Hi All,
After having had a DC disconnected for a couple of months, i'm having
trouble replicating with it.
I have 2 domain controllers. One of them (DC1) was shipped to a remote
site, so I followed the instructions in:
Preparing an Existing Domain Controller for Shipping and Long-Term
Disconnection:
http://www.microsoft.com/technet/pro...c0fc9cd77.mspx
And:
Reconnecting a Domain Controller After a Long-Term Disconnection:
http://www.microsoft.com/technet/pro...009fc66d1.mspx
When the shipped server was powered back on, it was running for a week
or so, before being able to reach the local domain controller.
Now the two domain controllers are finally able to see each other over
a VPN tunnel, but there seems to be some problems replicating.
When trying to replicate manually, i'm getting an error that "The
target principal name is incorrect".
Trying to manage the local DC (DC2) *from* the remote DC (DC1) gives an
"Access Denied" error.
It actually seems as if the replication works from DC1 to DC2, but not
the other way around.
The event log on DC1 gives quite a lot of KRB_AP_ERR_MODIFIED kerberos
errors, so i'm assuming that one of the DCs have had some sort of
machine account change, without the other DC being aware of it.
I think that i have to look into netdom, as stated in several KB
articles.
(disable kerberos, netdom reset, restart, start kerberos)
Any other ideas?
Was just wondering if anyone has any other input to the issue.
As i understand the above articles, i shouldn't have had any problems
reconnecting. What i do think could have been a problem, is that DC1
was allowed to start without being able to talk to the other. Comments
on that?
DC2 is holding all FSMO roles and can actually access DC1 quite fine.
DC1 cannot access anything on DC2
Thanks
--
/Sune
..