ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Solved DCs out of sync

    IT Discussion
    active directory replication recovery
    4
    14
    2.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • thwrT
      thwr
      last edited by thwr

      Well, looks like that my little problem yesterday (full harddrive on DC-2) caused more trouble than expected: My two DCs are out of sync now, and the second one even refuses to start AD services. Replication log / status lists quite a few lingering objects, Kerberos ticket issues and so on. The faulty DC is powered off right now to prevent user issues and further damage.

      No substantial changes have been made during the last couple of weeks. Just a few new users and password changes plus maybe 2 or 3 new machine accounts. Some clients and servers now refuse to authenticate users during login due to the well known "trust could not be established between..." error.

      I'm just trying to figure out how to fix this in an "elegant" way. Problem: I'll be out of office for the next two days because I will attend to a project meeting some hundred kilometers to the south. My train will depart in 3 hours. Murphy.

      Possible approaches:

      • My plan is to leave the faulty DC powered off and deploy a new DC and (hard) remove the faulty one when the new DC is in sync with the working DC.
      • Or should I better try to reanimate the dead one?

      Any thoughts about this?

      I'm aware that I might loose some AD objects, but that's ok. Like I said, it's just about a few accounts etc.

      PS: The working one is confirmed to be the one with the most current replication state. No wonder.

      DashrenderD 1 Reply Last reply Reply Quote 2
      • scottalanmillerS
        scottalanmiller
        last edited by

        Anytime something happens to a DC to get out of sync, just rebuild fresh.

        thwrT 1 Reply Last reply Reply Quote 1
        • thwrT
          thwr @scottalanmiller
          last edited by

          @scottalanmiller said in DCs out of sync:

          Anytime something happens to a DC to get out of sync, just rebuild fresh.

          So you would just deploy a new DC?

          1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller
            last edited by

            Yes, new DC would be my choice. No worries of lingering problems.

            thwrT 1 Reply Last reply Reply Quote 0
            • thwrT
              thwr @scottalanmiller
              last edited by

              @scottalanmiller said in DCs out of sync:

              Yes, new DC would be my choice. No worries of lingering problems.

              That's what I'm always praying. But better safe than sorry, that's why I asked. Thanks Scott.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                Good luck, and enjoy your trip!

                thwrT 1 Reply Last reply Reply Quote 0
                • thwrT
                  thwr @scottalanmiller
                  last edited by

                  @scottalanmiller said in DCs out of sync:

                  Good luck, and enjoy your trip!

                  Thanks. dcpromo looks good so far. Waiting for the reboot.

                  Still one hour left until I need to leave to catch the train 😉

                  thwrT 1 Reply Last reply Reply Quote 0
                  • thwrT
                    thwr @thwr
                    last edited by

                    @thwr said in DCs out of sync:

                    @scottalanmiller said in DCs out of sync:

                    Good luck, and enjoy your trip!

                    Thanks. dcpromo looks good so far. Waiting for the reboot.

                    Still one hour left until I need to leave to catch the train 😉

                    And... done

                    repadmin /showrepl does not show any errors. Same for dcdiag, which only complains about minor things as far as I can tell right now.

                    1 Reply Last reply Reply Quote 1
                    • scottalanmillerS
                      scottalanmiller
                      last edited by

                      Cool

                      1 Reply Last reply Reply Quote 0
                      • StrongBadS
                        StrongBad
                        last edited by

                        I think that I'm too late, but I concur that rebuilding is better than trying to find a way to recover the out of sync node - just not worth it.

                        thwrT 1 Reply Last reply Reply Quote 1
                        • thwrT
                          thwr @StrongBad
                          last edited by

                          @StrongBad said in DCs out of sync:

                          I think that I'm too late, but I concur that rebuilding is better than trying to find a way to recover the out of sync node - just not worth it.

                          That's the point. As long as you still have a working DC, issues are better solved by depolying a new machine.

                          1 Reply Last reply Reply Quote 2
                          • DashrenderD
                            Dashrender @thwr
                            last edited by

                            @thwr said in DCs out of sync:

                            No substantial changes have been made during the last couple of weeks. Just a few new users and password changes plus maybe 2 or 3 new machine accounts. Some clients and servers now refuse to authenticate users during login due to the well known "trust could not be established between..." error.

                            Where you still getting those errors after you powered down the broken DC? I'm guessing not since you moved forward with the install of another DC.

                            thwrT 1 Reply Last reply Reply Quote 0
                            • thwrT
                              thwr @Dashrender
                              last edited by

                              @Dashrender said in DCs out of sync:

                              @thwr said in DCs out of sync:

                              No substantial changes have been made during the last couple of weeks. Just a few new users and password changes plus maybe 2 or 3 new machine accounts. Some clients and servers now refuse to authenticate users during login due to the well known "trust could not be established between..." error.

                              Where you still getting those errors after you powered down the broken DC? I'm guessing not since you moved forward with the install of another DC.

                              Nope. Only "missing that other DC" errors now, which is fine. I've got some crappy internet connection (free WiFi in the train, next to no 3G/4G signal) here and can't check the current state. but it was fine half an our ago.

                              DashrenderD 1 Reply Last reply Reply Quote 0
                              • DashrenderD
                                Dashrender @thwr
                                last edited by

                                @thwr said in DCs out of sync:

                                @Dashrender said in DCs out of sync:

                                @thwr said in DCs out of sync:

                                No substantial changes have been made during the last couple of weeks. Just a few new users and password changes plus maybe 2 or 3 new machine accounts. Some clients and servers now refuse to authenticate users during login due to the well known "trust could not be established between..." error.

                                Where you still getting those errors after you powered down the broken DC? I'm guessing not since you moved forward with the install of another DC.

                                Nope. Only "missing that other DC" errors now, which is fine. I've got some crappy internet connection (free WiFi in the train, next to no 3G/4G signal) here and can't check the current state. but it was fine half an our ago.

                                OK, reading your OP, it seemed that you were getting those errors after turning off the broken DC, but since you're not - seems like you found a good solution.

                                1 Reply Last reply Reply Quote 0
                                • 1 / 1
                                • First post
                                  Last post