SOLVED
Home

Server 2012R2 AD access and replication problems

%3CLINGO-SUB%20id%3D%22lingo-sub-224629%22%20slang%3D%22en-US%22%3EServer%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224629%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20Server%202012R2%20which%20has%20several%20symptoms%20related%20to%20AD%20access%20and%20replication.%26nbsp%3B%20Here%20are%20some%20examples%20and%20some%20related%20event%20log%20descriptions%3A%3C%2FP%3E%3CP%3EGPMC%20cannot%20connect%20to%20the%20AD.%3C%2FP%3E%3CP%3EDFRS%20replication%20fails%20-%26nbsp%3BError%3A%201726%20(The%20remote%20procedure%20call%20failed.)%3C%2FP%3E%3CP%3ESMB%20outbound%20connections%20sometimes%20fail%20-%26nbsp%3BThe%20Kerberos%20client%20received%20a%20KRB_AP_ERR_MODIFIED%20error%20from%20the%20target%20server.%3C%2FP%3E%3CP%3EKnowledge%20Consistency%20Checker%20(KCC)%20was%20unable%20to%20form%20a%20complete%20spanning%20tree%20network%20topology.%3C%2FP%3E%3CP%3EDNS%20-%26nbsp%3BThe%20DNS%20server%20has%20encountered%20a%20critical%20error%20from%20the%20Active%20Directory.%20Check%20that%20the%20Active%20Directory%20is%20functioning%20properly.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20server%20is%20a%202012R2%20Hyper-V%20guest%2C%20it%20was%20hosted%20on%20a%20Fujitsu%20server%202012R2.%26nbsp%3B%20It%20has%20been%20moved%20(VHD%20only)%20to%20a%20Dell%20server%202016%20host%2C%20with%20a%20new%20vNIC%20and%20Hyper-V%20switch.%26nbsp%3B%20The%20problems%20described%20show%20no%20change%20both%20before%20and%20after%20the%20move.%26nbsp%3B%20The%20SYSVOL%20share%20seems%20to%20be%20normal.%26nbsp%3B%20The%20Windows%20firewall%20has%20been%20disabled.%26nbsp%3B%20SFC%20%2FSCANNOW%20and%20DISM%20healthchecks%20and%20restores%20have%20been%20completed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESome%20help%20would%20be%20appreciated!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-224629%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-227037%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-227037%22%20slang%3D%22en-US%22%3E%3CP%3EGlad%20to%20hear.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-227000%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-227000%22%20slang%3D%22en-US%22%3E%3CP%3EDave%2C%20an%20MTU%20adjustment%20was%20required%20on%20the%20VPN%20appliances%20and%20replication%20is%20looking%20much%20better.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20your%20help!%3C%2FP%3E%3CP%3EBob%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-225261%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-225261%22%20slang%3D%22en-US%22%3E%3CP%3E%3CEM%3EThe%20inter%20site%20tests%20looked%20to%20be%20completely%20failing.%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EI'd%20agree.%20I'd%20get%20in%20touch%20with%20your%20inter-site%20network%20support%20group.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-225260%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-225260%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%2C%20The%20portqryui%20tool%20is%20new%20to%20me%20and%20the%20results%20are%20in%20the%20OneDrive%20already%20shared.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERunning%20the%20tool%20at%20the%20AD1%20site%20locally%20gave%20what%20looked%20like%20good%20results%20to%26nbsp%3BLDAP%20queries%2C%26nbsp%3BTCP%20port%20389%2C%26nbsp%3BUDP%20port%20389%2C%26nbsp%3BTCP%20port%20636%2C%20and%20TCP%20port%203268%3B%20NETBIOS%26nbsp%3BUDP%20port%20137%20but%20no%20others.%26nbsp%3B%20The%20inter%20site%20tests%20looked%20to%20be%20completely%20failing.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-225191%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-225191%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20dcdiag%20you%20ran%20from%26nbsp%3B%3CSPAN%3ELGNAD1%20is%20totally%20unaware%20of%20the%20new%20DC%20(LGNAD4)%20you%20added%20in%20other%20network%20plus%20it%20cannot%20connect%20to%20LGNAD2.%20I%20don't%20know%20how%20long%20ago%20this%20might%20have%20happened.%20Seems%20there%20is%20some%20blocking%20going%20on.%20One%20method%20would%20be%20to%20use%20PortQryUI%20tool%20to%20check%20domains%20and%20trusts%20ports.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D24009%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D24009%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3Etool%20does%20not%20install%20anything%2C%20just%20extract%20and%20run%20it.%20I'd%20try%20between%20two%20on%20the%26nbsp%3B192.168.100.xxx%20network%20so%20you%20know%20what%20to%20expect%2C%20then%20run%20from%26nbsp%3BLGNAD1%20--%26gt%3B%26nbsp%3BLGNAD2%20and%26nbsp%3BLGNAD2--%26gt%3BLGNAD1%20%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-225051%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-225051%22%20slang%3D%22en-US%22%3E%3CP%3EDave%2C%20your%20diagnosis%20has%20been%20similar%20to%20mine%20and%26nbsp%3BI%20have%20also%20suspected%20a%20routing%20problem%20between%20the%20sites%20but%20extended%20pings%20look%20good%2C%20SMB%20file%20transfers%20are%20normal%20for%20the%20cross%20site%20shares%20which%20are%20available%2C%20and%20we%20are%20keeping%20routing%20as%20a%20potential%20cause.%3C%2FP%3E%3CP%3EHowever%20I%20do%20not%20understand%20how%20a%20site%20connection%20issue%20would%20affect%20AD%20operation%20within%20the%20one%20LGNAD1%20site%2C%20GPMC%20will%20not%20load%20since%20it%20cannot%20connect%20and%20I%20cannot%20add%20a%20second%20DC.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-224753%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224753%22%20slang%3D%22en-US%22%3E%3CP%3EThere%20may%20be%20routing%20issues%20between%20the%20two%20networks.%3C%2FP%3E%0A%3CDIV%3E192.168.1.254%3C%2FDIV%3E%0A%3CDIV%3E192.168.100.254%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-224751%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224751%22%20slang%3D%22en-US%22%3E%3CP%3EI%20agree%20that%26nbsp%3Bthe%26nbsp%3Bmost%20immediate%20problem%20appears%20to%20be%20connectivity%20with%20LGNAD2%2C%20however%20LGNAD2%20is%20in%20a%20AD%20site%20with%26nbsp%3Bno%20local%20issues%2C%20LGNAD4%20was%20added%20to%20the%20same%20site%20very%20recently%20with%20no%20problems.%26nbsp%3B%20I%20am%20unable%20to%20add%20another%20DC%20to%20the%20problem%20site%20alongside%20LGNAD1.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20comparison%20I%20have%20added%20dcdiag2.txt%20and%20dc2.txt%20to%20the%20same%20OneDrive%20share.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20again%2C%3C%2FP%3E%3CP%3EBob%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-224701%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224701%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20most%20immediate%20problem%20appears%20to%20be%20connectivity%20with%26nbsp%3B%3CSTRONG%3ELGNAD2%3C%2FSTRONG%3E%20If%20this%20domain%20controller%20has%20been%20forcefully%20removed%20or%20no%20longer%20available%20then%20you%20can%20seize%20roles%20(if%20needed)%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F255504%2Fusing-ntdsutil-exe-to-transfer-or-seize-fsmo-roles-to-a-domain-control%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F255504%2Fusing-ntdsutil-exe-to-transfer-or-seize-fsmo-roles-to-a-domain-control%3C%2FA%3E%3C%2FP%3E%0A%3CP%3Eand%20perform%20cleanup.%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fprevious-versions%2Fwindows%2Fit-pro%2Fwindows-server-2008-R2-and-2008%2Fcc816907(v%3Dws.10)%23bkmk_graphical%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fprevious-versions%2Fwindows%2Fit-pro%2Fwindows-server-2008-R2-and-2008%2Fcc816907(v%3Dws.10)%23bkmk_graphical%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-224684%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224684%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Dave%2C%20here%20are%20the%20files%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fpremiercomputerservices-my.sharepoint.com%2F%3Af%3A%2Fg%2Fpersonal%2Fbob_oswin_com%2FEpsocGG7CwlMm2qdMpfcKHgBNKCBbHl9mUKnlQSQguHN1Q%3Fe%3DCKpvib%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fpremiercomputerservices-my.sharepoint.com%2F%3Af%3A%2Fg%2Fpersonal%2Fbob_oswin_com%2FEpsocGG7CwlMm2qdMpfcKHgBNKCBbHl9mUKnlQSQguHN1Q%3Fe%3DCKpvib%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3EBob%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-224651%22%20slang%3D%22en-US%22%3ERe%3A%20Server%202012R2%20AD%20access%20and%20replication%20problems%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224651%22%20slang%3D%22en-US%22%3E%3CP%3EY%3CSPAN%3Eou%20can%20run%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EDcdiag%20%2Fv%20%2Fc%20%2Fd%20%2Fe%20%2Fs%3ADCName%20%26gt%3Bc%3A%5Cdcdiag.log%20%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E(please%20replace%20%3CSTRONG%3EDCName%3C%2FSTRONG%3E%20with%20your%20domain%20controller's%20netbios%20name)%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3Eipconfig%20%2Fall%20%26gt%3B%20C%3A%5Cdc1.txt%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3Ethen%20put%20files%20up%20on%20OneDrive%20and%20share%20a%20link.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Bob Smith
Occasional Contributor

I have a Server 2012R2 which has several symptoms related to AD access and replication.  Here are some examples and some related event log descriptions:

GPMC cannot connect to the AD.

DFRS replication fails - Error: 1726 (The remote procedure call failed.)

SMB outbound connections sometimes fail - The Kerberos client received a KRB_AP_ERR_MODIFIED error from the target server.

Knowledge Consistency Checker (KCC) was unable to form a complete spanning tree network topology.

DNS - The DNS server has encountered a critical error from the Active Directory. Check that the Active Directory is functioning properly.

 

The server is a 2012R2 Hyper-V guest, it was hosted on a Fujitsu server 2012R2.  It has been moved (VHD only) to a Dell server 2016 host, with a new vNIC and Hyper-V switch.  The problems described show no change both before and after the move.  The SYSVOL share seems to be normal.  The Windows firewall has been disabled.  SFC /SCANNOW and DISM healthchecks and restores have been completed.

 

Some help would be appreciated!

 

 

11 Replies

You can run;

Dcdiag /v /c /d /e /s:DCName >c:\dcdiag.log

(please replace DCName with your domain controller's netbios name)

ipconfig /all > C:\dc1.txt

then put files up on OneDrive and share a link.

 

 

 

Highlighted

The most immediate problem appears to be connectivity with LGNAD2 If this domain controller has been forcefully removed or no longer available then you can seize roles (if needed)

https://support.microsoft.com/en-us/help/255504/using-ntdsutil-exe-to-transfer-or-seize-fsmo-roles-t...

and perform cleanup.

https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc...

 

 

I agree that the most immediate problem appears to be connectivity with LGNAD2, however LGNAD2 is in a AD site with no local issues, LGNAD4 was added to the same site very recently with no problems.  I am unable to add another DC to the problem site alongside LGNAD1.

 

For comparison I have added dcdiag2.txt and dc2.txt to the same OneDrive share.

 

Thanks again,

Bob

There may be routing issues between the two networks.

192.168.1.254
192.168.100.254
 
 
 

Dave, your diagnosis has been similar to mine and I have also suspected a routing problem between the sites but extended pings look good, SMB file transfers are normal for the cross site shares which are available, and we are keeping routing as a potential cause.

However I do not understand how a site connection issue would affect AD operation within the one LGNAD1 site, GPMC will not load since it cannot connect and I cannot add a second DC.

Solution

The dcdiag you ran from LGNAD1 is totally unaware of the new DC (LGNAD4) you added in other network plus it cannot connect to LGNAD2. I don't know how long ago this might have happened. Seems there is some blocking going on. One method would be to use PortQryUI tool to check domains and trusts ports.

https://www.microsoft.com/en-us/download/details.aspx?id=24009

tool does not install anything, just extract and run it. I'd try between two on the 192.168.100.xxx network so you know what to expect, then run from LGNAD1 --> LGNAD2 and LGNAD2-->LGNAD1

 

 

 

Thanks, The portqryui tool is new to me and the results are in the OneDrive already shared.

 

Running the tool at the AD1 site locally gave what looked like good results to LDAP queries, TCP port 389, UDP port 389, TCP port 636, and TCP port 3268; NETBIOS UDP port 137 but no others.  The inter site tests looked to be completely failing.

The inter site tests looked to be completely failing.

I'd agree. I'd get in touch with your inter-site network support group.

 

 

 

Dave, an MTU adjustment was required on the VPN appliances and replication is looking much better.

 

Thanks for your help!

Bob

 

Glad to hear.

 

 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies