G
Guest
Hello, I have 5 DC's on my Windows 2000 AD Domain. Everything was working
fine till I noticed some errors on one of the DC's and only one of them.
Please see error below:
The attempt to establish a replication link with parameters
Partition: CN=Schema,CN=Configuration,DC=mydomain,DC=com
Source DSA DN: CN=NTDS
Settings,CN=DC2,CN=Servers,CN=site1,CN=Sites,CN=Configuration,DC=mydomain,DC=com
Source DSA Address: 155ec0d0-681f-4cb8-b0a7-5b046f3fe6c4._msdcs.mydomain.com
Inter-site Transport (if any): CN=IP,CN=Inter-Site
Transports,CN=Sites,CN=Configuration,DC=mydomain,DC=com
failed with the following status:
Access is denied.
The record data is the status code. This operation will be retried.
Then I get this error,
The Directory Service consistency checker has determined that either (a) there
is not enough physical connectivity published via the Active Directory Sites
and
Services Manager to create a spanning tree connecting all the sites containing
the Partition CN=Configuration,DC=mydomain,DC=com, or (b) replication cannot
be performed with one or more
critical servers in order for changes to propagate across all sites (most
often
due to the servers being unreachable).
For (a), please use the Active Directory Sites and Services Manager to do one
of the following:
1. Publish sufficient site connectivity information such that the system can
infer a route by which this Partition can reach this site. This option is
preferred.
2. Add an ntdsConnection object to a Domain Controller that contains the
Partition CN=Configuration,DC=mydomain,DC=com in this site from a Domain
Controller that contains the same
Partition in another site.
For (b), please see previous events logged by the NTDS KCC source that
identify the servers that could not be contacted.
I don't understand where this is getting denied?? Can someone help me with
the ACCESS IS DENIED error? Everything was working fine and I didn't change
anything???
fine till I noticed some errors on one of the DC's and only one of them.
Please see error below:
The attempt to establish a replication link with parameters
Partition: CN=Schema,CN=Configuration,DC=mydomain,DC=com
Source DSA DN: CN=NTDS
Settings,CN=DC2,CN=Servers,CN=site1,CN=Sites,CN=Configuration,DC=mydomain,DC=com
Source DSA Address: 155ec0d0-681f-4cb8-b0a7-5b046f3fe6c4._msdcs.mydomain.com
Inter-site Transport (if any): CN=IP,CN=Inter-Site
Transports,CN=Sites,CN=Configuration,DC=mydomain,DC=com
failed with the following status:
Access is denied.
The record data is the status code. This operation will be retried.
Then I get this error,
The Directory Service consistency checker has determined that either (a) there
is not enough physical connectivity published via the Active Directory Sites
and
Services Manager to create a spanning tree connecting all the sites containing
the Partition CN=Configuration,DC=mydomain,DC=com, or (b) replication cannot
be performed with one or more
critical servers in order for changes to propagate across all sites (most
often
due to the servers being unreachable).
For (a), please use the Active Directory Sites and Services Manager to do one
of the following:
1. Publish sufficient site connectivity information such that the system can
infer a route by which this Partition can reach this site. This option is
preferred.
2. Add an ntdsConnection object to a Domain Controller that contains the
Partition CN=Configuration,DC=mydomain,DC=com in this site from a Domain
Controller that contains the same
Partition in another site.
For (b), please see previous events logged by the NTDS KCC source that
identify the servers that could not be contacted.
I don't understand where this is getting denied?? Can someone help me with
the ACCESS IS DENIED error? Everything was working fine and I didn't change
anything???