AD域控制器管理出错

[复制链接]
查看11 | 回复8 | 2005-10-30 17:05:33 | 显示全部楼层 |阅读模式
AD中,两台域控制失去联系有一个星期了,现在重新连接,一是AD复制不成,二是没法去管理另一个域控制器,提示RPC服务器不可用,我看services中,RPC服务全开了,为什么?
回复

使用道具 举报

千问 | 2005-10-30 17:05:33 | 显示全部楼层
You can try the following articles:
A. http://support.microsoft.com/default.aspx?scid=kb;en-us;257187
B. Maybe Lingering object issue, http://support.microsoft.com/default.aspx?scid=kb;en-us;317097
If still failed, please upload the whole Event Log and use DCDIAG.exe /v test the DC.
回复

使用道具 举报

千问 | 2005-10-30 17:05:33 | 显示全部楼层
DC Diagnosis
Performing initial setup:
* Verifing that the local machine testerbdc, is a DC.
* Connecting to directory service on server testerbdc.
* Collecting site info.
* Identifying all servers.
* Found 2 DC(s). Testing 1 of them.
Done gathering initial info.
Doing initial non skippeable tests

Testing server: Default-First-Site-Name\testerBDC
Starting test: Connectivity
* Active Directory LDAP Services Check
* Active Directory RPC Services Check
......................... testerBDC passed test Connectivity
Doing primary tests

Testing server: Default-First-Site-Name\testerBDC
Starting test: Replications
* Replications Check
[Replications Check,testerBDC] A recent replication attempt failed:

From tester to testerBDC

Naming Context: CN=Schema,CN=Configuration,DC=cogel,DC=com

The replication generated an error (8524):

由于 DNS 查找故障,DSA 操作无法进行。

The failure occurred at 2002-12-08 16:27.44.

The last success occurred at 2002-12-01 17:49.55.

67 failures have occurred since the last success.

The guid-based DNS name 3728f463-5c0b-47f1-86c5-89211a937cd8._msdcs.tester.com

is not registered on one or more DNS servers.
[Replications Check,testerBDC] A recent replication attempt failed:

From tester to testerBDC

Naming Context: CN=Configuration,DC=cogel,DC=com

The replication generated an error (8524):

由于 DNS 查找故障,DSA 操作无法进行。

The failure occurred at 2002-12-08 15:59.19.

The last success occurred at 2002-12-01 17:49.54.

66 failures have occurred since the last success.

The guid-based DNS name 3728f463-5c0b-47f1-86c5-89211a937cd8._msdcs.tester.com

is not registered on one or more DNS servers.
[Replications Check,testerBDC] A recent replication attempt failed:

From tester to testerBDC

Naming Context: DC=cogel,DC=com

The replication generated an error (8524):

由于 DNS 查找故障,DSA 操作无法进行。

The failure occurred at 2002-12-08 15:59.19.

The last success occurred at 2002-12-01 17:49.54.

66 failures have occurred since the last success.

The guid-based DNS name 3728f463-5c0b-47f1-86c5-89211a937cd8._msdcs.tester.com

is not registered on one or more DNS servers.
......................... testerBDC passed test Replications
Test omitted by user request: Topology
Test omitted by user request: CutoffServers
Starting test: NCSecDesc
* Security Permissions Check for
CN=Schema,CN=Configuration,DC=cogel,DC=com
* Security Permissions Check for
CN=Configuration,DC=cogel,DC=com
* Security Permissions Check for
DC=cogel,DC=com
......................... testerBDC passed test NCSecDesc
Starting test: NetLogons
* Network Logons Privileges Check
......................... testerBDC passed test NetLogons
Starting test: Advertising
The DC testerBDC is advertising itself as a DC and having a DS.
The DC testerBDC is advertising as an LDAP server
The DC testerBDC is advertising as having a writeable directory
The DC testerBDC is advertising as a Key Distribution Center
The DC testerBDC is advertising as a time server
The DS testerBDC is advertising as a GC.
......................... testerBDC passed test Advertising
Starting test: KnowsOfRoleHolders
Role Schema Owner = CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com
Role Domain Owner = CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com
Role PDC Owner = CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com
Role Rid Owner = CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com
Role Infrastructure Update Owner = CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com
......................... testerBDC passed test KnowsOfRoleHolders
Starting test: RidManager
* Available RID Pool for the Domain is 3100 to 1073741823
* testerbdc.tester.com is the RID Master
* DsBind with RID Master was successful
* rIDAllocationPool is 1100 to 1599
* rIDNextRID: 1116
* rIDPreviousAllocationPool is 1100 to 1599
......................... testerBDC passed test RidManager
Starting test: MachineAccount
* SPN found :LDAP/testerbdc.tester.com/tester.com
* SPN found :LDAP/testerbdc.tester.com
* SPN found :LDAP/testerBDC
* SPN found :LDAP/testerbdc.tester.com/COGEL
* SPN found :LDAP/44e98ae2-50d0-4b1d-bc0a-3eee32b2e3ae._msdcs.tester.com
* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/44e98ae2-50d0-4b1d-bc0a-3eee32b2e3ae/tester.com
* SPN found :HOST/testerbdc.tester.com/tester.com
* SPN found :HOST/testerbdc.tester.com
* SPN found :HOST/testerBDC
* SPN found :HOST/testerbdc.tester.com/COGEL
* SPN found :GC/testerbdc.tester.com/tester.com
......................... testerBDC passed test MachineAccount
Starting test: Services
* Checking Service: Dnscache
* Checking Service: NtFrs
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: RpcSs
* Checking Service: RPCLOCATOR
* Checking Service: w32time
* Checking Service: TrkWks
* Checking Service: TrkSvr
* Checking Service: NETLOGON
* Checking Service: Dnscache
* Checking Service: NtFrs
......................... testerBDC passed test Services
Test omitted by user request: OutboundSecureChannels
Starting test: ObjectsReplicated
testerBDC is in domain DC=cogel,DC=com
Checking for CN=testerBDC,OU=Domain Controllers,DC=cogel,DC=com in domain DC=cogel,DC=com on 1 servers

Object is up-to-date on all servers.
Checking for CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com in domain CN=Configuration,DC=cogel,DC=com on 1 servers

Object is up-to-date on all servers.
......................... testerBDC passed test ObjectsReplicated
Starting test: frssysvol
* The File Replication Service Event log test
The SYSVOL has been shared, and the AD is no longer
prevented from starting by the File Replication Service.
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
An Warning Event occured.EventID: 0x800034C4

Time Generated: 12/08/2002 15:19:33

(Event String could not be retrieved)
An Warning Event occured.EventID: 0x800034C4

Time Generated: 12/08/2002 15:19:34

(Event String could not be retrieved)
......................... testerBDC passed test frssysvol
Starting test: kccevent
* The KCC Event log test
Found no KCC errors in Directory Service Event log in the last 15 minutes.
......................... testerBDC passed test kccevent
Starting test: systemlog
* The System Event log test
An Error Event occured.EventID: 0xC0000031

Time Generated: 12/08/2002 16:40:03

Event String: An unexpected error occured while trying to start
the server. The port may already be in use.
An Error Event occured.EventID: 0xC0000031

Time Generated: 12/08/2002 16:40:13

Event String: An unexpected error occured while trying to start
the server. The port may already be in use.
......................... testerBDC failed test systemlog

Running enterprise tests on : tester.com
Starting test: Intersite
Skipping site Default-First-Site-Name, this site is outside the scope
provided by the command line arguments provided.
......................... tester.com passed test Intersite
Starting test: FsmoCheck
GC Name: \\testerbdc.tester.com
Locator Flags: 0xe00001fd
PDC Name: \\testerbdc.tester.com
Locator Flags: 0xe00001fd
Time Server Name: \\testerbdc.tester.com
Locator Flags: 0xe00001fd
Preferred Time Server Name: \\testerbdc.tester.com
Locator Flags: 0xe00001fd
KDC Name: \\testerbdc.tester.com
Locator Flags: 0xe00001fd
......................... tester.com passed test FsmoCheck
回复

使用道具 举报

千问 | 2005-10-30 17:05:33 | 显示全部楼层
DC Diagnosis
Performing initial setup:
* Verifing that the local machine testerbdc, is a DC.
* Connecting to directory service on server testerbdc.
* Collecting site info.
* Identifying all servers.
* Found 2 DC(s). Testing 1 of them.
Done gathering initial info.
Doing initial non skippeable tests

Testing server: Default-First-Site-Name\testerBDC
Starting test: Connectivity
* Active Directory LDAP Services Check
* Active Directory RPC Services Check
......................... testerBDC passed test Connectivity
Doing primary tests

Testing server: Default-First-Site-Name\testerBDC
Starting test: Replications
* Replications Check
[Replications Check,testerBDC] A recent replication attempt failed:

From tester to testerBDC

Naming Context: CN=Configuration,DC=cogel,DC=com

The replication generated an error (8418):

由于有关服务器之间的架构不匹配,复制操作失败。

The failure occurred at 2002-12-08 16:59.19.

The last success occurred at 2002-12-01 17:49.54.

67 failures have occurred since the last success.
[Replications Check,testerBDC] A recent replication attempt failed:

From tester to testerBDC

Naming Context: DC=cogel,DC=com

The replication generated an error (8418):

由于有关服务器之间的架构不匹配,复制操作失败。

The failure occurred at 2002-12-08 16:59.19.

The last success occurred at 2002-12-01 17:49.54.

67 failures have occurred since the last success.
......................... testerBDC passed test Replications
Test omitted by user request: Topology
Test omitted by user request: CutoffServers
Starting test: NCSecDesc
* Security Permissions Check for
CN=Schema,CN=Configuration,DC=cogel,DC=com
* Security Permissions Check for
CN=Configuration,DC=cogel,DC=com
* Security Permissions Check for
DC=cogel,DC=com
......................... testerBDC passed test NCSecDesc
Starting test: NetLogons
* Network Logons Privileges Check
......................... testerBDC passed test NetLogons
Starting test: Advertising
The DC testerBDC is advertising itself as a DC and having a DS.
The DC testerBDC is advertising as an LDAP server
The DC testerBDC is advertising as having a writeable directory
The DC testerBDC is advertising as a Key Distribution Center
The DC testerBDC is advertising as a time server
The DS testerBDC is advertising as a GC.
......................... testerBDC passed test Advertising
Starting test: KnowsOfRoleHolders
Role Schema Owner = CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com
Role Domain Owner = CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com
Role PDC Owner = CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com
Role Rid Owner = CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com
Role Infrastructure Update Owner = CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com
......................... testerBDC passed test KnowsOfRoleHolders
Starting test: RidManager
* Available RID Pool for the Domain is 3100 to 1073741823
* testerbdc.tester.com is the RID Master
* DsBind with RID Master was successful
* rIDAllocationPool is 1100 to 1599
* rIDNextRID: 1116
* rIDPreviousAllocationPool is 1100 to 1599
......................... testerBDC passed test RidManager
Starting test: MachineAccount
* SPN found :LDAP/testerbdc.tester.com/tester.com
* SPN found :LDAP/testerbdc.tester.com
* SPN found :LDAP/testerBDC
* SPN found :LDAP/testerbdc.tester.com/COGEL
* SPN found :LDAP/44e98ae2-50d0-4b1d-bc0a-3eee32b2e3ae._msdcs.tester.com
* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/44e98ae2-50d0-4b1d-bc0a-3eee32b2e3ae/tester.com
* SPN found :HOST/testerbdc.tester.com/tester.com
* SPN found :HOST/testerbdc.tester.com
* SPN found :HOST/testerBDC
* SPN found :HOST/testerbdc.tester.com/COGEL
* SPN found :GC/testerbdc.tester.com/tester.com
......................... testerBDC passed test MachineAccount
Starting test: Services
* Checking Service: Dnscache
* Checking Service: NtFrs
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: RpcSs
* Checking Service: RPCLOCATOR
* Checking Service: w32time
* Checking Service: TrkWks
* Checking Service: TrkSvr
* Checking Service: NETLOGON
* Checking Service: Dnscache
* Checking Service: NtFrs
......................... testerBDC passed test Services
Test omitted by user request: OutboundSecureChannels
Starting test: ObjectsReplicated
testerBDC is in domain DC=cogel,DC=com
Checking for CN=testerBDC,OU=Domain Controllers,DC=cogel,DC=com in domain DC=cogel,DC=com on 1 servers

Object is up-to-date on all servers.
Checking for CN=NTDS Settings,CN=testerBDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=cogel,DC=com in domain CN=Configuration,DC=cogel,DC=com on 1 servers

Object is up-to-date on all servers.
......................... testerBDC passed test ObjectsReplicated
Starting test: frssysvol
* The File Replication Service Event log test
The SYSVOL has been shared, and the AD is no longer
prevented from starting by the File Replication Service.
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
An Warning Event occured.EventID: 0x800034C4

Time Generated: 12/08/2002 15:19:33

(Event String could not be retrieved)
An Warning Event occured.EventID: 0x800034C4

Time Generated: 12/08/2002 15:19:34

(Event String could not be retrieved)
......................... testerBDC passed test frssysvol
Starting test: kccevent
* The KCC Event log test
Found no KCC errors in Directory Service Event log in the last 15 minutes.
......................... testerBDC passed test kccevent
Starting test: systemlog
* The System Event log test
An Error Event occured.EventID: 0xC0000031

Time Generated: 12/08/2002 16:40:03

Event String: An unexpected error occured while trying to start
the server. The port may already be in use.
An Error Event occured.EventID: 0xC0000031

Time Generated: 12/08/2002 16:40:13

Event String: An unexpected error occured while trying to start
the server. The port may already be in use.
......................... testerBDC failed test systemlog

Running enterprise tests on : tester.com
Starting test: Intersite
Skipping site Default-First-Site-Name, this site is outside the scope
provided by the command line arguments provided.
......................... tester.com passed test Intersite
Starting test: FsmoCheck
GC Name: \\testerbdc.tester.com
Locator Flags: 0xe00001fd
PDC Name: \\testerbdc.tester.com
Locator Flags: 0xe00001fd
Time Server Name: \\testerbdc.tester.com
Locator Flags: 0xe00001fd
回复

使用道具 举报

千问 | 2005-10-30 17:05:33 | 显示全部楼层
打过SP3了吗?
回复

使用道具 举报

千问 | 2005-10-30 17:05:33 | 显示全部楼层
Active Directory Replication Domain Controller Replication Failure Output
Printed at2002-12-8 下午 05:31:28
Below are the replication failures detected on Domain Controllers for this domain:
Domain Controller Name:
tester

Directory Partition:CN=Schema,CN=Configuration,DC=cogel,DC=com

Replication Partner:Default-First-Site-Name\testerBDC

Failure Code:
8524

Failure Reason:
由于 DNS 查找故障,DSA 操作无法进行。
Domain Controller Name:
tester

Directory Partition:CN=Configuration,DC=cogel,DC=com

Replication Partner:Default-First-Site-Name\testerBDC

Failure Code:
8524

Failure Reason:
由于 DNS 查找故障,DSA 操作无法进行。
Domain Controller Name:
tester

Directory Partition:DC=cogel,DC=com

Replication Partner:Default-First-Site-Name\testerBDC

Failure Code:
8524

Failure Reason:
由于 DNS 查找故障,DSA 操作无法进行。
Domain Controller Name:
testerBDC

Directory Partition:CN=Configuration,DC=cogel,DC=com

Replication Partner:Default-First-Site-Name\tester

Failure Code:
8418

Failure Reason:
由于有关服务器之间的架构不匹配,复制操作失败。
Domain Controller Name:
testerBDC

Directory Partition:DC=cogel,DC=com

Replication Partner:Default-First-Site-Name\tester

Failure Code:
8418

Failure Reason:
由于有关服务器之间的架构不匹配,复制操作失败。
回复

使用道具 举报

千问 | 2005-10-30 17:05:33 | 显示全部楼层
感谢frankpro的大力支持。
回复

使用道具 举报

千问 | 2005-10-30 17:05:33 | 显示全部楼层
hehe, 我一开始就怀疑Dynamic Update的问题,一般你把netlogon.dns 删除再重起就work le.
ps: 我一般都是only allow secure update,这样更加安全.
回复

使用道具 举报

千问 | 2005-10-30 17:05:33 | 显示全部楼层
又想了一下,肯定是SRV记录出错了, DC Replicate时要到_msdcs下去找的,一旦丢失就会报找不到对应的服务. 师哥说的还真是对...
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

主题

0

回帖

4882万

积分

论坛元老

Rank: 8Rank: 8

积分
48824836
热门排行