dave said:
could you please help me with my replication errors, my servers are connected
via a 512/512 adsl vpn which is working perfectly, the usernames and
passwords are replicating but i'm receiving ntds kcc 1265 "access is denied"
errors, on my second post is the dcdaig of my errors.
thanks.
Most such problems are either DNS, routing, or firewall issues.
Looking at your (following message) DCDiag one sees these
numerous replication errors but I don't see the DNS errors I
expected....but then I don't see any DNS mentioned either so
perhaps you didn't run that test or it never got that far.
Since you say "vpn is working perfectly" let's concentrate on
the DNS (but I must express doubts about such claims when
one cannot find the problem -- try explaining your routing,
firewalls, and VPN to someone else to make sure you aren't
overlooking something obvious):
DNS
1) Dynamic for the zone supporting AD
2) All internal DNS client NIC\IP properties must specify SOLELY
that internal, dynamic DNS server (set.)
3) DCs and even DNS servers are DNS clients too -- see #2
4) DNS must be fully replicated
Restart NetLogon on any DC if you change any of the above that
affects a DC.
If you are using AD Integrated DNS you are going to have to stop
that temporarily and revert to single Master (Primary or even ONE
-- at most -- AD Integrated DNS server.)
Since you already have replication errors you cannot use AD for
DNS until you fix those and get a clean replication.
If you have to return to a single Master DNS, pick one, and set
ALL DCs to use only that one DNS server, restart their NetLogon
services and check to insure they are registered with the one
DNS they ALL use. (Also set the other DNS servers as secondaries
to it temporarily.)
Check to make sure that both Servers are registered in ALL of the
DNS servers, not just the A record but all of the associated
records in the _underscore subdomains (e.g., _MSDCS, _Sites etc.)
Finally, do make sure that you can route and that you are not filtering
the DC traffic too agressively over the VPN.