniz zaman durum nedir.ADC'ye ait connectionları görebiliyormusun?
Resimdeki gibi bişeyin olması normal mi arkdaşlar , işler kontrolünden çıktı gibi bişeye anlam veremiyorum.
Yardımlarınızı bekliyorum....
Tek taraflı replikasyon oluyor , ADC DC ye erişemiyor ama DC ADC ye erişiyor.
ADC üzerinde firewall falan mı var?
Windows Server 2003'den 2008'e upgrade'mi yaptınız?Windows.old bundan dolayı gözüküyor.Yani bu problem ile bir alakası yok.
Event ID : "GroupPolicy 1058 " & "Security-Kerberos 4" ADC üzerinde sürekli bu hataları alıyorum. SYSVOL e erişemediği için.
Event ID : "ActiveDirectory_DomainService 1864 Replication" & " ActiveDirectory_DomainService 2092 Replication" DC üzerindeki Active Directory eventlarını alıyorum.
Hyr herhangi bir upgrade işlemim olmadı 2 ay önce kurulmuş temiz bir sistemdi.
Her iki server daki firewall ları tamamen stop ettim.Daha önceden de stopdu.
Arkdaşlar \\<dcipadres> yazınca paylaşımlar geliyor. ama isim yazınca gelmiyor.
Şüphelendiğim ilk 5 update yukarıda sizde uninstall etsem mi ?
Arkdaşlar \\<dcipadres> yazınca paylaşımlar geliyor. ama isim yazınca gelmiyor.
O halde DNS inde problem var. Kontrol ettin mi bunları? Varmı bir hata?
netdiag komutu ile test etmeni yazmıştım.Etmemişsin.
Bunları kontrol etmeden sana nasıl yardımcı olabilelim. Son kullanıcı gibi bu niye çalışmıyor demekle problem çözülmez.
net stop kdc
netdom resetpwd /server:sunucu_adı /userd:etkialanı_adı\administrator /passwordd:yönetici_parolası
net start kdc
her 2 server da da yukarıdaki komutu yürüttüm ama fayda etmedi
Kim söyledi bu komutları kullanmanı?
C:\Program Files (x86)\Support Tools>netdiag.exe
......................................
Computer Name: DC
DNS Host Name: dc.xxxxxx.local
System info : Windows Server (R) 2008 Standard (Build 6002)
Processor : Intel64 Family 6 Model 26 Stepping 5, GenuineIntel
Hotfixes : none detected
Netcard queries test . . . . . . . : Passed
[WARNING] The net card 'RAS Async Adapter' may not be working because it has
not received any packets.
GetStats failed for 'isatap.{21C28571-184A-483F-A2C0-D4F929957639}'. [ERROR_
GEN_FAILURE]
Per interface results:
Adapter : Local Area Connection
Netcard queries test . . . : Passed
Host Name. . . . . . . . . : dc
IP Address . . . . . . . . : 10.0.0.12
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 10.0.0.1
Dns Servers. . . . . . . . : 10.0.0.12
10.0.0.13
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Passed
NetBT name test. . . . . . : Passed
No names have been found.
WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{21C28571-184A-483F-A2C0-D4F929957639}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Passed
NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Failed
[FATAL] Could not open file C:\Windows\system32\config\netlogon.dns for read
ing.
[FATAL] Could not open file C:\Windows\system32\config\netlogon.dns for read
ing.
[FATAL] No DNS servers have the DNS records for this DC registered.
Redir and Browser test . . . . . . : Failed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{21C28571-184A-483F-A2C0-D4F929957639}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{21C28571-184A-483F-A2C0-D4F929957639}
The browser is bound to 1 NetBt transport.
[FATAL] Cannot send mailslot message to 'xxxxxx*' via browser. [ERROR_IN
VALID_FUNCTION]
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Skipped
Kerberos test. . . . . . . . . . . : Failed
[FATAL] Cannot lookup package Kerberos.
The error occurred was: (null)
LDAP test. . . . . . . . . . . . . : Passed
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Skipped
Note: run "netsh ipsec dynamic show /?" for more detailed information
The command completed successfully
kb288167 yardımcı olabiliceğini düşündüm.
Hyr herhangi bir upgrade işlemim olmadı 2 ay önce kurulmuş temiz bir sistemdi.
Her iki server daki firewall ları tamamen stop ettim.Daha önceden de stopdu.
1)O zaman Windows.old'u silebilirsin.
2)Aşağıdaki yazdığın komutların yaşadığın problem ile bir alakası olmadığını düşünüyorum.Password reset komutları.
3)Şüphelendiğin KB'leri kaldırıp dene bakalım.Olmadı tekrar kurabilirsin.