Cannot enable inbound sync on RODC with repadmin /options server -disable_inbound_repl


after making modifications our active directory caused more replication traffic expected (it killed our 2x34mbit lines) had resort stopping inbound replication on the dcs in our branch offices using command: repadmin /options server +disable_inbound_repl.

we allowing servers sync again, works our normal dcs rodcs not accepting command: repadmin /options server -disable_inbound_repl. executes correctly doesn't seem apply.

is there can overcome this?

c:\>repadmin /options myrodc -disable_inbound_repl
current dsa options: is_gc disable_inbound_repl disable_outbound_repl is_rodc
new dsa options: is_gc disable_outbound_repl is_rodc

c:\>repadmin /showreps myrodc
site10\myrodc
dsa options: is_gc disable_inbound_repl disable_outbound_repl is_rodc
site options: (none)
dsa object guid: f8a33add-600f-40f0-ac8f-f70ab746de16
dsa invocationid: c846f9eb-0032-4703-9eed-832163d3f6a5

when try run command:

repadmin /replicate myrodc myhubdc cn=configuration,dc=mydomain,dc=com /readonly /force

i reply:

dsreplicasync() failed status 8452 (0x2104):
    naming context in process of being removed or not replicated specified server.

we're talking environment 100+ rodc , active directory database 3.6 gb demotion , promotion not valid option. forest functional level 2003, have 2003 r2, 2008r2 , 2008 r2 rodcs.

all repadmin commands should force or overrule disable_inbound_repl option have failed.

we discovered there different information in ntds attribute (which lives in configuration partition under sites/sitename/servers/servername) of rodc there in same attribute on normal dc (which makes sense after trying different fixes day). setting had on normal dc correct needed way rodc. since full replication of configuration partition failed ended trying replicate 1 object , did trick.

i have been able 4 boxes syncing again following procedure:

  • branch-rodc = read dc (with sync problem)
  • hub-rwdc = dc/gc writeable copy
  1. repadmin /options branch-rodc -disable_inbound_repl /homeserver:hub-rwdc
  2. repadmin /replsingleobj branch-rodc hub-rwdc "cn=ntds settings,cn=branch-rodc,cn=servers,cn=branchsite,cn=sites,cn=configuration,dc=corp,dc=com"
  3. repadmin /kcc branch-rodc
  4. repadmin /showrepl 
  5. (examine output of showrepl , in next command replace name hub-rwdc server selected kcc process)
  6. repadmin /replicate branch-rodc hub-rwdc cn=configuration,dc=corp,dc=com

that pretty seems going again. have got on hundred go time start scripting...

thanks suggestions.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group