I have 9 sites with a Domain Controoler in each site and 2 DCs in my Aurora
site. All sites a connected via a VPN with T1 and/or DSL lines also all
connections are the ,auto-generated. I have not made anything myself.
below is nore detailed information but I have no idea where to start or what
domain controller to make the changes on. Please help if you can.
the 1311 is an error message is
The Knowledge Consistency Checker (KCC) has detected problems with the
following directory partition.
Directory partition:
DC=ForestDnsZones,DC=cmtengr,DC=com
There is insufficient site connectivity information in Active Directory
Sites and Services for the KCC to create a spanning tree replication
topology. Or, one or more domain controllers with this directory partition
are unable to replicate the directory partition information. This is
probably due to inaccessible domain controllers.
the 1865 is an error message is
The Knowledge Consistency Checker (KCC) was unable to form a complete
spanning tree network topology. As a result, the following list of sites
cannot be reached from the local site.
Sites:
CN=RockfordOffice,CN=Sites,CN=Configuration,DC=cmtengr,DC=com
the 1566 is an error message is
All domain controllers in the following site that can replicate the
directory partition over this transport are currently unavailable.
Site:
CN=RockfordOffice,CN=Sites,CN=Configuration,DC=cmtengr,DC=com
Directory partition:
CN=Configuration,DC=cmtengr,DC=com
Transport:
CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=cmtengr,DC=com
I also used RepAdmin /replsummary and got this info
Source DC largest delta fails/total %% error
ARRPRINT 25m:39s 0 / 20 0
CHIPRINT 25m:33s 0 / 10 0
CMTDC1 29m:08s 0 / 30 0
COLPRINT 25m:32s 0 / 10 0
EDWPRINT 25m:37s 0 / 10 0
INDPRINT 25m:34s 0 / 10 0
PIAPRINT 25m:30s 0 / 10 0
RFDPRINT 23m:04s 8 / 40 20 (8442) The replication
s...
SPIPRINT 25m:31s 0 / 10 0
STLPRINT 25m:33s 0 / 10 0
I have been researchign the problem on and off for several months. I
think that there is a line you can add to the cisco routers to fix
this problem. something about adding "crypto ipsec df-bit clear" to
your ciscos (if you have them) which i got from here:
http://x220.minasi.com/forum/topic.asp?TOPIC_ID=9047
Please reply to this if this solves your issue. I am trying to
convince the people that administer our cisco's to try but they are
lazy and inept. Unfortunately I do not have access to manage the
routers myself. If you can give me a positive report that this solves
the issue, I can use it as more evidence in my fight with the cisco
admins.