Forum

Addtional DC ve Cli...
 
Bildirimler
Hepsini Temizle

Addtional DC ve Client larım Domain Control a erişemiyor

20 Yazılar
3 Üyeler
0 Reactions
2,049 Görüntüleme
(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 

Merhabalar arkadaşlar;


 ADC ve clientlarım Domain controller a erişemiyor , exchange den clientlarım bir bir düşüyor ve kullanıcı adı & şifre doğrulamalarını geçemiyorlar.Domain controllerımda bir problem var. ADC ile de replikasyonda sağlamadığına eminim. DC üzerinde exchange 2007 var ve serverlarımın 2 side server 2008 eng.



Gpupdate yaptığımda da aşağıdaki hataları veriyor.

C:\Windows\system32>gpupdate /force
Updating Policy...


User policy could not be updated successfully. The following errors were encount
ered:


The processing of Group Policy failed. Windows attempted to read the file .local\sysvol\XXXXX.local\Policies\{31B2F340-016D-11D2-945F-00C04FB98
4F9}\gpt.ini from a domain controller and was not successful. Group Policy setti
ngs may not be applied until this event is resolved. This issue may be transient
 and could be caused by one or more of the following:
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller
 has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.
Computer policy could not be updated successfully. The following errors were enc
ountered:


The processing of Group Policy failed. Windows attempted to read the file \\XXXXXX


To diagnose the failure, review the event log or invoke gpmc.msc to access infor
mation about Group Policy results.

 
Gönderildi : 29/09/2009 14:40

(@bugrakeskin)
Gönderiler: 5088
Illustrious Member
 

Merhaba
DC üzerinde problemler var. Herhangi bir değişiklik oldu mu?

dcdiag ve netdiag komutlarını dc üzerinde çalıştırıp çıktısını buraya yazarsanız bi bakalım.

 
Gönderildi : 29/09/2009 15:00

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 

Copyright (c) 2006 Microsoft Corporation.  All rights reserved.


C:\Users\Administrator>dcdiag


Directory Server Diagnosis


Performing initial setup:
   Trying to find home server...
   Home Server = dc
   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests


   Testing server: Default-First-Site-Name\DC
      Starting test: Connectivity
         ......................... DC passed test Connectivity


Doing primary tests


   Testing server: Default-First-Site-Name\DC
      Starting test: Advertising
         Warning: DsGetDcName returned information for
\\adc.xxxxxx.local,
         when we were trying to reach DC.
         SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE.
         ......................... DC failed test Advertising
      Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... DC passed test FrsEvent
      Starting test: DFSREvent
         ......................... DC passed test DFSREvent
      Starting test: SysVolCheck
         ......................... DC passed test SysVolCheck
      Starting test: KccEvent
         ......................... DC passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... DC passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... DC passed test MachineAccount
      Starting test: NCSecDesc
         ......................... DC passed test NCSecDesc
      Starting test: NetLogons
         ......................... DC passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... DC passed test ObjectsReplicated
      Starting test: Replications
         [Replications Check,Replications Check] Inbound replication is
         disabled.
         To correct, run "repadmin /options DC -DISABLE_INBOUND_REPL"
         [Replications Check,DC] Outbound replication is disabled.
         To correct, run "repadmin /options DC -DISABLE_OUTBOUND_REPL"
         ......................... DC failed test Replications
      Starting test: RidManager
         ......................... DC passed test RidManager
      Starting test: Services
            w32time Service is stopped on [DC]
            NETLOGON Service is paused on [DC]
         ......................... DC failed test Services
      Starting test: SystemLog
         An Warning Event occurred.  EventID: 0x80000008
            Time Generated: 09/29/2009   11:12:46
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Warning Event occurred.  EventID: 0x80000004
            Time Generated: 09/29/2009   11:12:46
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Warning Event occurred.  EventID: 0x80000003
            Time Generated: 09/29/2009   11:12:46
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Warning Event occurred.  EventID: 0x8000001D
            Time Generated: 09/29/2009   11:14:46
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Warning Event occurred.  EventID: 0x8000A000
            Time Generated: 09/29/2009   11:15:12
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Warning Event occurred.  EventID: 0x8000A000
            Time Generated: 09/29/2009   11:15:14
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Warning Event occurred.  EventID: 0x8000A000
            Time Generated: 09/29/2009   11:15:15
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Error Event occurred.  EventID: 0xC25A002E
            Time Generated: 09/29/2009   11:15:18
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Error Event occurred.  EventID: 0x00000406
            Time Generated: 09/29/2009   11:15:36
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Error Event occurred.  EventID: 0xC0001B6F
            Time Generated: 09/29/2009   11:16:13
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Error Event occurred.  EventID: 0xC0001B70
            Time Generated: 09/29/2009   11:16:30
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Error Event occurred.  EventID: 0xC25A002E
            Time Generated: 09/29/2009   11:30:56
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Error Event occurred.  EventID: 0xC0001B6F
            Time Generated: 09/29/2009   11:30:56
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Error Event occurred.  EventID: 0xC25A002E
            Time Generated: 09/29/2009   11:31:42
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         An Error Event occurred.  EventID: 0xC0001B6F
            Time Generated: 09/29/2009   11:31:42
            EvtFormatMessage failed, error 15100 The resource loader failed to f
ind MUI file..
            (Event String (event log = System) could not be retrieved, error
            0x3afc)
         ......................... DC failed test SystemLog
      Starting test: VerifyReferences
         ......................... DC passed test VerifyReferences



   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation


   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation


   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation


   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation


   Running partition tests on : xxxxxx
      Starting test: CheckSDRefDom
         ......................... xxxxxx passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... xxxxxx passed test CrossRefValidation


   Running enterprise tests on : xxxxxx.local
      Starting test: LocatorCheck
         ......................... xxxxxx.local passed test LocatorCheck
      Starting test: Intersite
         ......................... xxxxxx.local passed test Intersite


----------------------------------------------------------------------------------------------------------------------------------------------------------------


 Ben update aldıktan sonra olduğunu düşünüyorum daha önceden çok sağlıklı çalışıyordu....


 

 
Gönderildi : 29/09/2009 15:10

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 

C:\>repadmin /showrepl


Repadmin: running command /showrepl against full DC localhost
Default-First-Site-Name\DC
DSA Options: IS_GC DISABLE_INBOUND_REPL DISABLE_OUTBOUND_REPL
Site Options: (none)
DSA object GUID: b618a1ee-0ea8-42ff-a021-fdb810dde86b
DSA invocationID: b618a1ee-0ea8-42ff-a021-fdb810dde86b


==== INBOUND NEIGHBORS ======================================


DC=xxxxxx,DC=local
    Default-First-Site-Name\ADC via RPC
        DSA object GUID: d6835c36-0c16-4577-a750-a866ddd88193
        Last attempt @ 2009-09-29 11:59:44 failed, result 8457 (0x2109):
            The destination server is currently rejecting replication requests.
        95 consecutive failure(s).
        Last success @ 2009-09-07 15:09:44.


CN=Configuration,DC=xxxxxx,DC=local
    Default-First-Site-Name\ADC via RPC
        DSA object GUID: d6835c36-0c16-4577-a750-a866ddd88193
        Last attempt @ 2009-09-29 11:59:44 failed, result 8457 (0x2109):
            The destination server is currently rejecting replication requests.
        86 consecutive failure(s).
        Last success @ 2009-09-07 14:59:29.


CN=Schema,CN=Configuration,DC=xxxxxx,DC=local
    Default-First-Site-Name\ADC via RPC
        DSA object GUID: d6835c36-0c16-4577-a750-a866ddd88193
        Last attempt @ 2009-09-29 11:59:44 failed, result 8457 (0x2109):
            The destination server is currently rejecting replication requests.
        87 consecutive failure(s).
        Last success @ 2009-09-07 14:59:29.


DC=DomainDnsZones,DC=xxxxxx,DC=local
    Default-First-Site-Name\ADC via RPC
        DSA object GUID: d6835c36-0c16-4577-a750-a866ddd88193
        Last attempt @ 2009-09-29 11:59:44 failed, result 8457 (0x2109):
            The destination server is currently rejecting replication requests.
        89 consecutive failure(s).
        Last success @ 2009-09-07 14:59:29.


DC=ForestDnsZones,DC=xxxxxx,DC=local
    Default-First-Site-Name\ADC via RPC
        DSA object GUID: d6835c36-0c16-4577-a750-a866ddd88193
        Last attempt @ 2009-09-29 11:59:44 failed, result 8457 (0x2109):
            The destination server is currently rejecting replication requests.
        87 consecutive failure(s).
        Last success @ 2009-09-07 14:59:29.


Source: Default-First-Site-Name\ADC
******* 95 CONSECUTIVE FAILURES since 2009-09-07 15:09:44
Last error: 8457 (0x2109):
            The destination server is currently rejecting replication requests.

 
Gönderildi : 29/09/2009 15:16

(@Anonim)
Gönderiler: 0
 

Merhaba,


Çıktılardan anladığım kadarıyla SYSVOL klasörünün replikasyonunda sıkıntı var.Dolayısıyla group policy problemi.AD Site and Services'den manuel replication'ı tetiklediğiniz zaman durum nedir.ADC'ye ait connectionları görebiliyormusun?

 
Gönderildi : 29/09/2009 15:24

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 




Resimdeki gibi bişeyin olması normal mi arkdaşlar , işler kontrolünden çıktı gibi bişeye anlam veremiyorum.

Yardımlarınızı bekliyorum....

 
Gönderildi : 29/09/2009 15:29

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 

Tek taraflı replikasyon oluyor , ADC DC ye erişemiyor ama DC ADC ye erişiyor.

 
Gönderildi : 29/09/2009 15:38

(@bugrakeskin)
Gönderiler: 5088
Illustrious Member
 

ADC üzerinde firewall falan mı var?

 
Gönderildi : 29/09/2009 15:41

(@Anonim)
Gönderiler: 0
 

Windows Server 2003'den 2008'e upgrade'mi yaptınız?Windows.old bundan dolayı gözüküyor.Yani bu problem ile bir alakası yok.

 
Gönderildi : 29/09/2009 15:43

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 

Event ID : "GroupPolicy 1058 " & "Security-Kerberos 4" ADC üzerinde sürekli bu hataları alıyorum. SYSVOL e erişemediği için.
Event ID :  "ActiveDirectory_DomainService 1864 Replication"  & " ActiveDirectory_DomainService 2092 Replication" DC üzerindeki Active Directory eventlarını alıyorum.

 
Gönderildi : 29/09/2009 15:46

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 

Hyr herhangi bir upgrade işlemim olmadı 2 ay önce kurulmuş temiz bir sistemdi.

Her iki server daki firewall ları tamamen stop ettim.Daha önceden de stopdu.

 
Gönderildi : 29/09/2009 16:09

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 

Arkdaşlar \\<dcipadres> yazınca paylaşımlar geliyor. ama isim yazınca gelmiyor.

 
Gönderildi : 29/09/2009 16:29

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 





Şüphelendiğim ilk 5 update yukarıda sizde uninstall etsem mi ?

 
Gönderildi : 29/09/2009 16:38

(@bugrakeskin)
Gönderiler: 5088
Illustrious Member
 

Arkdaşlar \\<dcipadres> yazınca paylaşımlar geliyor. ama isim yazınca gelmiyor.

O halde DNS inde problem var. Kontrol ettin mi bunları? Varmı bir hata?

netdiag komutu ile test etmeni yazmıştım.Etmemişsin.

Bunları kontrol etmeden sana nasıl yardımcı olabilelim. Son kullanıcı gibi bu niye çalışmıyor demekle problem çözülmez.

 
Gönderildi : 29/09/2009 16:58

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 

net stop kdc
netdom resetpwd /server:sunucu_adı /userd:etkialanı_adı\administrator /passwordd:yönetici_parolası
net start kdc


her 2 server da da yukarıdaki komutu yürüttüm  ama fayda etmedi

 
Gönderildi : 29/09/2009 17:07

(@bugrakeskin)
Gönderiler: 5088
Illustrious Member
 

Kim söyledi bu komutları kullanmanı?

 
Gönderildi : 29/09/2009 17:14

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 

C:\Program Files (x86)\Support Tools>netdiag.exe


......................................


    Computer Name: DC
    DNS Host Name: dc.xxxxxx.local
    System info : Windows Server (R) 2008 Standard (Build 6002)
    Processor : Intel64 Family 6 Model 26 Stepping 5, GenuineIntel
    Hotfixes : none detected



Netcard queries test . . . . . . . : Passed
    [WARNING] The net card 'RAS Async Adapter' may not be working because it has
 not received any packets.
    GetStats failed for 'isatap.{21C28571-184A-483F-A2C0-D4F929957639}'. [ERROR_
GEN_FAILURE]


 


Per interface results:


    Adapter : Local Area Connection


        Netcard queries test . . . : Passed


        Host Name. . . . . . . . . : dc
        IP Address . . . . . . . . : 10.0.0.12
        Subnet Mask. . . . . . . . : 255.255.255.0
        Default Gateway. . . . . . : 10.0.0.1
        Dns Servers. . . . . . . . : 10.0.0.12
                                     10.0.0.13



        AutoConfiguration results. . . . . . : Passed


        Default gateway test . . . : Passed


        NetBT name test. . . . . . : Passed
            No names have been found.


        WINS service test. . . . . : Skipped
            There are no WINS servers configured for this interface.



Global results:



Domain membership test . . . . . . : Passed



NetBT transports test. . . . . . . : Passed
    List of NetBt transports currently configured:
        NetBT_Tcpip_{21C28571-184A-483F-A2C0-D4F929957639}
    1 NetBt transport currently configured.



Autonet address test . . . . . . . : Passed



IP loopback ping test. . . . . . . : Passed



Default gateway test . . . . . . . : Passed



NetBT name test. . . . . . . . . . : Passed
    [WARNING] You don't have a single interface with the <00> 'WorkStation Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.



Winsock test . . . . . . . . . . . : Passed



DNS test . . . . . . . . . . . . . : Failed
    [FATAL] Could not open file C:\Windows\system32\config\netlogon.dns for read
ing.
    [FATAL] Could not open file C:\Windows\system32\config\netlogon.dns for read
ing.
    [FATAL] No DNS servers have the DNS records for this DC registered.



Redir and Browser test . . . . . . : Failed
    List of NetBt transports currently bound to the Redir
        NetBT_Tcpip_{21C28571-184A-483F-A2C0-D4F929957639}
    The redir is bound to 1 NetBt transport.


    List of NetBt transports currently bound to the browser
        NetBT_Tcpip_{21C28571-184A-483F-A2C0-D4F929957639}
    The browser is bound to 1 NetBt transport.
    [FATAL] Cannot send mailslot message to 'xxxxxx*' via browser. [ERROR_IN
VALID_FUNCTION]



DC discovery test. . . . . . . . . : Passed



DC list test . . . . . . . . . . . : Passed



Trust relationship test. . . . . . : Skipped



Kerberos test. . . . . . . . . . . : Failed
    [FATAL] Cannot lookup package Kerberos.
    The error occurred was: (null)



LDAP test. . . . . . . . . . . . . : Passed



Bindings test. . . . . . . . . . . : Passed



WAN configuration test . . . . . . : Skipped
    No active remote access connections.



Modem diagnostics test . . . . . . : Passed


IP Security test . . . . . . . . . : Skipped


    Note: run "netsh ipsec dynamic show /?" for more detailed information



The command completed successfully

 
Gönderildi : 29/09/2009 17:43

(@bekirakgul)
Gönderiler: 237
Reputable Member
Konu başlatıcı
 

kb288167 yardımcı olabiliceğini düşündüm.

 
Gönderildi : 29/09/2009 19:23

(@Anonim)
Gönderiler: 0
 

Hyr herhangi bir upgrade işlemim olmadı 2 ay önce kurulmuş temiz bir sistemdi.

Her iki server daki firewall ları tamamen stop ettim.Daha önceden de stopdu.


1)O zaman Windows.old'u silebilirsin.


2)Aşağıdaki yazdığın komutların yaşadığın problem ile bir alakası olmadığını düşünüyorum.Password reset komutları.


3)Şüphelendiğin KB'leri kaldırıp dene bakalım.Olmadı tekrar kurabilirsin.

 
Gönderildi : 30/09/2009 13:40

Sayfa 1 / 2
Paylaş: