Ad Replication problems - Schema Mismatch

  • Thread starter Thread starter Paul D
  • Start date Start date
P

Paul D

Hi everyone. I hope someone can help me, as I've suddenly found that I am
having terrible problems where AD does not seem to be replicating. I'll try
to explain:

There are 2 AD domain controllers. Server1 was the first AD Domain
Controller to be installed, and has PDC role. Server2 replicates AD with
Server1, and is also the DNS server for the domain.

From AD Sites and Services, under "Servers/NTDS Settings", the "Replicate
Now" command gives the following errors:
From the Server1 object ...
"The following error occurred during the attempt to synchronize the domain
controller. The replication operation failed because of a schema mismatch
between the servers involved."

From the Server2 object...
"The following error occurred during the attempt to synchronize the domain
controller. Access is denied."

Event logs for Server1...
01/07/2003 16:38:10 NTDS General Error Global Catalog 1126 NT
AUTHORITY\ANONYMOUS LOGON Server1 Unable to establish connection with global
catalog.

01/07/2003 16:38:10 NTDS General Warning Global Catalog 1655 NT
AUTHORITY\ANONYMOUS LOGON Server1 The attempt to communicate with global
catalog \\Server1.ourdomain.co.uk failed with the following status: Access
is denied.The operation in progress might be unable to continue. The
directory service will use the locator to try find an available global
catalog server for the next operation that requires one. The record data is
the status code.

01/07/2003 17:16:31 Userenv Error None 1000 NT AUTHORITY\SYSTEM Server1
Windows cannot determine the user or computer name. Return value (5).

30/06/2003 23:24:00 Userenv Error None 1000 NT AUTHORITY\SYSTEM Server1
Windows cannot query for the list of Group Policy objects . A message that
describes the reason for this was previously logged by this policy engine.

30/06/2003 23:27:54 NtFrs Warning None 13562 N/A Server1 Following is the
summary of warnings and errors encountered by File Replication Service while
polling the Domain Controller Server1.ourdomain.co.uk for FRS replica set
configuration information. Could not bind to a Domain Controller. Will try
again at next polling cycle.


I would be very grateful if someone could offer some advice.

Many thanks
Paul
 
....so, my question is really, how can I resynchonize the Global
Catalog/Active Directory between the two DCs?

Many thanks
Paul
 
Hello Paul... if you have recently ran adprep.exe you would see this error
until the schema's convirge. If you are seeing this for anyother reason I'd
be suspicious. Could you run "dcdiag.exe" and see what it reports

dcdiag.exe is a reskit tool

tx
 
Charles

They were SP3. I have just upgraded them both manually & individually to
SP4.

Many thanks
Paul
 
Paul, according to what you have done, nothing should be problematic...
could you logon to both dc's and run the following reskit tool
"repadmin.exe /showreps"

post the output or mail me directly if you don't want it seen by the world

tx
 
Jeromy

Thank you for your kind offer, Jeromy. I'll post you the results of the
command sometime within the next 12 hours (I'm not at those systems at
present).

Thanks again, and best regards
Paul
 
Jeromy

Thanks for helping with this. I hope you can deduce something from this
repadmin output, as it is beyond me, I'm afraid! :-(

Many kind regards
Paul


***Server 1***

C:\>repadmin.exe /showreps
Default-First-Site-Name\server1
DSA Options : IS_GC
objectGuid : 7cad247a-16d3-4200-aa02-c7ed82bcf6a6
invocationID: 7cad247a-16d3-4200-aa02-c7ed82bcf6a6

==== INBOUND NEIGHBORS ======================================

CN=Schema,CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.42 was successful.

CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.42 failed, result 8418:
Can't retrieve message string 8418 (0x20e2), error
Last success @ 2003-06-30 15:39.21.
2 consecutive failure(s).

DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.41 failed, result 8418:
Can't retrieve message string 8418 (0x20e2), error
Last success @ 2003-06-30 15:39.21.
2 consecutive failure(s).

==== OUTBOUND NEIGHBORS FOR CHANGE NOTIFICATIONS ============

CN=Schema,CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05

CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05

DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05


***Server 2***

C:\>repadmin.exe /showreps
Default-First-Site-Name\server1
DSA Options : IS_GC
objectGuid : 7cad247a-16d3-4200-aa02-c7ed82bcf6a6
invocationID: 7cad247a-16d3-4200-aa02-c7ed82bcf6a6

==== INBOUND NEIGHBORS ======================================

CN=Schema,CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.42 was successful.

CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.42 failed, result 8418:
Can't retrieve message string 8418 (0x20e2), error
Last success @ 2003-06-30 15:39.21.
2 consecutive failure(s).

DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.41 failed, result 8418:
Can't retrieve message string 8418 (0x20e2), error
Last success @ 2003-06-30 15:39.21.
2 consecutive failure(s).

==== OUTBOUND NEIGHBORS FOR CHANGE NOTIFICATIONS ============

CN=Schema,CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05

CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05

DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
 
Jeromy

Thanks for helping with this. I hope you can deduce something from this
repadmin output, as it is beyond me, I'm afraid! :-(

Many kind regards
Paul


***Server 1***

C:\>repadmin.exe /showreps
Default-First-Site-Name\server1
DSA Options : IS_GC
objectGuid : 7cad247a-16d3-4200-aa02-c7ed82bcf6a6
invocationID: 7cad247a-16d3-4200-aa02-c7ed82bcf6a6

==== INBOUND NEIGHBORS ======================================

CN=Schema,CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.42 was successful.

CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.42 failed, result 8418:
Can't retrieve message string 8418 (0x20e2), error
Last success @ 2003-06-30 15:39.21.
2 consecutive failure(s).

DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.41 failed, result 8418:
Can't retrieve message string 8418 (0x20e2), error
Last success @ 2003-06-30 15:39.21.
2 consecutive failure(s).

==== OUTBOUND NEIGHBORS FOR CHANGE NOTIFICATIONS ============

CN=Schema,CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05

CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05

DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05


***Server 2***

C:\>repadmin.exe /showreps
Default-First-Site-Name\server1
DSA Options : IS_GC
objectGuid : 7cad247a-16d3-4200-aa02-c7ed82bcf6a6
invocationID: 7cad247a-16d3-4200-aa02-c7ed82bcf6a6

==== INBOUND NEIGHBORS ======================================

CN=Schema,CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.42 was successful.

CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.42 failed, result 8418:
Can't retrieve message string 8418 (0x20e2), error
Last success @ 2003-06-30 15:39.21.
2 consecutive failure(s).

DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
Last attempt @ 2003-07-04 08:45.41 failed, result 8418:
Can't retrieve message string 8418 (0x20e2), error
Last success @ 2003-06-30 15:39.21.
2 consecutive failure(s).

==== OUTBOUND NEIGHBORS FOR CHANGE NOTIFICATIONS ============

CN=Schema,CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05

CN=Configuration,DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05

DC=ourdomain,DC=co,DC=uk
Default-First-Site-Name\server2 via RPC
objectGuid: 204a1a95-f6e8-4a59-96dc-806c00ec9c05
 
Dear all
Unfortunately our DNS server failed over the weekend. It was AD-integrated,
so these problems must have had implications. Hence, I rebuild the DNS
server manually.

I hope someone can give me some suggestions about how to fix this. :-(

Cheers
Paul
 
Back
Top