Real-World Scenarios
Cross-Site Replication Delays: Network Latency and Site Link Configuration¶
Problem¶
Cross-site replication delays occur when replication between domain controllers (DCs) in different sites is significantly slower than expected, often due to network latency, suboptimal site link configurations, or bandwidth limitations.
Symptoms¶
- Replication latency exceeding 15 minutes.
repadmin /replsumshowing "replicated" status but delayed timestamps.- Users in remote sites experiencing stale password caches or permission issues.
Resolution Steps¶
- Verify Site Link Costs:
Use the Active Directory Sites and Services console to ensure site links have appropriate costs. Lower costs prioritize faster replication.
- Optimize Site Link Bandwidth:
Adjust the "Maximum Number of Replications per Site Link" setting to avoid congestion.
- Force Replication:
Userepadmin /replicateto manually trigger replication between specific DCs.
- Monitor Network Health:
Usepingandtracertto identify network bottlenecks between sites.
Partial Replication Failures: DNS Resolution and Schema Issues¶
Problem¶
Partial replication occurs when some directory data fails to replicate, often due to DNS misconfigurations, schema inconsistencies, or inaccessible replication partners.
Symptoms¶
repadmin /showreplshowing "partial" status for specific NCs.- Users unable to authenticate or access resources due to missing attribute updates.
- Event ID 13516 in Event Viewer (replication failure).
Resolution Steps¶
- Check DNS Resolution:
Ensure DCs can resolve each other via SRV records. Usenslookupto verify:
If records are missing, configure them using DNS management tools likednscmdor DNS Manager. - Validate Schema Consistency:
Rundcdiag /test:schemato check for schema conflicts.
- Force Schema Replication:
Userepadmin /syncallto force replication of the schema partition.
- Check Replication Partners:
Ensure replication partners are listed inrepadmin /showrepland are reachable.
Replication Conflicts: Attribute Overwrites and Manual Resolution¶
Problem¶
Replication conflicts arise when two DCs update the same attribute simultaneously, leading to data inconsistencies.
Symptoms¶
- Event ID 13517 (replication conflict detected).
- Users with conflicting attribute values (e.g., password hashes, group memberships).
repadmin /showreplshowing "conflict" in replication metadata.
Resolution Steps¶
- Identify Conflicting Attributes:
Userepadmin /showreplto locate conflicting NCs and attributes.
- Resolve Conflicts Manually:
- Use
repadmin /replto force a re-replication of the affected NC. - Avoid using
ntdsutilfor conflict resolution, as it is designed for database maintenance tasks. - Prevent Future Conflicts:
Enforce stricter replication intervals usingrepadmin /setto reduce overlap.
Key takeaways¶
- Use
repadmin /replsumanddcdiagfor quick replication health checks. - DNS resolution is critical for cross-site replication; validate SRV records regularly.
- Force replication with
repadmin /replicateorrepadmin /syncallfor partial failures. - Resolve conflicts by re-replicating affected NCs using
repadmin /repl. - Monitor network latency and site link costs to prevent cross-site delays.