ADs not Syncing

%3CLINGO-SUB%20id%3D%22lingo-sub-2073287%22%20slang%3D%22en-US%22%3EADs%20not%20Syncing%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2073287%22%20slang%3D%22en-US%22%3E%3CP%3EBrief%20description%20of%20the%20issue%3A%3C%2FP%3E%3CP%3EPrimary%20DC1%20(unhealthy)%20is%20not%20syncing%20to%20Secondary%20DC2%20(healthy)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELong%20description%3A%3C%2FP%3E%3CP%3EWe%20have%202%20VM%20DCs%20in%20our%20domain%20where%20the%20main%20is%20DC1%20running%20on%20Windows%20Server%202008%20R2%2C%20and%20our%20secondary%20DC2%20running%20on%20Windows%20Server%202012.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20suspect%20that%20our%20DC1%20is%20not%20syncing%20to%20our%20DC2%20due%20to%20the%20reasons%20below%3A%3C%2FP%3E%3CP%3E1)%20When%20DC2%20is%20down%20or%20offline%2C%20no%20one%20can%20authenticate.%3C%2FP%3E%3CP%3E2)%20Netlogon%20is%20paused%20and%20Windows%20Time%20service%20stopped.%3C%2FP%3E%3CP%3E3)%20Sysvol%20folder%20of%20DC1%20and%20DC2%20are%20not%20in%20sync%20on%20both%20sides%20(e.g.%20I%20create%20a%20file%2Ffolder%20on%20either%20side%20and%20it%20doesn't%20sync)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdditional%20info%3A%3C%2FP%3E%3CP%3E1)%20DC1%20has%202%20NICs%20and%202%20IPs%20on%202%20different%20VLANs%20because%20we%20use%20it%20as%20a%20file%20server%20as%20well.%20Not%20sure%20if%20this%20would%20have%20an%20impact%20to%20how%20AD%20works%20but%20I%20did%20set%20the%20NIC%20priority%20manually.%3C%2FP%3E%3CP%3E2)%20DC1%20is%20a%20file%20server%20and%20all%20home%20profiles%20and%20GPOs%20points%20back%20to%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20questions%20are%3A%3C%2FP%3E%3CP%3E1)%20How%20to%20confirm%20which%20DC%20is%20healthy%20and%20up-to-date%3F%20I%20assume%20my%20suspicions%20are%20correct%20but%20I'm%20not%20an%20expert.%3C%2FP%3E%3CP%3E2)%20How%20to%20search%20for%20clues%20to%20determine%20root%20cause%20and%20the%20next%20course%20of%20action%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPossible%20solutions%20I%20can%20think%20of%20and%20as%20per%20research%3A%3C%2FP%3E%3CP%3E1)%20Demote%20DC1%20and%20do%20metadata%20cleanup.%20After%20which%20we%20can%20add%20a%20new%20DC3%20running%20Windows%20Server%202016%20DC%20and%20make%20it%20primary.%20Problem%20with%20this%20though%20is%20that%20all%20home%20profiles%20and%20GPOs%20link%20back%20to%20DC1.%20(I%20did%20try%20this%20before%20but%20DC2%20wouldn't%20sync%20to%20the%20new%20DC3)%3C%2FP%3E%3CP%3E2)%20Create%20a%20new%20forest%20in%20a%20new%20DC%20and%20migrate%20the%20existing%20domain%20to%20it.%20Not%20sure%20if%20I%20can%20use%20the%20same%20domain%20name%20or%20how%20the%20existing%20computers%20would%20work%20without%20rejoining%20them%20to%20the%20new%20domain%20if%20ever.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHoping%20to%20get%20some%20help%20by%20pointing%20me%20to%20the%20right%20direction.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2073287%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2074392%22%20slang%3D%22en-US%22%3ERe%3A%20ADs%20not%20Syncing%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2074392%22%20slang%3D%22en-US%22%3E%3CP%3EMulti-homing%20a%20domain%20controller%20always%20causes%20no%20end%20to%20grief%20for%20active%20directory%20domain%20DNS.%20So%20that's%20the%20first%20issue%20to%20clear%20up%2C%20then%20do%20%3CSTRONG%3Eipconfig%20%2Fflushds%2C%20ipconfig%20%2Fregisterdns%3C%2FSTRONG%3E%2C%20restart%20the%20netlogon%20service.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EDepending%20on%20how%20long%20this%20situation%20has%20lasted%20the%202012%20may%20also%20have%20tombstoned%20in%20which%20case%20demoting%2C%20reboot%2C%20promo%20it%20again%20may%20be%20the%20simpler%20solution%20after%20above%20is%20corrected.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2077740%22%20slang%3D%22en-US%22%3ERe%3A%20ADs%20not%20Syncing%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2077740%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F51719%22%20target%3D%22_blank%22%3E%40Dave%20Patrick%3C%2FA%3E%26nbsp%3B%2C%20appreciate%20you%20helping%20me%20on%20this%20and%20for%20the%20lightning%20fast%20response.%3C%2FP%3E%3CP%3EI%20will%20test%20your%20advise%20in%20an%20isolated%20environment%20and%20let%20you%20know%20the%20outcome.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMore%20info%3A%3C%2FP%3E%3CP%3EI%20also%20see%20the%20following%20in%20event%20viewer.%3C%2FP%3E%3CP%3EEvent%202103%3A%3CBR%20%2F%3EThe%20Active%20Directory%20Domain%20Services%20database%20has%20been%20restored%20using%20an%20unsupported%20restoration%20procedure.%3CBR%20%2F%3EActive%20Directory%20Domain%20Services%20will%20be%20unable%20to%20log%20on%20users%20while%20this%20condition%20persists.%20As%20a%20result%2C%20the%20Net%20Logon%20service%20has%20paused.%3CBR%20%2F%3EUser%20Action%3CBR%20%2F%3ESee%20previous%20event%20logs%20for%20details.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20suspect%20this%20is%20due%20to%20the%20VM%20being%20rolled%20back%20to%20its%20previous%20state%20via%20snapshot.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20my%20test%20environment%2C%20tried%20deleting%20the%20registry%20key%20%22%3CSPAN%3EDSA%20not%20writable%3C%2FSPAN%3E%22%20from%26nbsp%3B%3CSPAN%3EHKLM%5CSystem%5CCurrentControlSet%5CServices%5CNTDS%5CParameters%20and%20it%20did%20resolve%20the%20NetLogon%20and%20Windows%20Time%20service%20issues%20but%20I'm%20not%20sure%20if%20it's%20the%20best%20thing%20to%20do.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EMy%20ultimate%20goal%20is%20to%20eventually%20remove%20DC1%20from%20the%20domain%20and%20add%20in%20a%20new%20primary%20DC%20running%202016%20or%202019.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2078099%22%20slang%3D%22en-US%22%3ERe%3A%20ADs%20not%20Syncing%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2078099%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F51719%22%20target%3D%22_blank%22%3E%40Dave%20Patrick%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20trying%20your%20recommendation%20in%20the%20test%20environment%2C%20it%20seems%20like%20I%20have%20now%20lost%20access%20to%20DC2%20and%20getting%20the%20error%20below%3A%3C%2FP%3E%3CP%3ELog%20Name%3A%20Directory%20Service%3CBR%20%2F%3ESource%3A%20Microsoft-Windows-ActiveDirectory_DomainService%3CBR%20%2F%3EDate%3A%2020%2F1%2F2021%205%3A38%3A01%20PM%3CBR%20%2F%3EEvent%20ID%3A%201308%3CBR%20%2F%3ETask%20Category%3A%20Knowledge%20Consistency%20Checker%3CBR%20%2F%3ELevel%3A%20Warning%3CBR%20%2F%3EKeywords%3A%20Classic%3CBR%20%2F%3EUser%3A%20ANONYMOUS%20LOGON%3CBR%20%2F%3EComputer%3A%20DC1.domain.name%3CBR%20%2F%3EDescription%3A%3CBR%20%2F%3EThe%20Knowledge%20Consistency%20Checker%20(KCC)%20has%20detected%20that%20successive%20attempts%20to%20replicate%20with%20the%20following%20directory%20service%20has%20consistently%20failed.%3CBR%20%2F%3E%3CBR%20%2F%3EAttempts%3A%3CBR%20%2F%3E4%3CBR%20%2F%3EDirectory%20service%3A%3CBR%20%2F%3ECN%3DNTDS%20Settings%2CCN%3DDC2%2CCN%3DServers%2CCN%3DDefault-First-Site-Name%2CCN%3DSites%2CCN%3DConfiguration%2CDC%3Ddomain%2CDC%3Dname%2CDC%3Dnet%3CBR%20%2F%3EPeriod%20of%20time%20(minutes)%3A%3CBR%20%2F%3E88989%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20Connection%20object%20for%20this%20directory%20service%20will%20be%20ignored%2C%20and%20a%20new%20temporary%20connection%20will%20be%20established%20to%20ensure%20that%20replication%20continues.%20Once%20replication%20with%20this%20directory%20service%20resumes%2C%20the%20temporary%20connection%20will%20be%20removed.%3CBR%20%2F%3E%3CBR%20%2F%3EAdditional%20Data%3CBR%20%2F%3EError%20value%3A%3CBR%20%2F%3E5%20Access%20is%20denied.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere's%20what%20I%20did%20to%20remove%20multi-homing%3A%3C%2FP%3E%3CP%3E1)%20Removed%20other%20and%20unused%20NICs%20in%20the%20system%20via%20device%20manager%3C%2FP%3E%3CP%3E2)%20Ran%26nbsp%3B%3CSTRONG%3Eipconfig%20%2Fflushdns%2C%20ipconfig%20%2Fregisterdns%26nbsp%3B%3C%2FSTRONG%3E%20and%20restarted%20NetLogon%20services%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EQuestion%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E1)%20Would%20it%20be%20easier%20to%20setup%20a%20new%20DC%20then%20promote%20it%20as%20the%20main%20then%20remove%20DC1%3F%3C%2FP%3E%3CP%3E2)%20Or%20do%20I%20have%20to%20fix%20the%20issue%20with%20DC1%20first%20before%20I%20can%20do%20anything%20else%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2078658%22%20slang%3D%22en-US%22%3ERe%3A%20ADs%20not%20Syncing%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2078658%22%20slang%3D%22en-US%22%3E%3CP%3EPlease%20run%3B%3C%2FP%3E%0A%3CP%3EDcdiag%20%2Fv%20%2Fc%20%2Fd%20%2Fe%20%2Fs%3A%25computername%25%20%26gt%3Bc%3A%5Cdcdiag.log%3CBR%20%2F%3Erepadmin%20%2Fshowrepl%20%26gt%3BC%3A%5Crepl.txt%3CBR%20%2F%3Eipconfig%20%2Fall%20%26gt%3B%20C%3A%5Cdc1.txt%3CBR%20%2F%3Eipconfig%20%2Fall%20%26gt%3B%20C%3A%5Cdc2.txt%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3Ethen%20put%20%60unzipped%60%20text%20files%20up%20on%20%3CA%20href%3D%22https%3A%2F%2Fonedrive.live.com%2Fabout%2Fen-us%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EOneDrive%3C%2FA%3E%20and%20share%20a%20link.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Brief description of the issue:

Primary DC1 (unhealthy) is not syncing to Secondary DC2 (healthy)

 

Long description:

We have 2 VM DCs in our domain where the main is DC1 running on Windows Server 2008 R2, and our secondary DC2 running on Windows Server 2012.

 

I suspect that our DC1 is not syncing to our DC2 due to the reasons below:

1) When DC2 is down or offline, no one can authenticate.

2) Netlogon is paused and Windows Time service stopped.

3) Sysvol folder of DC1 and DC2 are not in sync on both sides (e.g. I create a file/folder on either side and it doesn't sync)

 

Additional info:

1) DC1 has 2 NICs and 2 IPs on 2 different VLANs because we use it as a file server as well. Not sure if this would have an impact to how AD works but I did set the NIC priority manually.

2) DC1 is a file server and all home profiles and GPOs points back to it.

 

My questions are:

1) How to confirm which DC is healthy and up-to-date? I assume my suspicions are correct but I'm not an expert.

2) How to search for clues to determine root cause and the next course of action? 

 

Possible solutions I can think of and as per research:

1) Demote DC1 and do metadata cleanup. After which we can add a new DC3 running Windows Server 2016 DC and make it primary. Problem with this though is that all home profiles and GPOs link back to DC1. (I did try this before but DC2 wouldn't sync to the new DC3)

2) Create a new forest in a new DC and migrate the existing domain to it. Not sure if I can use the same domain name or how the existing computers would work without rejoining them to the new domain if ever.

 

Hoping to get some help by pointing me to the right direction.

13 Replies

Multi-homing a domain controller always causes no end to grief for active directory domain DNS. So that's the first issue to clear up, then do ipconfig /flushds, ipconfig /registerdns, restart the netlogon service.

 

Depending on how long this situation has lasted the 2012 may also have tombstoned in which case demoting, reboot, promo it again may be the simpler solution after above is corrected.

 

As to stopped services I'd check the system event log for details.

 

 

 

 

 

 

@Dave Patrick , appreciate you helping me on this and for the lightning fast response.

I will test your advise in an isolated environment and let you know the outcome.

 

More info:

I also see the following in event viewer.

Event 2103:
The Active Directory Domain Services database has been restored using an unsupported restoration procedure.
Active Directory Domain Services will be unable to log on users while this condition persists. As a result, the Net Logon service has paused.
User Action
See previous event logs for details.

 

I suspect this is due to the VM being rolled back to its previous state via snapshot.

 

In my test environment, tried deleting the registry key "DSA not writable" from HKLM\System\CurrentControlSet\Services\NTDS\Parameters and it did resolve the NetLogon and Windows Time service issues but I'm not sure if it's the best thing to do.

 

My ultimate goal is to eventually remove DC1 from the domain and add in a new primary DC running 2016 or 2019.

@Dave Patrick 

After trying your recommendation in the test environment, it seems like I have now lost access to DC2 and getting the error below:

Log Name: Directory Service
Source: Microsoft-Windows-ActiveDirectory_DomainService
Date: 20/1/2021 5:38:01 PM
Event ID: 1308
Task Category: Knowledge Consistency Checker
Level: Warning
Keywords: Classic
User: ANONYMOUS LOGON
Computer: DC1.domain.name
Description:
The Knowledge Consistency Checker (KCC) has detected that successive attempts to replicate with the following directory service has consistently failed.

Attempts:
4
Directory service:
CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=name,DC=net
Period of time (minutes):
88989

The Connection object for this directory service will be ignored, and a new temporary connection will be established to ensure that replication continues. Once replication with this directory service resumes, the temporary connection will be removed.

Additional Data
Error value:
5 Access is denied.

 

Here's what I did to remove multi-homing:

1) Removed other and unused NICs in the system via device manager

2) Ran ipconfig /flushdns, ipconfig /registerdns  and restarted NetLogon services

 

 

Question:

1) Would it be easier to setup a new DC then promote it as the main then remove DC1?

2) Or do I have to fix the issue with DC1 first before I can do anything else?

Please run;

Dcdiag /v /c /d /e /s:%computername% >c:\dcdiag.log
repadmin /showrepl >C:\repl.txt
ipconfig /all > C:\dc1.txt
ipconfig /all > C:\dc2.txt


then put `unzipped` text files up on OneDrive and share a link.

 

 

 

 

 

Glad to hear problem is sorted.

 

 

 

@Dave Patrick 

Actually we still haven't solved anything yet. 

What I meant on my PM was that I got the test environment working properly (meaning I don't get that access denied error message) after I recreated it. But we're yet to fix the ADs not synching. Kindly help check the logs you've requested and advise what I need to check on my end.

Please don't edit the files.

 

 

@Dave Patrick 

Files updated. 

Please check again

PBA-DC-01 is multi-homed. Multi-homing will always cause no end to grief for active directory DNS. After correcting this issue do an ipconfig /flushdns, ipconfig /registerdns and restart the netlogon service. If problems persist then put up a new set of files to look at.

 

 

 

@Dave Patrick 

Done. Files have been updated.

Please note that the files were taken from the test environment which is not connected to the internet.

PBA-DC-02 is missing a default gateway

NETLOGON Service is paused on [PBA-DC-01] this one is problematic. I'd check the event log for reasons why.

 IsmServ Service is stopped on [PBA-DC-02] (Intersite Messaging) this one is problematic. I'd check the event log for reasons why.

Windows Time Service [PBA-DC-02] should be auto start

 

 

@Dave Patrick 

@Dave Patrick 

Please see my response below in red font.

 

PBA-DC-02 is missing a default gateway

I think this wouldn't matter in the test environment but I have added the gateway anyway

 

NETLOGON Service is paused on [PBA-DC-01] this one is problematic. I'd check the event log for reasons why.  

I see the following in Event Viewer:

Log Name: Directory Service
Source: Microsoft-Windows-ActiveDirectory_DomainService
Date: 25/1/2021 10:53:45 AM
Event ID: 2103
Task Category: Service Control
Level: Error
Keywords: Classic
User: ANONYMOUS LOGON
Computer: PBA-DC-01.windows.pbagroup.net
Description:
The Active Directory Domain Services database has been restored using an unsupported restoration procedure.

Active Directory Domain Services will be unable to log on users while this condition persists. As a result, the Net Logon service has paused.

User Action
See previous event logs for details.

I think the above is due to the VM being rolled-back using a snapshot.

 

I also see warning events 2886 and 1539 but I think these are not so critical.

 

 IsmServ Service is stopped on [PBA-DC-02] (Intersite Messaging) this one is problematic. I'd check the event log for reasons why.

Service seems to be running when I checked.

 

Windows Time Service [PBA-DC-02] should be auto start

Service startup type set to automatic. Don't recall setting it to manual previously though.

 

Please advise on how to proceed in fixing the other errors/issues.

Thanks in advance!

I'd probably abandon that one, seize roles to another healthy one

Transfer or seize FSMO roles - Windows Server | Microsoft Docs

 

the perform cleanup to remove the failed one.

Clean up AD DS server metadata | Microsoft Docs
Step-By-Step: Manually Removing A Domain Controller Server (microsoft.com)

 

then stand up a new one for replacement.

 

(please don't forget to mark helpful replies)