Networking Forums

Networking Forums > Computer Networking > Windows Networking > IPSEC policy - replication not working

Reply
Thread Tools Display Modes

IPSEC policy - replication not working

 
 
Ketil
Guest
Posts: n/a

 
      06-28-2007, 11:18 AM
Hi,
I have implemented an ipsec policy that makes all traffic between my domain
controllers run over ipsec. This is done through a Group Policy in the domain
controllers OU. The reason for this is that the domain controllers are in
different sites and we will implement firewalls between them. DNS is standard
with all zones as AD integrated.

After activating the policy, everything seems OK. I can run all sorts
oftraffic between domain controllers, and all traffic seems to be flowing
freely. In Ipsec monitor I can see the packet numbers increasing and no
errors at all. But after som minutes, the following error starts poping up in
the Directory Service log on all Domain Controllers:

1311: There is insufficient site connectivity information in Active Directory
Sites and Services for the KCC to create a spanning tree replication
topology.

There is still no errors in ipsec monitor.

The 1311 error disappears again after a while when I disable the ipsec
policies. So it seems as ipsec is the reason for this, and not any other AD
configuration.

Any clues as to what can be the cause of this?
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Need help with ipsec policy Jim H Windows Networking 1 09-05-2008 02:49 PM
IPSec policy on servers connected to 2 networks Stuart Windows Networking 2 11-20-2007 02:59 PM
IPSec Policy Agent closes SMTP Ports PCGenieLA Windows Networking 0 07-16-2005 02:07 PM
IPSEc Policy Agent closes SMTP ports PCGenieLA Windows Networking 0 07-16-2005 02:05 PM
IPSec Policy Agent closes SMTP ports PCGenieLA Windows Networking 0 07-15-2005 10:59 PM



1 2 3 4 5 6 7 8 9 10 11