{"id":242,"date":"2020-08-29T10:39:46","date_gmt":"2020-08-29T09:39:46","guid":{"rendered":"https:\/\/debnar.org\/wp\/?p=242"},"modified":"2021-03-26T06:22:16","modified_gmt":"2021-03-26T05:22:16","slug":"aramszunet-es-az-activedirectory","status":"publish","type":"post","link":"https:\/\/debnar.org\/wp\/?p=242","title":{"rendered":"\u00c1ramsz\u00fcnet \u00e9s az ActiveDirectory"},"content":{"rendered":"<p>J\u00falius v\u00e9g\u00e9n volt egy \u00e1ramsz\u00fcnet ami k\u00e9t DC-t \u00e9rintett (sz\u00fcnetmentes nem b\u00edrta szusszal). A &#8220;PDC&#8221;-nek szerencs\u00e9re nem t\u00f6rt\u00e9nt baja, no meg arr\u00f3l van ment\u00e9s is persze, \u00edgy elkezdtem kidebugolni a probl\u00e9m\u00e1t amib\u0151l azt\u00e1n kiesett 2 hiba is.<\/p>\n<p><a href=\"#ad-dfsr-incident-tldr\">tl;dr<\/a> a v\u00e9g\u00e9n<\/p>\n<p><!--more--><\/p>\n<h1>AD replika hiba<\/h1>\n<h2>\u00c9szlel\u00e9s<\/h2>\n<p>T\u00fcnetek az al\u00e1bbiak voltak:<\/p>\n<ul>\n<li>Nem lehetett mindig bejelentkezni egy felhaszn\u00e1l\u00f3val<\/li>\n<li>Nem megb\u00edzhat\u00f3 kapcsolatot \u00edrt a tartom\u00e1nnyal<\/li>\n<li>Bejelentkez\u00e9s m\u00e9g ment de policyket m\u00e1r nem kapta meg.<\/li>\n<li>\u00daj g\u00e9peket nem lehetett bel\u00e9ptetni (the target account name is incorrect)<\/li>\n<\/ul>\n<p>Ek\u00f6zben a logokban arra panaszkodott, hogy nem siker\u00fclt friss\u00edteni a DNS-ben a bejegyz\u00e9seket.<\/p>\n<blockquote><p>A DNS-rekord (&#8216;455543f8-4b64-4128-9f12-61c1c3705652._msdcs.CONTOSO.local. 600 IN CNAME dc1.CONTOSO.local.&#8217;) dinamikus regisztr\u00e1ci\u00f3ja nem siker\u00fclt a k\u00f6vetkez\u0151 DNS-kiszolg\u00e1l\u00f3n:<\/p>\n<p>DNS-kiszolg\u00e1l\u00f3 IP-c\u00edme: 192.168.65.3<br \/>\nVisszak\u00fcld\u00f6tt v\u00e1laszk\u00f3d (RCODE): 5<br \/>\nVisszak\u00fcld\u00f6tt \u00e1llapotk\u00f3d: 9005<\/p><\/blockquote>\n<p>Ha a DNS kezel\u0151t megpr\u00f3b\u00e1ltam megnynit a 192.168.65.3-on azt mondta, hogy nem l\u00e9tezik illetve ACCESS DENIED.<\/p>\n<p>R\u00e1n\u00e9ztem a replik\u00e1ra a DC1-r\u0151l, ott rendben volt, a probl\u00e9ma az EXCALIBUR DC-n volt (t\u00f6bbek k\u00f6zt ilyen hib\u00e1k voltak):<\/p>\n<blockquote><p>DC=DomainDnsZones,DC=CONTOSO,DC=local<br \/>\nDefault-First-Site-Name\\DC1 via RPC<br \/>\nDSA object GUID: 455543f8-4b64-4128-9f12-61c1c3705652<br \/>\nLast attempt @ 2020-08-28 17:15:38 failed, result 1908 (0x774):<br \/>\nCould not find the domain controller for this domain.<br \/>\n57 consecutive failure(s).<br \/>\nLast success @ 2020-07-22 18:52:45.<\/p>\n<p>Source: Default-First-Site-Name\\DC1<br \/>\n******* 466 CONSECUTIVE FAILURES since 2020-07-22 19:29:34<br \/>\nLast error: 1256 (0x4e8):<br \/>\nThe remote system is not available. For information about network tr<br \/>\noubleshooting, see Windows Help.<\/p><\/blockquote>\n<p>Illetve ilyen is (ez m\u00e1r csak az event viewerb\u0151l van de a repadmin is \u00edrta):<\/p>\n<blockquote><p><span style=\"font-family: Segoe UI, serif;\"><span style=\"font-size: small;\"><span lang=\"hu-HU\">Internal event: Active Directory Domain Services could not update the following object with changes received from the following source directory service. This is because an error occurred during the application of the changes to Active Directory Domain Services on the directory service. <\/span><\/span><\/span><\/p>\n<p><span style=\"font-family: Segoe UI, serif;\"><span style=\"font-size: small;\"><span lang=\"hu-HU\">Object:<br \/>\nDC=CONTOSO,DC=local<br \/>\nObject GUID:<br \/>\n0f1e7c61-6c89-4d3d-b3a1-1b8aa0dfe827<br \/>\nSource directory service:<br \/>\n455543f8-4b64-4128-9f12-61c1c3705652._msdcs.CONTOSO.local<br \/>\nSynchronization of the directory service with the source directory service is blocked until this update problem is corrected.<br \/>\nThis operation will be tried again at the next scheduled replication.<br \/>\nUser Action<br \/>\nRestart the local computer if this condition appears to be related to low system resources (for example, low physical or virtual memory).<br \/>\nAdditional Data<br \/>\nError value:<br \/>\n1127 While accessing the hard disk, a disk operation failed even after retries.<\/span><\/span><\/span><\/p><\/blockquote>\n<p>repadmin \/syncall nem seg\u00edtett, ugyanaz a hiba, egy gyors reboot ut\u00e1n mi a helyzet? Indul\u00e1skor futott egy checkdisk:<\/p>\n<blockquote><p>Checking file system on C:<br \/>\nThe type of the file system is NTFS.<\/p>\n<p>One of your disks needs to be checked for consistency. You<br \/>\nmay cancel the disk check, but it is strongly recommended<br \/>\nthat you continue.<br \/>\nWindows will now check the disk.<\/p>\n<p>CHKDSK is verifying files (stage 1 of 3)&#8230;<br \/>\nCleaning up instance tags for file 0x175.<br \/>\nCleaning up instance tags for file 0x7634.<br \/>\nCleaning up instance tags for file 0x764b.<br \/>\nCleaning up instance tags for file 0xf491.<br \/>\nCleaning up instance tags for file 0xfe9d.<br \/>\nCleaning up instance tags for file 0xfea3.<br \/>\nThe attribute of type 0x80 and instance tag 0x0 in file 0x10f60<br \/>\nhas allocated length of 0xb77650000 instead of 0xb77640000.<br \/>\nDeleted corrupt attribute list entry<br \/>\nwith type code 128 in file 69472.<br \/>\nUnable to locate attribute with instance tag 0x0 and segment<br \/>\nreference 0x2ea7000000004253. The expected attribute type is 0x80.<br \/>\nDeleting corrupt attribute record (128, $J)<br \/>\nfrom file record segment 16979.<br \/>\nUnable to locate attribute with instance tag 0x0 and segment<br \/>\nreference 0xaf1f00000000d9b6. The expected attribute type is 0x80.<br \/>\nDeleting corrupt attribute record (128, $J)<br \/>\nfrom file record segment 55734.<br \/>\nUnable to locate attribute with instance tag 0x0 and segment<br \/>\nreference 0x24f1000000011c24. The expected attribute type is 0x80.<br \/>\nDeleting corrupt attribute record (128, $J)<br \/>\nfrom file record segment 72740.<br \/>\nUnable to locate attribute with instance tag 0x0 and segment<br \/>\nreference 0x1c910000000123b3. The expected attribute type is 0x80.<br \/>\nDeleting corrupt attribute record (128, $J)<br \/>\nfrom file record segment 74675.<br \/>\nUnable to locate attribute with instance tag 0x0 and segment<br \/>\nreference 0x6ed4000000012495. The expected attribute type is 0x80.<br \/>\nDeleting corrupt attribute record (128, $J)<br \/>\nfrom file record segment 74901.<br \/>\nUnable to locate attribute with instance tag 0x0 and segment<br \/>\nreference 0x2271000000012ec1. The expected attribute type is 0x80.<br \/>\nDeleting corrupt attribute record (128, $J)<br \/>\nfrom file record segment 77505.<br \/>\nUnable to locate attribute with instance tag 0x0 and segment<br \/>\nreference 0x1442000000025048. The expected attribute type is 0x80.<br \/>\nDeleting corrupt attribute record (128, $J)<br \/>\nfrom file record segment 151624.<br \/>\nUnable to locate attribute with instance tag 0x0 and segment<br \/>\nreference 0xad900000002509f. The expected attribute type is 0x80.<br \/>\nDeleting corrupt attribute record (128, $J)<br \/>\nfrom file record segment 151711.<br \/>\nCleaning up instance tags for file 0x16627.<br \/>\n288768 file records processed. File verification completed.<br \/>\nDeleting orphan file record segment 16979.<br \/>\nDeleting orphan file record segment 55734.<br \/>\nDeleting orphan file record segment 78543.<br \/>\n13117 large file records processed. 0 bad file records processed.<br \/>\nCHKDSK is verifying indexes (stage 2 of 3)&#8230;<br \/>\n375066 index entries processed. Index verification completed.<br \/>\n0 unindexed files scanned. 0 unindexed files recovered.<br \/>\nCHKDSK is verifying security descriptors (stage 3 of 3)&#8230;<br \/>\nCleaning up 45 unused index entries from index $SII of file 0x9.<br \/>\nCleaning up 45 unused index entries from index $SDH of file 0x9.<br \/>\nCleaning up 45 unused security descriptors.<br \/>\nSecurity descriptor verification completed.<br \/>\n43150 data files processed. CHKDSK is verifying Usn Journal&#8230;<br \/>\nCreating Usn Journal $J data stream<br \/>\nUsn Journal verification completed.<br \/>\nCHKDSK discovered free space marked as allocated in the<br \/>\nmaster file table (MFT) bitmap.<br \/>\nCHKDSK discovered free space marked as allocated in the volume bitmap.<\/p>\n<p>Windows has made corrections to the file system.<br \/>\nNo further action is required.<\/p>\n<p>523926527 KB total disk space.<br \/>\n146761988 KB in 150555 files.<br \/>\n116572 KB in 43151 indexes.<br \/>\n0 KB in bad sectors.<br \/>\n378207 KB in use by the system.<br \/>\n65536 KB occupied by the log file.<br \/>\n376669760 KB available on disk.<\/p>\n<p>4096 bytes in each allocation unit.<br \/>\n130981631 total allocation units on disk.<br \/>\n94167440 allocation units available on disk.<\/p>\n<p>Internal Info:<br \/>\n00 68 04 00 b4 f4 02 00 b7 83 05 00 00 00 00 00 .h&#8230;&#8230;&#8230;&#8230;..<br \/>\n54 02 00 00 de 00 00 00 00 00 00 00 00 00 00 00 T&#8230;&#8230;&#8230;&#8230;&#8230;<br \/>\n20 03 00 14 e7 00 00 00 00 00 00 00 00 00 00 00 &#8230;&#8230;&#8230;&#8230;&#8230;<\/p>\n<p>Windows has finished checking your disk.<br \/>\nPlease wait while your computer restarts.<\/p><\/blockquote>\n<p>Teh\u00e1t hib\u00e1t tal\u00e1lt, logban \u00edrta is, hogy s\u00e9r\u00fclt az AD DB f\u00e1jl.<\/p>\n<blockquote><p>This event contains REPAIR PROCEDURES for the 1084 event which has previously been logged. This message indicates a specific issue with the consistency of the Active Directory Domain Services database on this replication destination. A database error occurred while applying replicated changes to the following object. The database had unexpected contents, preventing the change from being made.<\/p>\n<p>Object:<br \/>\nDC=CONTOSO,DC=local<br \/>\nObject GUID:<br \/>\n0f1e7c61-6c89-4d3d-b3a1-1b8aa0dfe827<br \/>\nSource domain controller:<br \/>\n455543f8-4b64-4128-9f12-61c1c3705652._msdcs.CONTOSO.local<\/p>\n<p>User Action<\/p>\n<p>&#8230;.jav\u00edt\u00e1sr\u00f3l \u00edr itt, de minket annyira ez nem izgat, van egy \u00e9p p\u00e9ld\u00e1nyunk<\/p>\n<p>Domain Services Databases.<\/p>\n<p>If none of these actions succeed and the replication error continues, you should demote this domain controller and promote it again.<\/p>\n<p>Additional Data<br \/>\nPrimary Error value:<br \/>\n1127 While accessing the hard disk, a disk operation failed even after retries.<br \/>\nSecondary Error value:<br \/>\n-510 JET_errLogWriteFail, Failure writing to log file<\/p><\/blockquote>\n<h2>Jav\u00edt\u00e1s<\/h2>\n<p>No de kit \u00e9rdekel, van egy eg\u00e9szs\u00e9ges DC-nk, syncelj\u00fck \u00e1t onnan. Persze ez nyilv\u00e1n nem megy a szinkron &#8220;The target principal name is incorrect&#8221; hib\u00e1val meg\u00e1ll. A probl\u00e9ma, hogy t\u00fal r\u00e9gen cs\u00faszott sz\u00e9t az eg\u00e9sz (1 h\u00f3nap) emiatt a kerberos ticketek is teljesen elm\u00e1sztak. Kell egy force szinkron(<a title=\"1\" href=\"https:\/\/support.microsoft.com\/en-us\/help\/2090913\/active-directory-replication-error-2146893022-the-target-principal-nam\" target=\"_blank\" rel=\"noopener\">1<\/a>):<\/p>\n<p>Ehhez el\u0151sz\u00f6r is \u00e1ll\u00edtsuk le a &#8220;Kerberos Key Distribution Center&#8221; szolg\u00e1ltat\u00e1st azon a szerveren ahova forceolni akarjuk a szinkront:<\/p>\n<blockquote><p><span style=\"font-family: Segoe UI, serif;\"><span style=\"font-size: small;\">net stop kdc<\/span><\/span><\/p><\/blockquote>\n<p>Forceoljunk ki egy configuration szinkront<\/p>\n<p><a href=\"\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/replicateconfigfromselecteddc.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-244\" src=\"\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/replicateconfigfromselecteddc-300x170.png\" alt=\"Replicate configuration from the selected DC\" width=\"300\" height=\"170\" srcset=\"https:\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/replicateconfigfromselecteddc-300x170.png 300w, https:\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/replicateconfigfromselecteddc.png 897w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Ind\u00edtsuk el a kor\u00e1bban le\u00e1ll\u00edtott &#8220;Kerberos Key Distribution Center&#8221;-t:<\/p>\n<blockquote><p>net start kdc<\/p><\/blockquote>\n<p>Ezekut\u00e1n rem\u00e9lhet\u0151leg m\u00e1r rendben lesz. Hagyjunk egy kis id\u0151t m\u00edg mindent rendben leszinkroniz\u00e1l. K\u00f6zvetlen\u00fcl ut\u00e1na:<\/p>\n<blockquote><p>C:\\Windows\\system32&gt;repadmin \/showrepl<\/p>\n<p>Repadmin: running command \/showrepl against full DC localhost<br \/>\nDefault-First-Site-Name\\EXCALIBUR<br \/>\nDSA Options: IS_GC<br \/>\nSite Options: (none)<br \/>\nDSA object GUID: 57e27dc2-70fd-49e2-8c71-702f9f125f22<br \/>\nDSA invocationID: ea8948bc-8291-40c2-b7b4-722497a869f5<\/p>\n<p>==== INBOUND NEIGHBORS ======================================<\/p>\n<p>DC=CONTOSO,DC=local<br \/>\nDefault-First-Site-Name\\DC1 via RPC<br \/>\nDSA object GUID: 455543f8-4b64-4128-9f12-61c1c3705652<br \/>\nLast attempt @ 2020-08-28 17:42:59 was successful.<\/p>\n<p>CN=Configuration,DC=CONTOSO,DC=local<br \/>\nDefault-First-Site-Name\\DC1 via RPC<br \/>\nDSA object GUID: 455543f8-4b64-4128-9f12-61c1c3705652<br \/>\nLast attempt @ 2020-08-28 17:21:51 was successful.<\/p>\n<p>CN=Schema,CN=Configuration,DC=CONTOSO,DC=local<br \/>\nDefault-First-Site-Name\\DC1 via RPC<br \/>\nDSA object GUID: 455543f8-4b64-4128-9f12-61c1c3705652<br \/>\nLast attempt @ 2020-08-28 17:14:37 failed, result 1908 (0x774):<br \/>\nCould not find the domain controller for this domain.<br \/>\n55 consecutive failure(s).<br \/>\nLast success @ 2020-07-22 18:52:45.<\/p>\n<p>DC=DomainDnsZones,DC=CONTOSO,DC=local<br \/>\nDefault-First-Site-Name\\DC1 via RPC<br \/>\nDSA object GUID: 455543f8-4b64-4128-9f12-61c1c3705652<br \/>\nLast attempt @ 2020-08-28 17:15:38 failed, result 1908 (0x774):<br \/>\nCould not find the domain controller for this domain.<br \/>\n57 consecutive failure(s).<br \/>\nLast success @ 2020-07-22 18:52:45.<\/p>\n<p>DC=ForestDnsZones,DC=CONTOSO,DC=local<br \/>\nDefault-First-Site-Name\\DC1 via RPC<br \/>\nDSA object GUID: 455543f8-4b64-4128-9f12-61c1c3705652<br \/>\nLast attempt @ 2020-08-28 17:34:45 was successful.<\/p>\n<p>Source: Default-First-Site-Name\\DC1<br \/>\n******* 57 CONSECUTIVE FAILURES since 2020-07-22 18:52:45<br \/>\nLast error: 1908 (0x774):<br \/>\nCould not find the domain controller for this domain.<\/p><\/blockquote>\n<p>Maximum f\u00e9l \u00f3ra ut\u00e1n mindent sz\u00e9pen replik\u00e1l.<\/p>\n<h1>DFSR hiba<\/h1>\n<p>Ezut\u00e1n sz\u00e9pen be lehetett jelentkezni mindenhova, majd ha nyomtam egy gpupdate-et akkor k\u00f6z\u00f6lte, hogy sikertelen volt, nem tal\u00e1lja a megadott policyt, szerveren event viewerben is l\u00e1tsz\u00f3dott a hiba:<\/p>\n<blockquote><p>&#8211; EventData<\/p>\n<p>SupportInfo1 1<br \/>\nSupportInfo2 4875<br \/>\nProcessingMode 0<br \/>\nProcessingTimeInMilliseconds 610<br \/>\nErrorCode 3<br \/>\nErrorDescription The system cannot find the path specified.<br \/>\nDCName \\\\EXCALIBUR.CONTOSO.local<br \/>\nExtensionName Group Policy Power Options<br \/>\nExtensionId {E62688F0-25FD-4c90-BFF5-F508B9D2E31F}<\/p><\/blockquote>\n<p>Val\u00f3ban be\u00edrva az int\u00e9z\u0151be nem tal\u00e1lthat\u00f3 a policy, m\u00edg a DC1 szerveren igen. Ezzel az a probl\u00e9ma, hogy nagyon r\u00e9gen \u00e1llt le, amit nem tal\u00e1lt policy az valamikor febru\u00e1rban sz\u00fcletett. Nem tudom, hogy nem der\u00fclt ez ki kor\u00e1bban, mindenesetre event logban:<\/p>\n<blockquote><p><span style=\"font-family: Segoe UI, serif;\"><span style=\"font-size: small;\">The DFS Replication service stopped replication on volume C:. This occurs when a DFSR JET database is not shut down cleanly and Auto Recovery is disabled. To resolve this issue, back up the files in the affected replicated folders, and then use the ResumeReplication WMI method to resume replication. <\/span><\/span><\/p>\n<p><span style=\"font-family: Segoe UI, serif;\"><span style=\"font-size: small;\"><span lang=\"hu-HU\">Additional Information:<br \/>\nVolume: C:<br \/>\nGUID: CA16872C-04BB-11E3-93E8-806E6F6E6963<br \/>\nRecovery Steps<br \/>\n1. Back up the files in all replicated folders on the volume. Failure to do so may result in data loss due to unexpected conflict resolution during the recovery of the replicated folders.<br \/>\n2. To resume the replication for this volume, use the WMI method ResumeReplication of the DfsrVolumeConfig class. For example, from an elevated command prompt, type the following command:<br \/>\nwmic \/namespace:\\\\root\\microsoftdfs path dfsrVolumeConfig where volumeGuid=&#8221;CA16872C-04BB-11E3-93E8-806E6F6E6963&#8243; call ResumeReplication <\/span><\/span><\/span><\/p>\n<p><span style=\"font-family: Segoe UI, serif;\"><span style=\"font-size: small;\">For more information, see <a href=\"http:\/\/support.microsoft.com\/kb\/2663685\">http:\/\/support.microsoft.com\/kb\/2663685<\/a>.<\/span><\/span><\/p><\/blockquote>\n<p>Teh\u00e1t ott is van mit kell csin\u00e1lni, gyors backup mindk\u00e9t DC-n (sima f\u00e1jlm\u00e1sol\u00e1s) a c:\\windows\\SYSVOL\\domain k\u00f6nyvt\u00e1rr\u00f3l majd futtatni a<\/p>\n<blockquote><p><span style=\"font-family: Segoe UI, serif;\"><span style=\"font-size: small;\"><span lang=\"hu-HU\">wmic \/namespace:\\\\root\\microsoftdfs path dfsrVolumeConfig where volumeGuid=&#8221;CA16872C-04BB-11E3-93E8-806E6F6E6963&#8243; call ResumeReplication <\/span><\/span><\/span><\/p><\/blockquote>\n<p>Ha szerencs\u00e9sek vagyunk ennyi el\u00e9g is, miut\u00e1n nekem nagyon r\u00e9gen sz\u00e9tcs\u00faszott ez\u00e9rt az al\u00e1bbi hiba\u00fczenetet dobta:<\/p>\n<blockquote><p>The DFS Replication service stopped replication on the folder with the following local path: C:\\Windows\\SYSVOL\\domain. This server has been disconnected from other partners for 267 days, which is longer than the time allowed by the MaxOfflineTimeInDays parameter (60). DFS Replication considers the data in this folder to be stale, and this server will not replicate the folder until this error is corrected.<\/p>\n<p>To resume replication of this folder, use the DFS Management snap-in to remove this server from the replication group, and then add it back to the group. This causes the server to perform an initial synchronization task, which replaces the stale data with fresh data from other members of the replication group.<\/p>\n<p>Additional Information:<br \/>\nError: 9061 (The replicated folder has been offline for too long.)<br \/>\nReplicated Folder Name: SYSVOL Share<br \/>\nReplicated Folder ID: 6E031177-CEA1-49CC-97BD-7E20A2DEFA70<br \/>\nReplication Group Name: Domain System Volume<br \/>\nReplication Group ID: 2AB23F75-C70A-45F4-BE47-43BFCC8F2FDA<br \/>\nMember ID: A9B0D353-863C-4E4E-A325-06E072CA5F3F<\/p><\/blockquote>\n<p>267 nap. Az sz\u00e9p eset. F\u0151leg, hogy fel sem t\u0171nt. Annyi baj legyen kellene egy force szinkron.<\/p>\n<h2>Non-authoritive \u00e9s authoritive szinkron<\/h2>\n<p>K\u00e9t lehet\u0151s\u00e9g\u00fcnk van non-authoritive szinkront csin\u00e1lni, ez ilyen kb. automata, kital\u00e1lja, hogy mi a j\u00f3 nek\u00fcnk, ezt akkor j\u00e1tszhatjuk meg ha t\u00f6bb mint 2 DC-nk van \u00e9s t\u00f6bb mint a DC-k 50% rendben van(<a title=\"2\" href=\"https:\/\/support.microsoft.com\/en-us\/help\/2218556\/how-to-force-an-authoritative-and-non-authoritative-synchronization-fo\" target=\"_blank\" rel=\"noopener\">2<\/a>). Az, hogy mi van rendben azt al\u00e1bbival ellen\u0151r\u00edzhetj\u00fck:<\/p>\n<blockquote><p>for \/f %i IN (&#8216;dsquery server -o rdn&#8217;) do @echo %i &amp;&amp; @wmic \/node:&#8221;%i&#8221; \/namespace:\\\\root\\microsoftdfs path dfsrreplicatedfolderinfo WHERE replicatedfoldername=&#8217;SYSVOL share&#8217; get replicationgroupname,replicatedfoldername,state<\/p><\/blockquote>\n<p>Egy ilyen p\u00e9ld\u00e1ul nem j\u00f3:<\/p>\n<blockquote><p>EXCALIBUR<br \/>\nNo Instance(s) Available.<br \/>\nDC1<br \/>\nReplicatedFolderName\u00a0 ReplicationGroupName\u00a0 State<br \/>\nSYSVOL Share\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Domain System Volume\u00a0 2<\/p><\/blockquote>\n<p>Nekem nincs meg legal\u00e1bb az 50+1 % \u00edgy marad az authoritive szinkron, nagy elt\u00e9r\u00e9s nincs a kett\u0151 k\u00f6zt am\u00fagy, egy attrib\u00fatum \u00e9rt\u00e9k. Mi a nagyj\u00e1b\u00f3li menet?<\/p>\n<h3>Non authoritive eset\u00e9ben:<\/h3>\n<ol>\n<li>Kivenni a rossz szervert a replik\u00e1ci\u00f3b\u00f3l<\/li>\n<li>Friss\u00edteni a DFS szinkroniz\u00e1l\u00e1st AD-b\u00f3l<\/li>\n<li>Visszarakni a rossz szervert a replik\u00e1b\u00f3l<\/li>\n<li>Friss\u00edteni a DFS szinkroniz\u00e1l\u00e1st AD-b\u00f3l<\/li>\n<\/ol>\n<h3 id=\"ad-dfsr-incident-authoritiveDFSR\">Authoritive eset\u00e9ben:<\/h3>\n<ol>\n<li>Le\u00e1ll\u00edtani a DFS replik\u00e1ci\u00f3kat<\/li>\n<li>Le\u00e1ll\u00edteni mindenhol a replik\u00e1ci\u00f3t \u00e9s kinevezni egy &#8220;master&#8221;-t<\/li>\n<li>&#8220;master&#8221;-en elindulhat a DFS replik\u00e1ci\u00f3<\/li>\n<li>Visszarakni a &#8220;master&#8221;-t<\/li>\n<li>Friss\u00edteni a DFS szinkroniz\u00e1l\u00e1st AD-b\u00f3l a masteren<\/li>\n<li>Mindenhol m\u00e1sutt elind\u00edthat\u00f3 a DFS replik\u00e1ci\u00f3<\/li>\n<li>Visszarakni a t\u00f6bbi szervert is<\/li>\n<li>Friss\u00edteni a DFS szinkroniz\u00e1l\u00e1st AD-b\u00f3l<\/li>\n<\/ol>\n<p>Authoritive akkor, hogyan is n\u00e9z ki pontosan:<\/p>\n<p>\u00c1ll\u00edtsuk le a DFS replik\u00e1ci\u00f3t mindenhol<\/p>\n<blockquote><p>net stop dfsr<\/p><\/blockquote>\n<p>Nyissunk meg egy ADSI editort \u00e9s m\u00f3dos\u00edtsuk az al\u00e1bbit(egyszer\u0171s\u00e9g kedv\u00e9\u00e9rt \u00e9rdemes ezt a kiszemelt masteren csin\u00e1lni):<\/p>\n<blockquote><p>CN=SYSVOL Subscription,CN=Domain System Volume,CN=DFSR-LocalSettings,CN=<em>&lt;amelyik a master lesz&gt;<\/em>,OU=Domain Controllers,DC=<em>&lt;domain&gt;<\/em><\/p><\/blockquote>\n<p>K\u00e9t attrib\u00fatumot \u00edrjunk \u00e1t:<\/p>\n<blockquote><p>msDFSR-Enabled=FALSE<br \/>\nmsDFSR-options=1<\/p><\/blockquote>\n<p>Ezzel letiltottuk a szinkront \u00e9s kinevezt\u00fck masternek.<a href=\"\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/adsieditor_authoritivedfsReplication.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-246\" src=\"\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/adsieditor_authoritivedfsReplication-300x165.png\" alt=\"ADSI editorban kb. \u00edgy n\u00e9z ki\" width=\"300\" height=\"165\" srcset=\"https:\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/adsieditor_authoritivedfsReplication-300x165.png 300w, https:\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/adsieditor_authoritivedfsReplication-1024x564.png 1024w, https:\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/adsieditor_authoritivedfsReplication.png 1086w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Az \u00f6sszes t\u00f6bbi szerveren a Domain Controllers alatt \u00e1ll\u00edtsuk \u00e1t az<\/p>\n<blockquote><p>msDFSR-Enabled=FALSE<\/p><\/blockquote>\n<p>attrib\u00fatumot.<\/p>\n<p>Replik\u00e1ljuk le a m\u00f3dos\u00edt\u00e1st(\u00e9n ezt a m\u00e1sik szerveren nyomtam, nem ahol az ADSI editor futott, de l\u00e9nyegtelen, \u00fagyis ellen\u0151r\u00edzz\u00fck ezut\u00e1n):<\/p>\n<blockquote><p>repadmin \/syncall \/AdP<\/p><\/blockquote>\n<p>A masteren elindulhat a DFSR replik\u00e1ci\u00f3s szolg\u00e1ltat\u00e1s:<\/p>\n<blockquote><p>net start dfsr<\/p><\/blockquote>\n<p>Event viewer nyissuk meg a masteren \u00e9s az &#8220;Applications \u00e9s Services Logs&#8221; alatt a &#8220;DFS replication&#8221; alatt n\u00e9zz\u00fck a 4114-es sz\u00e1m\u00fa bejegyz\u00e9st ahol j\u00f3 esetben ilyet kell l\u00e1ssunk:<\/p>\n<blockquote><p>The replicated folder at local path C:\\Windows\\SYSVOL\\domain has been disabled. The replicated folder will not participate in replication until it is enabled. All data in the replicated folder will be treated as pre-existing data when this replicated folder is enabled.<\/p><\/blockquote>\n<p>Engedj\u00fck vissza az ADSI-ban a masternek a replik\u00e1l\u00e1st:<\/p>\n<blockquote><p>msDFSR-Enabled=TRUE<\/p><\/blockquote>\n<p>Nyomjunk egy c\u00edmt\u00e1r replik\u00e1t:<\/p>\n<blockquote><p>repadmin \/syncall \/AdP<\/p><\/blockquote>\n<p>A masteren pedig egy DFSR szinkront a c\u00edmt\u00e1rb\u00f3l:<\/p>\n<blockquote><p>dfsrdiag PollAD<\/p><\/blockquote>\n<p>Eventviewerben keress\u00fck az el\u0151z\u0151 helyen a 4602-es bejegyz\u00e9st, hogy sikeresen inicializ\u00e1lta a DFS-t\u00a0 \u00e9s, hogy \u0151 a master (ez most csak magyarul van meg):<\/p>\n<blockquote><p>Az elosztott f\u00e1jlrendszer replik\u00e1ci\u00f3s szolg\u00e1ltat\u00e1sa sikeresen inicializ\u00e1lta a(z) C:\\Windows\\SYSVOL\\domain\u00a0 helyi el\u00e9r\u00e9si \u00faton tal\u00e1lhat\u00f3 SYSVOL replik\u00e1lt mapp\u00e1t. Ez a tag a replik\u00e1lt mappa\u00a0 kijel\u00f6lt els\u0151dleges tagja. Felhaszn\u00e1l\u00f3i m\u0171velet nem sz\u00fcks\u00e9ges.\u00a0 A SYSVOL megoszt\u00e1s megl\u00e9t\u00e9nek ellen\u0151rz\u00e9s\u00e9hez nyisson egy parancssori ablakot,\u00a0 \u00e9s \u00edrja be a &#8220;net share&#8221; parancsot.<\/p><\/blockquote>\n<p>Ezekut\u00e1n az \u00f6sszes t\u00f6bbi DC-n ind\u00edthat\u00f3 a DFSR<\/p>\n<blockquote><p>net start dfsr<\/p><\/blockquote>\n<p>majd az ADSI editorban nyomhatjuk a<\/p>\n<blockquote><p>msDFSR-Enabled=TRUE<\/p><\/blockquote>\n<p>attrib\u00fatumot ut\u00e1na pedig olvassuk ki a c\u00edmt\u00e1rb\u00f3l a konfigot:<\/p>\n<blockquote><p>dfsrdiag \/pollad<\/p><\/blockquote>\n<p>Less\u00fck az eventviewer a 4614-es bejegyz\u00e9s ut\u00e1n:<\/p>\n<blockquote><p>The DFS Replication service initialized SYSVOL at local path C:\\Windows\\SYSVOL\\domain and is waiting to perform initial replication&#8230;..<\/p><\/blockquote>\n<p>Amit k\u00f6vetni fog egy rakat 4414-es:<\/p>\n<blockquote><p>The DFS Replication service detected that a file was changed on multiple servers&#8230;..<\/p><\/blockquote>\n<p>Majd z\u00e1r\u00e1sk\u00e9ppen egy 4604-es<\/p>\n<blockquote><p>The DFS Replication service successfully initialized the SYSVOL replicated folder at local path C:\\Windows\\SYSVOL\\domain. This member has completed initial synchronization of SYSVOL with partner dc1.CONTOSO.local.\u00a0 To check for the presence of the SYSVOL share, open a command prompt window and then type &#8220;net share&#8221;.<\/p><\/blockquote>\n<p>Val\u00f3ban, mostm\u00e1r mindenhol minden policy megtal\u00e1lhat\u00f3.<\/p>\n<p>M\u00e1r csak egy j\u00f3 monitoringot kell erre a DFSR-re kital\u00e1lni.<\/p>\n<h1 id=\"ad-dfsr-incident-tldr\">tl;dr<\/h1>\n<p>Google husz\u00e1roknak :p<\/p>\n<p>Nem megy az AD replika a k\u00f6vetkez\u0151 hib\u00e1val: The target principal name is incorrect<\/p>\n<p>Megold\u00e1s: net stop kdc, repadmin \/syncall, net start kdc<\/p>\n<p>Nem megy DFSR SYSVOL<\/p>\n<p>Megold\u00e1s: non-authoritive vagy authoritive szinkron, ehhez <a href=\"#ad-dfsr-incident-authoritiveDFSR\">fentebb<\/a> a le\u00edr\u00e1s<\/p>\n<h1>Megjegyz\u00e9s &#8211; 2021.03.26<\/h1>\n<p>\u00dajfent el\u0151j\u00f6tt a DFS szinkroniz\u00e1ci\u00f3s probl\u00e9ma, mindk\u00e9t f\u00e9l szinkroniz\u00e1ci\u00f3s \u00e1llapota 2-es state k\u00f3ddal volt (initial sync). Szemmel l\u00e1that\u00f3an bizonyos \u00fajabb GPO-k hi\u00e1nyoztak is az egyik oldalr\u00f3l. Szerencs\u00e9re GPO m\u00f3dos\u00edt\u00e1s csak az egyik DC-n t\u00f6rt\u00e9nik, \u00edgy nem kellett \u00f6sszef\u00e9s\u00fclni \u0151ket. Egy sima non-authoritive szinkron ut\u00e1n mindk\u00e9t oldalon megvoltak az objectek de a master kiv\u00e9tel\u00e9ve az \u00f6sszes t\u00f6bbi (1 db) replika maradt 2-es state-ben.<\/p>\n<p>Ilyenkor seg\u00edts\u00e9get adhat a Group Policy Management -&gt;Domain -&gt;&lt;domain\u00fcnk neve&gt;-re ha r\u00e1kattintunk majd jobb als\u00f3 sarokban Detect Now:<\/p>\n<div id=\"attachment_280\" style=\"width: 310px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/GPOEditor.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-280\" class=\"size-medium wp-image-280\" src=\"https:\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/GPOEditor-300x185.png\" alt=\"SYSVOL DFS Status\" width=\"300\" height=\"185\" srcset=\"https:\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/GPOEditor-300x185.png 300w, https:\/\/debnar.org\/wp\/wp-content\/uploads\/2020\/08\/GPOEditor.png 764w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-280\" class=\"wp-caption-text\">SYSVOL DFS status<\/p><\/div>\n<p>Ha van hib\u00e1nk akkor ki fogja \u00edrni fel\u00fclre. Ide \u00edrta nekem, hogy az egyik GPO ACL-je nem egyezik mindenhol. Megn\u00e9zve senkinek nem volt hozz\u00e1f\u00e9r\u00e9se a f\u00e1jlhoz. M\u00f3dos\u00edtottam mindenhol k\u00e9zzel (vagy minden replik\u00e1n let\u00f6r\u00f6lni, masteren korrig\u00e1lni, majd mehet egy (non-)authoritive sync.<\/p>\n<p>Ezut\u00e1n minden SYSVOL DFS Group stateje n\u00e9gyes k\u00f3dot kapott (normal).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>J\u00falius v\u00e9g\u00e9n volt egy \u00e1ramsz\u00fcnet ami k\u00e9t DC-t \u00e9rintett (sz\u00fcnetmentes nem b\u00edrta szusszal). A &#8220;PDC&#8221;-nek szerencs\u00e9re nem t\u00f6rt\u00e9nt baja, no meg arr\u00f3l van ment\u00e9s is persze, \u00edgy elkezdtem kidebugolni a probl\u00e9m\u00e1t amib\u0151l azt\u00e1n kiesett 2 hiba is. tl;dr a v\u00e9g\u00e9n<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[82,4,1,75],"tags":[83,81,79,80,77],"class_list":["post-242","post","type-post","status-publish","format-standard","hentry","category-activedirectory","category-szerver-felugyelet","category-uncategorized","category-windows","tag-activedirectory","tag-aramszunet","tag-dfsr","tag-replication","tag-sysvol"],"_links":{"self":[{"href":"https:\/\/debnar.org\/wp\/index.php?rest_route=\/wp\/v2\/posts\/242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/debnar.org\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/debnar.org\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/debnar.org\/wp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/debnar.org\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=242"}],"version-history":[{"count":8,"href":"https:\/\/debnar.org\/wp\/index.php?rest_route=\/wp\/v2\/posts\/242\/revisions"}],"predecessor-version":[{"id":281,"href":"https:\/\/debnar.org\/wp\/index.php?rest_route=\/wp\/v2\/posts\/242\/revisions\/281"}],"wp:attachment":[{"href":"https:\/\/debnar.org\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/debnar.org\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/debnar.org\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}