Arsynic Posted February 27, 2007 Posted February 27, 2007 (edited) Backstory:My company has a WAN consisting of six sites each with a domain controller. We are thinking about acquiring another smaller company with three sites with a WAN of their own. My boss wanted one domain and he wanted all the sites connected to one another. However, since our sites were using old firewalls with some incompatible tunneling protocol the two companies cannot be tied together in a full mesh. I managed to connect all three sites of the other company to our main office's firewall. I then demoted all of the other company's domain controllers and added them to our domain, so now we have a total of nine domain controllers. But that created a replication issue. The three new DC's can only communicate with one of the original DC's due to the incomplete WAN links. Everything worked fine because our main office acted like a "bridge" to the rest of the domain. So while the communication between the DCs weren't complete, the AD database was always up-to-date due to the "bridge" DC. Problem:Recently that "bridge" DC failed. I'm talking complete hardware failure. We could not bring it back to life so now we have a situation where five servers from my company cannot replicate to the other three servers. I tried to remedy this by installing Windows 2000 server on a temporary DC. The problem I have now is that the new DC can see all 8 other DC's, but the three DCs from the other site can't see the new DC. I now have a situation where replication only happens one way on the "bridge". I can get changes from the other three DCs which replicate fine amongst each other but the changes from my company don't show up on their end since there's no inbound replication on the other three serves due to the fact that they don't know the new server exists. Question:How can I manually FORCE the three DCs to recognize the new "bridge" domain controller. I've tried everything. I'm trying to avoid doing a DCpromo and redoing the domain controllers. Is there a way I can get the other company's DCS to see the new one so that I can manually create an inbound replication link? Edited February 27, 2007 by Arsynic
Stoic Joker Posted February 27, 2007 Posted February 27, 2007 Which FSMO roles were held by the DC that died?Have they been seized by the new "Temp" DC?If all domains were under a single forest root, was it the Forest root server that died?Which DCs hold which FSMO roles?
Arsynic Posted February 28, 2007 Author Posted February 28, 2007 Nevermind. I am able to get full communication between sites. However, it still won't replicate. The FSMO roles are all held by one server which all sites are able to communicate with. I manually created a connection object from the site to another DC but it still isn't replicating.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now