Rob Golding

Technology Consultant
  • rss
  • Home
  • About
  • RSS
  • Contact

Active Directory Replication Problems

September 8, 2007

One word, or at least one acronym: GUID.

Background: I manage a multi-tree forest, with two trees, one in each of two sites. They are connected by a slow site-to-site VPN link, over which all AD replication takes place.

The domain controller at the forest-root-domain needed rebuilding, as the operating system was installed on a flaky single disk, and was due to be moved to a RAID1 array. So I thought it best to promote another DC, transfer all FSMO roles, rebuild the first, and transfer the roles back. This process went swimmingly, and the first DC was back online in no time.

However, when it came to the second site, it seemed that no replication whatsoever was taking place. After delving into AD with tools such as adsiedit and replmon, I discovered that the second DC had not “heard” about the rebuild of the first. This meant that the GUID had not been updated to hold the value of the newly installed server. The fact that I had used the same name as before didn’t help the situation at all.

In the end, it was clear that I would have to either restore the original DC from a System State backup, or rebuild the second domain from scratch. I chose the latter, as it was a small domain, and wouldn’t take very long. Now the process is complete, and we have a fully functioning forest again (after lots of metadata cleanup and /forceremoval’s!).

I won’t forget this one in a hurry - allow time for big changes to replicate before making more big changes!

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Slashdot
  • StumbleUpon
  • Technorati
Categories
Active Directory, Home Network, Technology, Windows Server
Comments rss
Comments rss
Trackback
Trackback

« Back to School! Out with Exchange, in with WSUS! »

One response

I frequent that rebuilt Domain!

Marcus Whybrow | September 8, 2007 | 2:55 pm

I frequent that rebuilt Domain!

Leave a comment

You can use these tags : <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

Oh no, I cannot read this. Please, generate a

Pages

  • About
  • RSS

Navigation

  • Active Directory
  • Exchange
  • Home Network
  • Life
  • Linux
  • Technology
  • Virtualization
  • VMware
  • Web Development
  • Windows Server

Archives

  • July 2008
  • April 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007

Recent Posts

  • Using Locally-Attached Network Printers with Terminal Services
  • Cacti and Network Weathermap
  • Restoring the Separate _msdcs Zone
  • Roadwarrior with IPCop & OpenVPN
  • New IPCop Firewall

Weathermap

rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox