Hi All,<\/p>\n
I have 1 site out of 3 that is having replication errors. Seems to be a Kerberos issue with error -2146893022. Upon many Google searches over the last month I have come to the conclusion that all existing articles solutions on this error do not work in this situation. THe topology looks like the following:<\/p>\n
Site 1: 1 Windows 2016 Domain Controller<\/p>\n
Site 2: 1 Windows 2016 DC and 1 Windows 2012 DC<\/p>\n
Site 3: 1 Windows 2012 DC (I had 1 2016 DC here but demoted it and have not been able to re-promote it)<\/p>\n
Sites 1 & 2 are replicating AD no problem. Site 3 has an unreplicated copy of the AD and I cannot get the DC to replicate. It reports that the Windows 2016 DC in Site and Aite 1 are unreachable. I downloaded and ran the Port Query tool and it connects to both DC’s on ports 53, 88 & 389.<\/p>\n
I had originally had a Windows 2003 server in Site1 That was the original AD server for this forest. It died and I have made sure that all of the remaining junk from that server was cleaned out of AD and DNS. Not sure what else to consider at this point. DCDIAG reports that RPC Bind fails due to Target Principal Name being incorrect and the password is bad. I have reset the password on both DC’s in Site 1 and Site 2 many times to no avail.<\/p>\n
Each location is connected by Site-to-Site VPN<\/p>\n
Thanks for any help,
\nDon<\/p>","upvoteCount":0,"answerCount":36,"datePublished":"2024-07-08T23:37:42.095Z","author":{"@type":"Person","name":"donmangiarelli4968","url":"https://community.spiceworks.com/u/donmangiarelli4968"},"suggestedAnswer":[{"@type":"Answer","text":"
Hi All,<\/p>\n
I have 1 site out of 3 that is having replication errors. Seems to be a Kerberos issue with error -2146893022. Upon many Google searches over the last month I have come to the conclusion that all existing articles solutions on this error do not work in this situation. THe topology looks like the following:<\/p>\n
Site 1: 1 Windows 2016 Domain Controller<\/p>\n
Site 2: 1 Windows 2016 DC and 1 Windows 2012 DC<\/p>\n
Site 3: 1 Windows 2012 DC (I had 1 2016 DC here but demoted it and have not been able to re-promote it)<\/p>\n
Sites 1 & 2 are replicating AD no problem. Site 3 has an unreplicated copy of the AD and I cannot get the DC to replicate. It reports that the Windows 2016 DC in Site and Aite 1 are unreachable. I downloaded and ran the Port Query tool and it connects to both DC’s on ports 53, 88 & 389.<\/p>\n
I had originally had a Windows 2003 server in Site1 That was the original AD server for this forest. It died and I have made sure that all of the remaining junk from that server was cleaned out of AD and DNS. Not sure what else to consider at this point. DCDIAG reports that RPC Bind fails due to Target Principal Name being incorrect and the password is bad. I have reset the password on both DC’s in Site 1 and Site 2 many times to no avail.<\/p>\n
Each location is connected by Site-to-Site VPN<\/p>\n
Thanks for any help,
\nDon<\/p>","upvoteCount":0,"datePublished":"2024-07-08T23:37:42.222Z","url":"https://community.spiceworks.com/t/ad-replication-woes/1094047/1","author":{"@type":"Person","name":"donmangiarelli4968","url":"https://community.spiceworks.com/u/donmangiarelli4968"}},{"@type":"Answer","text":"
How is DNS set up on your DC NICs? Is each DC pointing at another for primary and itself secondary?<\/p>\n