Networking Forums

Networking Forums > Computer Networking > Windows Networking > Atypical TCP/IP Traffic from Active Directory

Reply
Thread Tools Display Modes

Atypical TCP/IP Traffic from Active Directory

 
 
Billy Leung
Guest
Posts: n/a

 
      02-09-2007, 01:29 AM
Hi all,

I am having problem of replication.

About one week ago, I retored the drive C from an image file. This image
file was created by a software Drive Image which is similar to Ghost. But
this is not for server.

Everything seems ok after restore. However, I noticed from the event viewer
that the replication with other DC was not successful. I tried to manually
replicate in "Active Directory Sites and Services". But it failed with an
error message pop up, saying "The destination server is currently rejecting
replication requests." Then, I tried to use command REPADMIN /OPTIONS
server_name -DISABLE_INBOUND_REPL and -DISABLE_OUTBOUND_REPL. It does not
work.

I tried to restart the server, and get the error event as follows:

Before windows shutdown:-

Event ID: 8250
The Win32 API call 'DsGetDCNameW' returned error code [0x862] The specified
component could not be found in the configuration information. The service
could not be initialized. Make sure that the operating system was installed
properly.

Event ID: 8026
LDAP Bind was unsuccessful on directory server_name for distinguished name
''. Directory returned error:[0x51] Server Down.

After restart:-

Event ID: 1000
#50070: Unable to connect to the database STS_Config on
server_name\SharePoint. Check the database connection information and make
sure that the database server is running.

Event ID: 8231
Permanent failure reported by policy group provider for 'CN=System
Policies,CN=XXXXXXXXXXX,CN=Microsoft
Exchange,CN=Services,CN=Configuration,DC=XXXXXXXXX XX,DC=local':'MAD.EXE',
error=80040103. Taking provider offline.

Event ID: 2103
The Active Directory database has been restored using an unsupported
restoration procedure. Active Directory will be unable to log on users while
this condition persists. As a result, the Net Logon service has paused. User
Action See previous event logs for details.

Event ID: 2103
Process MAD.EXE (PID=2624). All Global Catalog Servers in use are not
responding:
dc1
dc2

Event ID: 7022
The Microsoft Exchange IMAP4 service hung on starting.

Event ID: 7022
The Microsoft Exchange Routing Engine service hung on starting.

Event ID: 8197
Error initializing session for virtual machine SBS-2003. The error number is
0x8004011d. Make sure Microsoft Exchange Store is running.

Event ID: 5000
Unable to initialize the Microsoft Exchange Information Store service. -
Error 0x80004005.

Event ID: 1121
Error 0x80004005 connecting to the Microsoft Active Directory.

Event ID: 7024
The Microsoft Exchange Information Store service terminated with
service-specific error 0 (0x0).

Event ID: 7001
The Microsoft Connector for POP3 Mailboxes service depends on the Microsoft
Exchange Information Store service which failed to start because of the
following error: The service has returned a service-specific error code.

Event ID: 1194
Accept clients on external interface MAPIRPC failed with error 0x4b1.


After entering Windows, I have to start the service of Information Store
manually.

I believe later on, our user in the company will end up unable to logon.
Please help. Any advice will be greatly appreciated.



PS:

One more thing that may be helpful to understand what cause the problem. I
use the Server Perfomance Advisor (Microsoft) to collect the Active
Directory data. The report indicates that there is atypical TCP/IP traffic
from active directory. The warning message is:

Active Directory typically uses Lsass.exe or Ldifde.exe to send data. Active
Directory is sending data using other processes and should be investigated.




Billy


 
Reply With Quote
 
 
 
 
Andrei Ungureanu [MVP]
Guest
Posts: n/a

 
      02-09-2007, 04:54 PM
Remove AD from that server and dcpromo again.
http://support.microsoft.com/default...b;en-us;875495
Event 2103 says all.

--
Regards,
Andrei Ungureanu
www.eventid.net
Test our new EventReader!
http://www.altairtech.ca/eventreader...lt2.asp?ref=au


"Billy Leung" <(E-Mail Removed)> wrote in message
news:%23Vw0ZI$(E-Mail Removed)...
> Hi all,
>
> I am having problem of replication.
>
> About one week ago, I retored the drive C from an image file. This image
> file was created by a software Drive Image which is similar to Ghost. But
> this is not for server.
>
> Everything seems ok after restore. However, I noticed from the event
> viewer that the replication with other DC was not successful. I tried to
> manually replicate in "Active Directory Sites and Services". But it failed
> with an error message pop up, saying "The destination server is currently
> rejecting replication requests." Then, I tried to use command REPADMIN
> /OPTIONS server_name -DISABLE_INBOUND_REPL and -DISABLE_OUTBOUND_REPL. It
> does not work.
>
> I tried to restart the server, and get the error event as follows:
>
> Before windows shutdown:-
>
> Event ID: 8250
> The Win32 API call 'DsGetDCNameW' returned error code [0x862] The
> specified component could not be found in the configuration information.
> The service could not be initialized. Make sure that the operating system
> was installed properly.
>
> Event ID: 8026
> LDAP Bind was unsuccessful on directory server_name for distinguished name
> ''. Directory returned error:[0x51] Server Down.
>
> After restart:-
>
> Event ID: 1000
> #50070: Unable to connect to the database STS_Config on
> server_name\SharePoint. Check the database connection information and
> make
> sure that the database server is running.
>
> Event ID: 8231
> Permanent failure reported by policy group provider for 'CN=System
> Policies,CN=XXXXXXXXXXX,CN=Microsoft
> Exchange,CN=Services,CN=Configuration,DC=XXXXXXXXX XX,DC=local':'MAD.EXE',
> error=80040103. Taking provider offline.
>
> Event ID: 2103
> The Active Directory database has been restored using an unsupported
> restoration procedure. Active Directory will be unable to log on users
> while this condition persists. As a result, the Net Logon service has
> paused. User Action See previous event logs for details.
>
> Event ID: 2103
> Process MAD.EXE (PID=2624). All Global Catalog Servers in use are not
> responding:
> dc1
> dc2
>
> Event ID: 7022
> The Microsoft Exchange IMAP4 service hung on starting.
>
> Event ID: 7022
> The Microsoft Exchange Routing Engine service hung on starting.
>
> Event ID: 8197
> Error initializing session for virtual machine SBS-2003. The error number
> is 0x8004011d. Make sure Microsoft Exchange Store is running.
>
> Event ID: 5000
> Unable to initialize the Microsoft Exchange Information Store service. -
> Error 0x80004005.
>
> Event ID: 1121
> Error 0x80004005 connecting to the Microsoft Active Directory.
>
> Event ID: 7024
> The Microsoft Exchange Information Store service terminated with
> service-specific error 0 (0x0).
>
> Event ID: 7001
> The Microsoft Connector for POP3 Mailboxes service depends on the
> Microsoft Exchange Information Store service which failed to start because
> of the following error: The service has returned a service-specific error
> code.
>
> Event ID: 1194
> Accept clients on external interface MAPIRPC failed with error 0x4b1.
>
>
> After entering Windows, I have to start the service of Information Store
> manually.
>
> I believe later on, our user in the company will end up unable to logon.
> Please help. Any advice will be greatly appreciated.
>
>
>
> PS:
>
> One more thing that may be helpful to understand what cause the problem. I
> use the Server Perfomance Advisor (Microsoft) to collect the Active
> Directory data. The report indicates that there is atypical TCP/IP traffic
> from active directory. The warning message is:
>
> Active Directory typically uses Lsass.exe or Ldifde.exe to send data.
> Active Directory is sending data using other processes and should be
> investigated.
>
>
>
>
> Billy
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Active Directory Sub-net Patrick Whittle Windows Networking 2 10-11-2009 07:45 AM
eap-tls without active directory liolemaire@gmail.com Wireless Internet 2 11-26-2006 07:26 AM
Active Directory and more than 254 IPs Roman Windows Networking 4 11-14-2006 03:14 AM
Forcing Active Directory traffic through Specific NIC? Jane Smith Windows Networking 6 08-13-2005 12:52 AM
Cannot log into active directory paul Windows Networking 0 08-20-2003 09:32 AM



1 2 3 4 5 6 7 8 9 10 11