DalayLamer 1. С железом все ок.
2. Тут обнаружилась трабла с синхронизацией
Вот сами тесты:
[more=DcDiag с первого DC]C:\Documents and Settings\admin>"C:\Program Files\Support Tools\dcdiag.exe"
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site\IT-1
Starting test: Connectivity
......................... IT-1 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site\IT-1
Starting test: Replications
[Replications Check,IT-1] A recent replication attempt failed:
From IT-6 to IT-1
Naming Context: CN=Schema,CN=Configuration,DC=domain,DC=local
The replication generated an error (8456):
Win32 Error 8456
The failure occurred at 2009-10-22 11:58.34.
The last success occurred at 2009-09-15 10:47.45.
889 failures have occurred since the last success.
Replication has been explicitly disabled through the server options.
[Replications Check,IT-1] A recent replication attempt failed:
From IT-6 to IT-1
Naming Context: CN=Configuration,DC=domain,DC=local
The replication generated an error (8456):
Win32 Error 8456
The failure occurred at 2009-10-22 11:58.34.
The last success occurred at 2009-09-15 12:12.32.
3408 failures have occurred since the last success.
Replication has been explicitly disabled through the server options.
[Replications Check,IT-1] A recent replication attempt failed:
From IT-6 to IT-1
Naming Context: DC=domain,DC=local
The replication generated an error (8456):
Win32 Error 8456
The failure occurred at 2009-10-22 12:16.30.
The last success occurred at 2009-09-15 12:22.48.
19721 failures have occurred since the last success.
Replication has been explicitly disabled through the server options.
......................... IT-1 passed test Replications
Starting test: NCSecDesc
......................... IT-1 passed test NCSecDesc
Starting test: NetLogons
......................... IT-1 passed test NetLogons
Starting test: Advertising
......................... IT-1 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... IT-1 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... IT-1 passed test RidManager
Starting test: MachineAccount
......................... IT-1 passed test MachineAccount
Starting test: Services
......................... IT-1 passed test Services
Starting test: ObjectsReplicated
......................... IT-1 passed test ObjectsReplicated
Starting test: frssysvol
There are errors after the SYSVOL has been shared.
The SYSVOL can prevent the AD from starting.
......................... IT-1 passed test frssysvol
Starting test: kccevent
......................... IT-1 passed test kccevent
Starting test: systemlog
......................... IT-1 passed test systemlog
Running enterprise tests on : domain.local
Starting test: Intersite
......................... domain.local passed test Intersite
Starting test: FsmoCheck
......................... domain.local passed test FsmoCheck
C:\Documents and Settings\admin>[/more]
[more=NetDiag с первого DC]Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.
C:\Documents and Settings\admin>"C:\Program Files\Resource Kit\NETDIAG.EXE"
.....................................
Computer Name: IT-1
DNS Host Name: it-1.domain.local
System info : Windows 2000 Server (Build 2195)
Processor : x86 Family 15 Model 2 Stepping 9, GenuineIntel
List of installed hotfixes :
KB829558
KB842773
KB893803v2
KB957097
KB958644
KB958687
MSI30-KB884016
Q147222
Netcard queries test . . . . . . . : Passed
[WARNING] The net card 'RAS Async Adapter' may not be working because it has
not received any packets.
Per interface results:
Adapter : Local Area Connection
Netcard queries test . . . : Passed
Host Name. . . . . . . . . : it-1
IP Address . . . . . . . . : 192.168.1.100
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.1.47
Dns Servers. . . . . . . . : 127.0.0.1
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Passed
NetBT name test. . . . . . : Passed
WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{CDE43020-B9D9-4F81-93DF-BD42186285D4}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Passed
NetBT name test. . . . . . . . . . : Passed
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server '127.0.0.1' a
nd other DCs also have some of the names registered.
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{CDE43020-B9D9-4F81-93DF-BD42186285D4}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{CDE43020-B9D9-4F81-93DF-BD42186285D4}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Skipped
Kerberos test. . . . . . . . . . . : Passed
LDAP test. . . . . . . . . . . . . : Passed
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Passed
IPSec policy service is active, but no policy is assigned.
The command completed successfully
C:\Documents and Settings\admin>[/more]
[more=DcDiag с второго DC]C:\Documents and Settings\admin>C:\WINDOWS\ServicePackFiles\i386\dcdiag.exe
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site\IT-6
Starting test: Connectivity
......................... IT-6 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site\IT-6
Starting test: Replications
[Replications Check,IT-6] Inbound replication is disabled.
To correct, run "repadmin /options IT-6 -DISABLE_INBOUND_REPL"
[Replications Check,IT-6] Outbound replication is disabled.
To correct, run "repadmin /options IT-6 -DISABLE_OUTBOUND_REPL"
......................... IT-6 failed test Replications
Starting test: NCSecDesc
......................... IT-6 passed test NCSecDesc
Starting test: NetLogons
......................... IT-6 passed test NetLogons
Starting test: Advertising
Warning: DsGetDcName returned information for \\it-1.domain.local, whe
n we were trying to reach IT-6.
Server is not responding or is not considered suitable.
......................... IT-6 failed test Advertising
Starting test: KnowsOfRoleHolders
......................... IT-6 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... IT-6 passed test RidManager
Starting test: MachineAccount
......................... IT-6 passed test MachineAccount
Starting test: Services
NETLOGON Service is paused on [IT-6]
......................... IT-6 failed test Services
Starting test: ObjectsReplicated
......................... IT-6 passed test ObjectsReplicated
Starting test: frssysvol
......................... IT-6 passed test frssysvol
Starting test: frsevent
......................... IT-6 passed test frsevent
Starting test: kccevent
......................... IT-6 passed test kccevent
Starting test: systemlog
......................... IT-6 passed test systemlog
Starting test: VerifyReferences
......................... IT-6 passed test VerifyReferences
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : domain
Starting test: CrossRefValidation
......................... domain passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... domain passed test CheckSDRefDom
Running enterprise tests on : domain.local
Starting test: Intersite
......................... domain.local passed test Intersite
Starting test: FsmoCheck
......................... domain.local passed test FsmoCheck
C:\Documents and Settings\admin>[/more]
[more=NetDiag с второго DC]Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.
C:\Documents and Settings\admin>netdiag
'netdiag' is not recognized as an internal or external command,
operable program or batch file.
C:\Documents and Settings\admin>D:\!Instull\support\netdiag.exe
....................................
Computer Name: IT-6
DNS Host Name: it-6.domain.local
System info : Microsoft Windows Server 2003 R2 (Build 3790)
Processor : x86 Family 6 Model 15 Stepping 13, GenuineIntel
List of installed hotfixes :
KB958644
Q147222
Netcard queries test . . . . . . . : Passed
[WARNING] The net card '1394 Net Adapter' may not be working because it has
not received any packets.
Per interface results:
Adapter : Local Area Connection
Netcard queries test . . . : Passed
Host Name. . . . . . . . . : it-6
IP Address . . . . . . . . : 192.168.1.106
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.1.47
Dns Servers. . . . . . . . : 192.168.1.100
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Passed
NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenge
r Service', <20> 'WINS' names is missing.
WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{FDFE85FF-4844-4C04-83A6-CBEDD67B0B09}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Passed
NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server '192.168.1.10
0' and other DCs also have some of the names registered.
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{FDFE85FF-4844-4C04-83A6-CBEDD67B0B09}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{FDFE85FF-4844-4C04-83A6-CBEDD67B0B09}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Passed
Secure channel for domain 'domain' is to '\\it-1.domain.local'.
Kerberos test. . . . . . . . . . . : Passed
LDAP test. . . . . . . . . . . . . : Passed
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Skipped
Note: run "netsh ipsec dynamic show /?" for more detailed information
The command completed successfully
C:\Documents and Settings\admin>[/more]
[more=NetDiag с Exchange сервера]Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.
C:\Documents and Settings\admin.domain>"C:\Program Files\Resource Kit\NETDIAG.E
XE"
....................................
Computer Name: IT3
DNS Host Name: it3.domain.local
System info : Windows 2000 Server (Build 2195)
Processor : x86 Family 15 Model 15 Stepping 2, AuthenticAMD
List of installed hotfixes :
KB822343
KB823182
KB823559
KB824105
KB825119
KB826232
KB828035
KB828749
KB832353
KB832359
KB841356
KB842773
KB883935
KB885836
KB890046
KB893803v2
KB896423
KB896424
KB902400
KB904706
KB905414
KB905495-IE6SP1-20050805.184113
KB905915-IE6SP1-20051122.175908
KB908523
KB908531
KB911280
KB911564
KB913580
KB914388
KB914389
KB917008
KB917422
KB917537
KB917736
KB917953
KB918118
KB920213
KB920670
KB920683
KB920685
KB920958
KB921398
KB922582
KB923191
KB923414
KB923689
KB923694-OE6SP1-20061106.120000
KB923980
KB924191
KB924270
KB924667
KB925398_WMP64
KB926436
KB928090-IE6SP1-20070125.120000
KB928843
KB929969-IE6SP1-20061220.120000
KB957097
KB958644
KB958687
Q147222
Update Rollup 1
Netcard queries test . . . . . . . : Passed
Per interface results:
Adapter : Local Area Connection 3
Netcard queries test . . . : Passed
Host Name. . . . . . . . . : it3
IP Address . . . . . . . . : 192.168.1.103
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.1.47
Dns Servers. . . . . . . . : 192.168.1.100
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Passed
NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenge
r Service', <20> 'WINS' names is missing.
WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{7530D17C-2AC0-418D-8025-F9340146FE92}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Passed
NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{7530D17C-2AC0-418D-8025-F9340146FE92}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{7530D17C-2AC0-418D-8025-F9340146FE92}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Failed
Secure channel for domain 'domain' is to '\\it-1.domain.local'.
[FATAL] Cannot test secure channel for domain 'domain' to DC 'it-6'. [ERROR
_SERVICE_NOT_ACTIVE]
Kerberos test. . . . . . . . . . . : Passed
LDAP test. . . . . . . . . . . . . : Passed
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Passed
IPSec policy service is active, but no policy is assigned.
The command completed successfully
C:\Documents and Settings\admin.domain>[/more]
3. еще буду делать...