AD проблемы.

Обсуждение сетевых операционных систем и их применения (Windows, Linux, FreeBSD, Novell и т.д.)

Модератор: Модераторы

Администратор
Аватара пользователя
Сообщения: 2875
Зарегистрирован: 05 янв 2004, 17:21
Откуда: Москва

Сообщение GifteD » 08 апр 2004, 19:16

Два DC
В ивенте одного Directory servis постоянно

Event Type: Warning
Event Source: NTDS KCC
Event Category: (1)
Event ID: 1265
Date: 08.04.2004
Time: 18:45:28
User: N/A
Computer: JETCENTRAL1
Description:
The attempt to establish a replication link with parameters

Второй

Event Type: Warning
Event Source: NtFrs
Event Category: None
Event ID: 13508
Date: 08.04.2004
Time: 13:41:29
User: N/A
Computer: JETCENTRAL2
Description:
The File Replication Service is having trouble enabling replication from JETCENTRAL1 to JETCENTRAL2 for c:\winnt\sysvol\domain using the DNS name jetcentral1.jettravel.ru. FRS will keep retrying.
Following are some of the reasons you would see this warning.

[1] FRS can not correctly resolve the DNS name jetcentral1.jettravel.ru from this computer.
[2] FRS is not running on jetcentral1.jettravel.ru.
[3] The topology information in the Active Directory for this replica has not yet replicated to all the Domain Controllers.

This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.
Data:
0000: 0d 00 00 00 ....



Partition: CN=Configuration,DC=jettravel,DC=ru
Source DSA DN: CN=NTDS Settings,CN=JETDATA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=jettravel,DC=ru
Source DSA Address: 07ebe808-a698-4ded-ae82-dc4b27a533c7._msdcs.jettravel.ru
Inter-site Transport (if any):

failed with the following status:

The DSA operation is unable to proceed because of a DNS lookup failure.

The record data is the status code. This operation will be retried.
Data:
0000: 4c 21 00 00 L!..

На немже в system


Event Type: Error
Event Source: SAM
Event Category: None
Event ID: 16650
Date: 08.04.2004
Time: 19:09:13
User: N/A
Computer: JETCENTRAL2
Description:
The account-identifier allocator failed to initialize properly. The record data contains the NT error code that caused the failure. Windows 2000 will retry the initialization until it succeeds; until that time, account creation will be denied on this Domain Controller. Please look for other SAM event logs that may indicate the exact reason for the failure.
Data:
0000: a7 02 00 c0 §..À


dcdiag

DC Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial non skippeable tests

Testing server: Default-First-Site-Name\JETCENTRAL1
Starting test: Connectivity
......................... JETCENTRAL1 passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\JETCENTRAL1
Starting test: Replications
......................... JETCENTRAL1 passed test Replications
Starting test: NCSecDesc
......................... JETCENTRAL1 passed test NCSecDesc
Starting test: NetLogons
......................... JETCENTRAL1 passed test NetLogons
Starting test: Advertising
......................... JETCENTRAL1 passed test Advertising
Starting test: KnowsOfRoleHolders
Warning: CN="NTDS Settings
DEL:72912f8e-a6e7-4d9b-a475-1cee732d85a0",CN=JETCENTRAL2,CN=Servers,CN=Defa
irst-Site-Name,CN=Sites,CN=Configuration,DC=jettravel,DC=ru is the Schema O
but is deleted.
Warning: CN="NTDS Settings
DEL:72912f8e-a6e7-4d9b-a475-1cee732d85a0",CN=JETCENTRAL2,CN=Servers,CN=Defa
irst-Site-Name,CN=Sites,CN=Configuration,DC=jettravel,DC=ru is the Rid Owne
t is deleted.
......................... JETCENTRAL1 failed test KnowsOfRoleHolde
Starting test: RidManager
Warning: FSMO Role Owner is deleted.
......................... JETCENTRAL1 passed test RidManager
Starting test: MachineAccount
......................... JETCENTRAL1 passed test MachineAccount
Starting test: Services
......................... JETCENTRAL1 passed test Services
Starting test: ObjectsReplicated
......................... JETCENTRAL1 passed test ObjectsReplicate
Starting test: frssysvol
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
......................... JETCENTRAL1 passed test frssysvol
Starting test: kccevent
An Warning Event occured. EventID: 0x800004F1
Time Generated: 04/08/2004 19:00:28
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x800004F1
Time Generated: 04/08/2004 19:00:28
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x800004F1
Time Generated: 04/08/2004 19:00:28
(Event String could not be retrieved)
......................... JETCENTRAL1 failed test kccevent
Starting test: systemlog
An Error Event occured. EventID: 0x80001770
Time Generated: 04/08/2004 18:00:55
Event String: The System log file is full.
......................... JETCENTRAL1 failed test systemlog

Running enterprise tests on : jettravel.ru
Starting test: Intersite
......................... jettravel.ru passed test Intersite
Starting test: FsmoCheck
......................... jettravel.ru passed test FsmoCheck

netdiag
.....................................

Computer Name: JETCENTRAL1
DNS Host Name: jetcentral1.jettravel.ru
System info : Windows 2000 Server (Build 2195)
Processor : x86 Family 15 Model 2 Stepping 9, GenuineIntel
List of installed hotfixes :
Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

Adapter : Local Area Connection 2

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : jetcentral1
IP Address . . . . . . . . : 192.168.11.252
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.11.251
Dns Servers. . . . . . . . : 192.168.11.252


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed
\Device\NetBT_Tcpip_{A573AB2B-3C22-41E5-B741-DB9A8A0C9743}
[WARNING] At least one of your <03> 'Messenger Service' names is
istered properly.

WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{A573AB2B-3C22-41E5-B741-DB9A8A0C9743}
1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server '192.1
52' and other DCs also have some of the names registered.


Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{A573AB2B-3C22-41E5-B741-DB9A8A0C9743}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{A573AB2B-3C22-41E5-B741-DB9A8A0C9743}
The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed
[WARNING] Failed to query SPN registration on DC 'jetcentral2.jettrav

[WARNING] Failed to query SPN registration on DC 'jetcentral1.jettrav

[WARNING] Failed to query SPN registration on DC 'jetdata.jettravel.r


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Passed
IPSec policy service is active, but no policy is assigned.


The command completed successfully

ipconfig c первого
Windows 2000 IP Configuration

Host Name . . . . . . . . . . . . : jetcentral1
Primary DNS Suffix . . . . . . . : jettravel.ru
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : jettravel.ru

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : ASUSTeK/Broadcom 440x 10/100 Integra
ted Controller
Physical Address. . . . . . . . . : 00-0E-A6-37-8F-41
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.11.252
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.11.251
DNS Servers . . . . . . . . . . . : 192.168.11.252
Windows 2000 IP Configuration

Со второго

Host Name . . . . . . . . . . . . : jetcentral2
Primary DNS Suffix . . . . . . . : jettravel.ru
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : jettravel.ru

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel 8255x-based PCI Ethernet Adapt
er (10/100)
Physical Address. . . . . . . . . : 00-D0-B7-B7-32-B9
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.11.253
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.11.251
DNS Servers . . . . . . . . . . . : 192.168.11.252


подскажите с чего начать.

Он здесь живет
Сообщения: 2394
Зарегистрирован: 19 дек 2003, 20:43
Откуда: Москва

Сообщение Harry33 » 09 апр 2004, 11:20

Из dcdiag наблюдается отстусвие хозяина RID, схемы и прочего...
Странно как оно у тебя все работает.
1. Умирали ли контроллеры в данном домене?
Если помирали ntdsutil.exe очистка метаданных о почивших контроллерах и захват одним из серверов недостающих ролей.
Если ничего не пропадало, опиши как распределены роли Хозяина схемы, архитектуры, RID, эмулятора PDC, и GC между имеющимися контроллерами
Знания, которые нельзя применить - бесполезны

Администратор
Аватара пользователя
Сообщения: 2875
Зарегистрирован: 05 янв 2004, 17:21
Откуда: Москва

Сообщение GifteD » 09 апр 2004, 11:47

Да, действительно странно.
Да, действительно, Один из контроллеров действительно умер.
Осталось два
JETCENTRAL1 держатель GC
JETCENTRAL2

Щас запись о нем есть в остнастве Active Directory Sites and Services
в NTDS settings. Connections c него убрал, но удалить его не могу.

ntdsutil.exe Еще не разу не пробовал. Щас чувствую предстоит.

Если можешь опиши в краце как мне подстраховаца. Бекапы system state? еще что-ть?

Администратор
Сообщения: 3444
Зарегистрирован: 19 дек 2003, 13:36
Откуда: Москва

Сообщение domovoy » 09 апр 2004, 12:00

GifteD
Бэкапы в первую очередь,
Данная утилита НЕ ДАЕТ возможности отката изменений, тоесть одно не верное нажатие и ...
Правильно заданный вопрос - это уже половина ответа.

Администратор
Аватара пользователя
Сообщения: 2875
Зарегистрирован: 05 янв 2004, 17:21
Откуда: Москва

Сообщение GifteD » 12 апр 2004, 19:52

Выражаю благодарность 2 domovoy, Harry33

Вопрос стал решаться.
По горячим следам.
1. Прочитал про роли
2. Сделал бекапы.
3. Затушил "неправильный" DC. Отчистил метаданные. ntdsutil.exe
4. Перехватил роли.

Перезагрузку пока не делал DCDIAG , теперь выглядит так
DC Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial non skippeable tests

Testing server: Default-First-Site-Name\JETCENTRAL1
Starting test: Connectivity
......................... JETCENTRAL1 passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\JETCENTRAL1
Starting test: Replications
......................... JETCENTRAL1 passed test Replications
Starting test: NCSecDesc
......................... JETCENTRAL1 passed test NCSecDesc
Starting test: NetLogons
......................... JETCENTRAL1 passed test NetLogons
Starting test: Advertising
......................... JETCENTRAL1 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... JETCENTRAL1 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... JETCENTRAL1 passed test RidManager
Starting test: MachineAccount
......................... JETCENTRAL1 passed test MachineAccount
Starting test: Services
......................... JETCENTRAL1 passed test Services
Starting test: ObjectsReplicated
......................... JETCENTRAL1 passed test ObjectsReplicated
Starting test: frssysvol
Error: No record of File Replication System, SYSVOL started.
The Active Directory may be prevented from starting.
......................... JETCENTRAL1 passed test frssysvol
Starting test: kccevent
......................... JETCENTRAL1 passed test kccevent
Starting test: systemlog
......................... JETCENTRAL1 passed test systemlog

Running enterprise tests on : jettravel.ru
Starting test: Intersite
......................... jettravel.ru passed test Intersite
Starting test: FsmoCheck
......................... jettravel.ru passed test FsmoCheck

Отсталась проблема!При попытке открыть груповую политику DC получаю ошибку. Нет прав.

Он здесь живет
Сообщения: 2394
Зарегистрирован: 19 дек 2003, 20:43
Откуда: Москва

Сообщение Harry33 » 13 апр 2004, 09:49

Теперь перезапусти службу netlogon (net stop netlogon net start netlogon) на контроллере и проверь все ли записи srv на DNS правильные и указывают на твой DC
Знания, которые нельзя применить - бесполезны

Вернуться в Сетевые операционные системы

Кто сейчас на конференции

Сейчас этот форум просматривают: нет зарегистрированных пользователей и гости: 21