Wsador
02-09-2012, 18:22
Добрый вечер.
Досталась ситуация с проблемным доменом. В сети сети были 2 КД(физический и виртуальный). Физический сломался - перенесли все роли на виртуальный. Установили новый дополнительный физический КД.Сейчас на него не реплицируются NETLOGON и SYSVOL.
Вот dcdiag c виртуального КД vdc
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = VDC
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\VDC
Starting test: Connectivity
......................... VDC passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\VDC
Starting test: Advertising
......................... VDC passed test Advertising
Starting test: FrsEvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... VDC failed test FrsEvent
Starting test: DFSREvent
......................... VDC passed test DFSREvent
Starting test: SysVolCheck
......................... VDC passed test SysVolCheck
Starting test: KccEvent
......................... VDC passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... VDC passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... VDC passed test MachineAccount
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=DomainDnsZones,DC=srv,DC=local
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ForestDnsZones,DC=srv,DC=local
......................... VDC failed test NCSecDesc
Starting test: NetLogons
......................... VDC passed test NetLogons
Starting test: ObjectsReplicated
......................... VDC passed test ObjectsReplicated
Starting test: Replications
......................... VDC passed test Replications
Starting test: RidManager
......................... VDC passed test RidManager
Starting test: Services
......................... VDC passed test Services
Starting test: SystemLog
......................... VDC passed test SystemLog
Starting test: VerifyReferences
......................... VDC passed test VerifyReferences
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : srv
Starting test: CheckSDRefDom
......................... srv passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... srv passed test CrossRefValidation
Running enterprise tests on : srv.local
Starting test: LocatorCheck
......................... srv.local passed test LocatorCheck
Starting test: Intersite
......................... srv.local passed test Intersite
Вот dcdiag c нового физического КД adc:
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = adc
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\ADC
Starting test: Connectivity
......................... ADC passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\ADC
Starting test: Advertising
Warning: DsGetDcName returned information for \\VDC.srv.local, when we
were trying to reach ADC.
SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE.
......................... ADC failed test Advertising
Starting test: FrsEvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... ADC passed test FrsEvent
Starting test: DFSREvent
......................... ADC passed test DFSREvent
Starting test: SysVolCheck
......................... ADC passed test SysVolCheck
Starting test: KccEvent
......................... ADC passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... ADC passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... ADC passed test MachineAccount
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ForestDnsZones,DC=srv,DC=local
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=DomainDnsZones,DC=srv,DC=local
......................... ADC failed test NCSecDesc
Starting test: NetLogons
Unable to connect to the NETLOGON share! (\\ADC\netlogon)
[ADC] An net use or LsaPolicy operation failed with error 67,
The network name cannot be found..
......................... ADC failed test NetLogons
Starting test: ObjectsReplicated
......................... ADC passed test ObjectsReplicated
Starting test: Replications
......................... ADC passed test Replications
Starting test: RidManager
......................... ADC passed test RidManager
Starting test: Services
......................... ADC passed test Services
Starting test: SystemLog
......................... ADC passed test SystemLog
Starting test: VerifyReferences
......................... ADC passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : srv
Starting test: CheckSDRefDom
......................... srv passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... srv passed test CrossRefValidation
Running enterprise tests on : srv.local
Starting test: LocatorCheck
......................... srv.local passed test LocatorCheck
Starting test: Intersite
......................... srv.local passed test Intersite
Как поправить репликацию?На новом КД по имени \\adc нет папок SYSVOL и NETLOGON
Досталась ситуация с проблемным доменом. В сети сети были 2 КД(физический и виртуальный). Физический сломался - перенесли все роли на виртуальный. Установили новый дополнительный физический КД.Сейчас на него не реплицируются NETLOGON и SYSVOL.
Вот dcdiag c виртуального КД vdc
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = VDC
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\VDC
Starting test: Connectivity
......................... VDC passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\VDC
Starting test: Advertising
......................... VDC passed test Advertising
Starting test: FrsEvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... VDC failed test FrsEvent
Starting test: DFSREvent
......................... VDC passed test DFSREvent
Starting test: SysVolCheck
......................... VDC passed test SysVolCheck
Starting test: KccEvent
......................... VDC passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... VDC passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... VDC passed test MachineAccount
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=DomainDnsZones,DC=srv,DC=local
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ForestDnsZones,DC=srv,DC=local
......................... VDC failed test NCSecDesc
Starting test: NetLogons
......................... VDC passed test NetLogons
Starting test: ObjectsReplicated
......................... VDC passed test ObjectsReplicated
Starting test: Replications
......................... VDC passed test Replications
Starting test: RidManager
......................... VDC passed test RidManager
Starting test: Services
......................... VDC passed test Services
Starting test: SystemLog
......................... VDC passed test SystemLog
Starting test: VerifyReferences
......................... VDC passed test VerifyReferences
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : srv
Starting test: CheckSDRefDom
......................... srv passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... srv passed test CrossRefValidation
Running enterprise tests on : srv.local
Starting test: LocatorCheck
......................... srv.local passed test LocatorCheck
Starting test: Intersite
......................... srv.local passed test Intersite
Вот dcdiag c нового физического КД adc:
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = adc
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\ADC
Starting test: Connectivity
......................... ADC passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\ADC
Starting test: Advertising
Warning: DsGetDcName returned information for \\VDC.srv.local, when we
were trying to reach ADC.
SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE.
......................... ADC failed test Advertising
Starting test: FrsEvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... ADC passed test FrsEvent
Starting test: DFSREvent
......................... ADC passed test DFSREvent
Starting test: SysVolCheck
......................... ADC passed test SysVolCheck
Starting test: KccEvent
......................... ADC passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... ADC passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... ADC passed test MachineAccount
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ForestDnsZones,DC=srv,DC=local
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=DomainDnsZones,DC=srv,DC=local
......................... ADC failed test NCSecDesc
Starting test: NetLogons
Unable to connect to the NETLOGON share! (\\ADC\netlogon)
[ADC] An net use or LsaPolicy operation failed with error 67,
The network name cannot be found..
......................... ADC failed test NetLogons
Starting test: ObjectsReplicated
......................... ADC passed test ObjectsReplicated
Starting test: Replications
......................... ADC passed test Replications
Starting test: RidManager
......................... ADC passed test RidManager
Starting test: Services
......................... ADC passed test Services
Starting test: SystemLog
......................... ADC passed test SystemLog
Starting test: VerifyReferences
......................... ADC passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : srv
Starting test: CheckSDRefDom
......................... srv passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... srv passed test CrossRefValidation
Running enterprise tests on : srv.local
Starting test: LocatorCheck
......................... srv.local passed test LocatorCheck
Starting test: Intersite
......................... srv.local passed test Intersite
Как поправить репликацию?На новом КД по имени \\adc нет папок SYSVOL и NETLOGON