Search

Adre Blog

  • Welcome
  • About
  • Connections
  • RSS
DC

Replication error 1699 on Windows 2003

Posted by: Seb

28

May

One of my domain controllers has encountered a problem that caused replication errors on the other DCs. In the event viewer of my other two controllers I got the following error every few minutes:

Event Type: Error
Event Source: NTDS Replication
Event Category: Replication
Event ID: 1699
User: CORP \ DC01 $
Computer: DC02
Description:
The local domain controller failed to retrieve the changes requested for the following directory partition. Consequently, it could not send change requests to the domain controller at the following network address.

Directory partition:
DC = corp, DC = local, DC = com
Network Address:
0c03a47c-75e2-4745-b632-6a0671731f28._msdcs.corp.local.com
Extended request code:
0

Additional data
Error value:
The 8453 Replication access was denied.

System Center Operations Manager 2007 I also recovered errors, indicating that replication was slow or not working on some domain controllers.

When I tried to force replication from DC01 in Active Directory Sites and Services I got an error "The replication operation failed due to incorrect matching patterns between the servers involved." From DC02 or DC03 I got a success message "Active Directory has replicated the connections".
Continue reading "Replication error 1699 on Windows 2003"

Tags: Active Directory , Domain Controller , Replication , Windows 2003
4 comments

Configure an authoritative time server in Windows 2003

Posted by: Seb

29

August

In a field it is important that the clocks of all machines are synchronized. Indeed the Kerberos authentication protocol default requires a maximum difference of 5 minutes ENTERED clocks to prevent attacks.

If authentication was based solely on a username and a password it would be theoretically possible for an attacker to record network traffic, extract data and replay them to the server. The Kerberos session keys are unique and based on the client's time, which avoids these attacks if the maximum permissible difference is relatively small.

To be certain that all clocks are synchronized with each other it is necessary to define an authoritative time source. It is possible to configure the domain controller PDC operation master so that it becomes a source of stratum 2 time source synchronizing to a Stratum 1 time (usually a time server based on an atomic clock) .


Continue reading "Setting up an authoritative time server in Windows 2003"

Tags: domain controller , Kerberos , NTP , Windows 2003
4 comments

Problem of replication of SYSVOL and NETLOGON shares

Posted by: Seb

28

August

I recently installed two new domain controllers in Windows 2003 R2 to replace an old Domain Controller in Windows 2000 which showed some signs of weakness. Problem, after the usual phase of dcpromo the SYSVOL and NETLOGON shares have not created automatically on two new CDs. FSMO role transfers them have gone smoothly and Active Directory (users, computers) and the DNS replicate perfectly.

This problem is really critical because if the domain controller in Windows 2000 should die it would not be possible to authenticate to the field or on the SQL Server using Windows authentication. A very regular backup system state with ntbackup of DC is critical as the situation is not stabilized. Second group policies are not replicated and servers are not fully considered as domain controllers SYSVOL and NETLOGON shares have not been created.

Continue reading "Problem replication of SYSVOL and NETLOGON shares"

Tags: Active Directory , Domain Controller , netlogon , replication , sysvol , Windows 2003
5 comments

Translator

French flagItalian flagChinese (Simplified) flagEnglish flagGerman flagSpanish flagJapanese flagArabic flagRussian flagNorwegian flag

Keywords

Backup Remote Office Domain Controller Deployment Disaster Recovery Linux Software Monitoring MySQL OpenVPN Operations Manager 2007 pfSense PHP RAID Replication SQL Server SQL Server 2005 VPN Windows 2003 WSUS

Meta

  • Registration
  • Log in
  • RSS feed of articles
  • Comments RSS
  • WordPress.org

Blogs updated

  • SQL Fool

    Close the preview

    Loading ...
  • The Deployment Guys

    Close the preview

    Loading ...
  • Benedict Sautière

    Close the preview

    Loading ...
  • Advisec Blog

    Close the preview

    Loading ...
  • Ask the Directory Services Team

    Close the preview

    Loading ...
  • Fabrice Meillon

    Close the preview

    Loading ...
  • MSSQL Tips

    Close the preview

    Loading ...
  • CSS SQL Server Engineers

    Close the preview

    Loading ...
  • SQL Server Storage Engine

    Close the preview

    Loading ...
  • I Want Some Moore

    Close the preview

    Loading ...
  • The WSUS Support Team

    Close the preview

    Loading ...
  • Stephen Papp

    Close the preview

    Loading ...
  • Windows Networking

    Close the preview

    Loading ...
  • Blogmotion

    Close the preview

    Loading ...

Recent Topics

  • Aligning partitions for SQL Server
  • Merging two SVN repositories on Ubuntu
  • Using SSH and Remote Desktop with Visio
  • Managing backups files and MySQL on Ubuntu
  • Restore an iPhone 3G iOS 4 to 3.1.3 on Snow Leopard
  • Installing a LAMP on Ubuntu Dedibox

Recent Comments

  • Mana in Configure a time server do ...
  • julia in Installing and configuring WS ...
  • Oni in Installing a LAMP Dedibox penny ...
  • Emilie in Restoring an iPhone 3G iOS 4 to ...
  • Machine and contol in five common tasks administratio ...
  • kornemuz in Configure a time server do ...

Topics most commented

  • Restore an iPhone 3G iOS 4 to 3.1.3 on Snow Leopard - 54
  • Installing Cacti on Windows / IIS 6 - 23
  • Error installing WSUS 3.0 SP2 - 12
  • pfsense and OpenVPN for road warriors - 11
  • Installing and configuring WSUS 3.0 SP2 - 9
  • Installing a LAMP on Ubuntu Dedibox - 7