question

JohnBowden-7341 avatar image
0 Votes"
JohnBowden-7341 asked DSPatrick commented

new 2019 Windows AD server with an error running DCDIAG

I have to DC's now, one a 2012R2 (SVR1) and 2019 DC (SVR2). I've added a 3rd one called SVR2A. I am removing AD services from SVR1 because we are going to move it to a 2019 server down the road.

DCDIAG fails just on this one. Passes on everything else. So SVR2a also does not have the NetLogon folders because of this.

Testing server: Default-First-Site-Name\SVR2A

   Starting test: Advertising

      Warning: DsGetDcName returned information for

      \\SVR1.mydomain.ca, when we were trying to reach SVR2A.

      SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE.

      ......................... SVR2A failed test Advertising

Any idea on how to fix this?


windows-serverwindows-active-directory
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DSPatrick avatar image
0 Votes"
DSPatrick answered

Please run;

Dcdiag /v /c /d /e /s:%computername% >C:\dcdiag.log
repadmin /showrepl >C:\repl.txt
ipconfig /all > C:\dc1.txt
ipconfig /all > C:\dc2.txt
ipconfig /all > C:\dc3.txt

then put unzipped text files up on OneDrive and share a link.



5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

JohnBowden-7341 avatar image
0 Votes"
JohnBowden-7341 answered DSPatrick commented

svr2a-repl.txt (2.2 KiB)
svr2-repl.txt (2.2 KiB)
svr1-repl.txt (2.2 KiB)
svr2a-dcdiag.log (101.0 KiB)
svr2-dcdiag.log (96.0 KiB)
svr1-dcdiag.log (95.4 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Have you done the non-authoritative sync? Another method is to move the roles off, demote, reboot, promo the problematic one again.
https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/troubleshoot-missing-sysvol-and-netlogon-shares

--please don't forget to upvote and Accept as answer if the reply is helpful--






0 Votes 0 ·
DSPatrick avatar image
0 Votes"
DSPatrick answered DSPatrick commented

Still need the other three files. You can work through this one for the missing netlogon, sysvol shares.
https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/troubleshoot-missing-sysvol-and-netlogon-shares

--please don't forget to upvote and Accept as answer if the reply is helpful--






· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Just checking if there's any progress or updates?

--please don't forget to upvote and Accept as answer if the reply is helpful--



0 Votes 0 ·
Thameur-BOURBITA avatar image
0 Votes"
Thameur-BOURBITA answered

Hi,

Check the required ports for sysvol replication is already opened between new domain controller and its replication partner. If it's not the case and you still have the same issue, you should launch non-authoritative restore for sysvol replication:

force-authoritative-non-authoritative-synchronization



Please don't forget to mark helpful reply as answer

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LimitlessTechnology-2700 avatar image
0 Votes"
LimitlessTechnology-2700 answered

Hello JohnBowden

You can follow the troubleshooting approach suggested in the next thread: https://social.technet.microsoft.com/Forums/lync/en-US/6713c55f-0bc5-4d74-a18b-b867ccc9d059/server-is-not-responding-or-is-not-considered-suitable-ad2008r2-failed?forum=winserverDS



--If the reply is helpful, please Upvote and Accept as answer--

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

JohnBowden-7341 avatar image
0 Votes"
JohnBowden-7341 answered

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DSPatrick avatar image
0 Votes"
DSPatrick answered DSPatrick commented

Have you performed the steps here?
https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/troubleshoot-missing-sysvol-and-netlogon-shares

Another method is to move roles off, demote, reboot, promo again the problematic one.



--please don't forget to upvote and Accept as answer if the reply is helpful--




· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Just checking if there's any progress or updates?

--please don't forget to upvote and Accept as answer if the reply is helpful--



0 Votes 0 ·
JohnBowden-7341 avatar image
0 Votes"
JohnBowden-7341 answered DSPatrick commented

Hi all, I had to back bench this issue for a few days because I was running around with my hair on fire. All good now
I've just demoted SVR2a from the domain, restarted and all looks good. I am going to restart the SVR1 tomorrow morning. SVR2 was just restarted. So far all looks good. I'm going to leave SVR2a as a domain server but have nothing to do with AD. Once I get SVR1 restarted, I will let it settle for the day and then run through all of those diagnostics and create the reports, assuming that there are still issues.
Thanks for the support so far, much appreciated.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Just checking if there's any progress or updates?

--please don't forget to upvote and Accept as answer if the reply is helpful--



0 Votes 0 ·
JohnBowden-7341 avatar image
0 Votes"
JohnBowden-7341 answered

Today, I removed SVR2a, demoted it, removed everything from it, AD and DNS. After that, I went through the DNS and cleared any occurrence of that server.

The only error now in the dcdiag log file is the following

////////////////////////////////////////
Starting test: DFSREvent

      The DFS Replication Event Log. 
      There are warning or error events within the last 24 hours after the

      SYSVOL has been shared.  Failing SYSVOL replication problems may cause

      Group Policy problems. 
      A warning event occurred.  EventID: 0x80001396

         Time Generated: 01/26/2022   14:54:35

         Event String:

         The DFS Replication service is stopping communication with partner SVR2A for replication group Domain System Volume due to an error. The service will retry the connection periodically. 

////////////////////////////////////////

So, somewhere else, I need to remove SVR2a from a list or config file.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DSPatrick avatar image
0 Votes"
DSPatrick answered DSPatrick commented

You can remove the remnants from active directory by following along here.
https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/ad-ds-metadata-cleanup
https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-manually-removing-a-domain-controller-server/ba-p/280564

--please don't forget to upvote and Accept as answer if the reply is helpful--



· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Just checking if there's any progress or updates?

--please don't forget to upvote and Accept as answer if the reply is helpful--



0 Votes 0 ·