DC 复制问题

DC 复制问题

我似乎在我们的域控制器之间的复制方面遇到了问题,设置如下;

一个域两个域控制器(2008),一个是虚拟化的,一个是物理的,域控制器之间的同一站点 ping 正常。

好的,基本上我必须对托管虚拟机的服务器进行 BIOS 升级(域控制器是虚拟机之一)。更新后,我们的思科交换机出现问题,因为启用了智能端口并阻止了所有虚拟机与包含所有其他物理机的物理网络之间的流量。

现在我们通过禁用 2960 上的智能端口解决了这个问题,所有虚拟机都可以与物理机成功通信,一切都很正常。但是;当我们为域控制器启动虚拟机时,启动需要很长时间(我知道 AD / DNS 问题很常见)。当它最终启动时,我登录并立即尝试 ping 第二个 DC。ping 响应正常,网络一切正常。但突然间,域控制器不同步了。我尝试了 repadmin /syncall,但出现错误,我尝试了 dcdiag /q,也出现错误。RPC 服务无法与 FSMO 持有者通信(简而言之)。

我检查了一下,dfsr 服务运行正常。我关闭了所有防火墙和防病毒软件,但它们仍然无法通信,只能通过 ping 进行通信。什么都没变??

有人能告诉我从哪里开始吗?为了测试目的,我在第二个 DC 上创建了一个对象,但它没有复制到第一个 DC(FSMO 持有者)。

C:\Users\Administrator>dcdiag /q
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... IME-DC1 failed test DFSREvent
         [Replications Check,IME-DC1] A recent replication attempt failed:
            From IME-DC2 to IME-DC1
            Naming Context: DC=ForestDnsZones,DC=XXX,DC=com
            The replication generated an error (1726):
            The remote procedure call failed.
            The failure occurred at 2013-10-02 21:11:34.
            The last success occurred at 2013-10-02 20:05:07.
            2 failures have occurred since the last success.
         [Replications Check,IME-DC1] A recent replication attempt failed:
            From IME-DC2 to IME-DC1
            Naming Context: DC=DomainDnsZones,DC=XXX,DC=com
            The replication generated an error (1726):
            The remote procedure call failed.
            The failure occurred at 2013-10-02 21:09:56.
            The last success occurred at 2013-10-02 20:04:39.
            2 failures have occurred since the last success.
         [Replications Check,IME-DC1] A recent replication attempt failed:
            From IME-DC2 to IME-DC1
            Naming Context: CN=Schema,CN=Configuration,DC=XXX,DC=com
            The replication generated an error (1726):
            The remote procedure call failed.
            The failure occurred at 2013-10-02 21:02:40.
            The last success occurred at 2013-10-02 17:55:42.
            6 failures have occurred since the last success.
         [Replications Check,IME-DC1] A recent replication attempt failed:
            From IME-DC2 to IME-DC1
            Naming Context: CN=Configuration,DC=XXX,DC=com
            The replication generated an error (1726):
            The remote procedure call failed.
            The failure occurred at 2013-10-02 20:57:56.
            The last success occurred at 2013-10-02 20:04:36.
            3 failures have occurred since the last success.
         [Replications Check,IME-DC1] A recent replication attempt failed:
            From IME-DC2 to IME-DC1
            Naming Context: DC=XXX,DC=com
            The replication generated an error (1726):
            The remote procedure call failed.
            The failure occurred at 2013-10-02 21:05:29.
            The last success occurred at 2013-10-02 20:05:10.
            2 failures have occurred since the last success.
         ......................... IME-DC1 failed test Replications
         An Error Event occurred.  EventID: 0x00000457
            Time Generated: 10/02/2013   21:47:42
            Event String:
            Driver Microsoft XPS Document Writer v4 required for printer Microso
ft XPS Document Writer is unknown. Contact the administrator to install the driv
er before you log in again.
         ......................... IME-DC1 failed test SystemLog

C:\Users\Administrator>

我还包括了来自活动目录日志的事件日志错误。

Log Name:      Directory Service
Source:        Microsoft-Windows-ActiveDirectory_DomainService
Date:          02/10/2013 22:13:33
Event ID:      1308
Task Category: Knowledge Consistency Checker
Level:         Warning
Keywords:      Classic
User:          ANONYMOUS LOGON
Computer:      IME-DC1.XXX.com
Description:
The Knowledge Consistency Checker (KCC) has detected that successive attempts to replicate with the following directory service has consistently failed. 

Attempts:
7 
Directory service:
CN=NTDS Settings,CN=IME-DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=XXX,DC=com 
Period of time (minutes):
128 

The Connection object for this directory service will be ignored, and a new temporary connection will be established to ensure that replication continues. Once replication with this directory service resumes, the temporary connection will be removed. 

Additional Data 
Error value:
1818 The remote procedure call was cancelled.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-ActiveDirectory_DomainService" Guid="{0e8478c5-3605-4e8c-8497-1e730c959516}" EventSourceName="NTDS KCC" />
    <EventID Qualifiers="32768">1308</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>1</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2013-10-02T18:13:33.071Z" />
    <EventRecordID>12274</EventRecordID>
    <Correlation />
    <Execution ProcessID="652" ThreadID="1332" />
    <Channel>Directory Service</Channel>
    <Computer>IME-DC1.XXX.com</Computer>
    <Security UserID="S-1-5-7" />
  </System>
  <EventData>
    <Data>7</Data>
    <Data>CN=NTDS Settings,CN=IME-DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=XXX,DC=com</Data>
    <Data>128</Data>
    <Data>The remote procedure call was cancelled.</Data>
    <Data>1818</Data>
  </EventData>
</Event>

答案1

启动时间过长表明您在 DC 的网络适配器设置中对 DNS 服务器的排序有误。这也可能导致您看到的复制问题。阅读此问题的答案并更正您的设置。我想您之后可能会看到改进。

AD 域控制器的 DNS 服务器的顺序应该是什么?为什么?

如果这仍不能解决问题,您需要找出两台服务器之间 RPC 无法正常工作的原因。这可能是由于网络配置问题、防火墙问题(硬件或基于主机)或任何其他原因造成的。简单地 ping 服务器并不能确保 RPC 能够成功通信,它只能说明两台服务器之间的 ICMP 正在工作。

相关内容