Текст описания события ID 1925 отчет не удалось установить связь репликации для следующей изменяемый раздел каталога, и текст описания содержит различающееся имя раздела каталога, назначение Попытка репликации из источника. Код ошибки события предоставляет дополнительные сведения о причине проблемы.
Ниже приведен пример текста события.
Log Name: Directory Service Source: Microsoft-Windows-ActiveDirectory_DomainService Date: 3/12/2008 8:14:13 AM Event ID: 1925 Task Category: Knowledge Consistency Checker Level: Warning Keywords: Classic User: ANONYMOUS LOGON Computer: DC3.contoso.com Description: The attempt to establish a replication link for the following writable directory partition failed. Directory partition: CN=Configuration,DC=contoso,DC=com Source domain controller: CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=contoso,DC=com Source domain controller address: f8786828-ecf5-4b7d-ad12-8ab60178f7cd._msdcs.contoso.com Intersite transport (if any): CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=contoso,DC=com This domain controller will be unable to replicate with the source domain controller until this problem is corrected. User Action Verify if the source domain controller is accessible or network connectivity is available. Additional Data Error value: 1908 Could not find the domain controller for this domain.
Диагностика
Сбой при 1925 идентификатор события содержит ошибку 1908 «Не удалось найти контроллер домена для этого домена» в результате проблемы связи между контроллером домена, который вернул ошибку и исходного контроллера домена репликации Active Directory, Получает имя события текст.
Решение
Для решения этой проблемы используйте следующие тесты:
-
Проверьте подключение к глобальной сети
-
Определите максимальный размер пакета и при необходимости изменить.
Проверьте подключение к глобальной сети
Убедитесь, что нет никаких проблем основное подключение к базовой сети между контроллерами домена, особенно если они разделяются связи глобальной сети (WAN) или брандмауэры. Сведения о тестировании проблему такого типа см. в статье 310099 (http://go.microsoft.com/fwlink/?LinkId=69995) и в базе знаний Майкрософт в статье 159211 (http://go.microsoft.com/fwlink/?LinkId=69996)).
Определяет максимальный размер пакета
По умолчанию протокол проверки подлинности Kerberos в Windows 2000, Windows XP, Windows Server 2003, Windows Server 2003 R2, Windows Vista и Windows Server 2008 использует протокол UDP (User Datagram) при данных, помещающихся в пакеты не превышает 2 000 байт. Любые данные, размер которых превышает это значение использует протокол TCP для передачи пакетов. Устройством, таким как брандмауэр сети часто удаляются пакетов из более чем 1500 байт.
Чтобы избежать этой проблемы, можно определить размер пакета, который может разместить в сети. Затем можно редактировать реестр таким образом, что максимальное число байтов для использования UDP наименьшее значение, которое появляется, меньше 8 байт для учетной записи размер заголовка.
Чтобы проверить размер пакетов, которые можно разместить в сети можно использовать команду ping .
Членство в группе Пользователи доменаили эквивалент и Вход в систему направо на контроллере домена являются минимальным требованием для выполнения этой процедуры. Подробные сведения об использовании соответствующих учетных записей и членства в группе в Локальные и доменные группы по умолчанию (http://go.microsoft.com/fwlink/?LinkId=83477).
Чтобы определить наименьший общий размер пакета
-
С конечный контроллер домена проверьте связь с исходного контроллера домена по его IP-адрес. В командной строке введите следующую команду и нажмите клавишу ВВОД:
ping <IP_address> -f -l 1472
-
Из исходного контроллера домена команда в шаге 1 для проверки связи с IP-адресом конечный контроллер домена.
-
Если ping команда завершает в обоих направлениях, каких-либо дополнительных изменений не требуется.
-
Если ping команда не выполняется в любом направлении, монотонно меньшее число, которое используется в -l Чтобы найти наименьшее общий размер пакета, работает параметр между контроллерами домена источника и назначения.
Примечание
Dcdiag.exe содержит следующий метод для выполнения этого теста:
dcdiag /test:CheckSecurityError /s:<SourceDomainControllerName>
Можно изменить реестр, чтобы установить максимальный размер пакетов до значения, которое определяется метод PING минус 8 байт для учета размер заголовка. В качестве альтернативы можно отредактировать реестр, чтобы всегда превышено максимальное число байтов для с помощью протокола UDP и поэтому Kerberos всегда использует протокол TCP.
Можно изменить значение по умолчанию 2 000 байт, изменив параметр реестра MaxPacketSize в HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsaKerberosParameters. Используйте следующую процедуру для изменения этого параметра реестра.
Предупреждение.
Рекомендуется, что вы не следует редактировать непосредственно реестра пока другие альтернативы не существует. Изменения в реестре не проверяются с помощью редактора реестра или с помощью Windows до их применения, и в результате могут быть сохранены неверные значения. Это может привести к неустранимой ошибки в системе. Если возможно, используйте групповую политику или другими средствами Windows, такие как консоль управления (MMC) для выполнения задач, а не непосредственное редактирование реестра. Если необходимо отредактировать реестр, будьте осторожны.
Требования
-
Учетные данные: Минимальным требованием для выполнения этой процедуры является членство в «Администраторы домена»или наличие эквивалентных прав.
-
Инструмент: Regedit.exe
Чтобы изменить максимальный размер пакета
-
В меню Пуск выберите пункт Выполнить, введите команду regedit и нажмите ОК.
-
Перейдите к HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsaKerberosParameters.
-
Изменение — или, если он не существует в области сведений, создание, запись MaxPacketSize следующим образом:
-
Чтобы изменить запись, если она существует в области сведений:
Щелкните правой кнопкой мыши MaxPacketSize, нажмите кнопку Изменитьи затем в поле значение введите 1 , чтобы принудительно Kerberos на использование протокола TCP или значение, установленное для снижения значение, соответствующее максимальный размер.
-
Чтобы создать запись, если она не существует в области сведений:
Щелкните правой кнопкой мыши Параметры, нажмите кнопку Новый параметр DWORD, введите имя MaxPacketSizeи затем перейдите к шагу 3a, чтобы отредактировать запись.
-
-
Нажмите кнопку ОК.
-
Контроллер домена, чтобы это изменение вступило в силу, необходимо перезапустить.
См. также:
Другие ресурсы
Наблюдение и устранение неполадок репликации Active Directory с помощью программы Repadmin
Нужна дополнительная помощь?
Some Background:
OS:Win Server 2012 R2 on both machines
These error messages started occurring after and attempted an installation of a new backup domain controller. There were replications issues between the PDC and the newly installed DC from the beginning (likely due to incorrect configuration during the install).
I ended up performing a forced demotion of the backup DC (DC2), and metadata cleanup on both machines. Again, I installed and promoted the new backup machine to a DC to no avail. Currently all master roles belong to DC1. AD changes made on DC1 are replicated
to DC2, i.e., PW changes. The issue seems to be with DC2 establishing a secure channel with DC1, not the other way around.
Event ID 4:
The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server servermain$. The target name used was E3514235-4B06-11D1-AB04-00C04FC2DCD2/68c402df-a3a0-4a41-8454-0210e86148e8/gps.com@gps.com. This indicates that the target server failed to decrypt
the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This
error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password.
If the server name is not fully qualified, and the target domain (GPS.COM) is different from the client domain (GPS.COM), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.
In this case I diabled the KDC service on DC2 as well cleared out its kerberos tickets. I then performed a PW reset on DC1 using the netdom utility for the administrator account, which went through. Restarted KDC service, power cycled DC2, and the problem was
not corrected.
Some Notes:
— Within AD sites and services (on DC1), I try replicating from DC2 and get the message, «The following occured…The target principal name is incorrect.» The same happens when I try to replicate DC2 to DC1.
— There also appears to be some DNS issues. After checking sites and services, DC1 has NTDS and DNS setting listed underneath it, DC2 only has NTDS setting, not sure if this is standard behavior or not.
— Just to clarify, end-user machines are able to resolve DNS fine, but on DC1 when trying to resolve either a local FQDN or even an outside FQDN, like google.com, I get this error:
google.com
C:UsersAdministrator>nslookup google.com
DNS request timed out.
timeout was 2 seconds.
Server: UnKnown
Address: ::1
DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.
*** Request to UnKnown timed-out
Resolve the name of DC2
Microsoft Windows [Version 6.3.9600]
(c) 2013 Microsoft Corporation. All rights reserved.
C:UsersAdministrator>nslookup GPSDC2
1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa
primary name server = localhost
responsible mail addr = nobody.invalid
serial = 1
refresh = 600 (10 mins)
retry = 1200 (20 mins)
expire = 604800 (7 days)
default TTL = 10800 (3 hours)
Server: UnKnown
Address: ::1
DNS request timed out.
timeout was 2 seconds.
*** Request to UnKnown timed-out
Running these same lookups from end-user host machines on the domain or on DC2 work.
And then there’s error 1925, which I’m guessing is related to the kerberos authentication issue:
The attempt to establish a replication link for the following writable directory partition failed.
Directory partition:
DC=gps,DC=com
Source directory service:
CN=NTDS Settings,CN=GPSDC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gps,DC=com
Source directory service address:
68c402df-a3a0-4a41-8454-0210e86148e8._msdcs.gps.com
Intersite transport (if any):
This directory service will be unable to replicate with the source directory service until this problem is corrected.
User Action
Verify if the source directory service is accessible or network connectivity is available.
Additional Data
Error value:
2148074274 The target principal name is incorrect.
At this point I’ve read most support articles related to these error codes and haven’t found anything that quite addresses the issues I’m experienceing, or at least the solutions tried didn’t work. I welcome any suggestions advice, and will post any log info
that you think will be helpful in solving this issue. Thank you for your time in looking over my notes.
-
10.11.08 10:18
есть два контроллера домена, 2003 SE R2 SP2. все работало нормально, но вдруг перестала работать репликация.
на pdc постоянно сыпется вот эта ошибка 1925 , а на втором контроллере постоянно сообщается, что первый контроллер недоступен по ДНС. бред.
какие есть пути решения проблемы?
IT crowd. старый добрый троллинг.
-
10.11.08 10:53Ответ на сообщение ошибка 1925 при репликации AD на двух DC пользователя whiplash
гы, походу ДНС заглючил…

с первичного:DNS test . . . . . . . . . . . . . : Failed
[WARNING] The DNS entries for this DC are not registered correctly on DNS server ‘127.0.0.1’. Please wait for 30 minutes for DNS server replication.
[FATAL] No DNS servers have the DNS records for this DC registered.со второго:
DNS test . . . . . . . . . . . . . : Failed
[WARNING] The DNS entries for this DC are not registered correctly on DNS server ‘192.168.0.5’. Please wait for 30 minutes for DNS server replication.
[WARNING] The DNS entries for this DC are not registered correctly on DNS server ‘192.168.0.4’. Please wait for 30 minutes for DNS server replication.
[FATAL] No DNS servers have the DNS records for this DC registered.красота какая. вопрос — у нас в сети до создания второго DC было два ДНС сервера — первый 0.4, на фрихе, и второй 0.5, он же PDC. на PDC ессно в качестве ДНС сервера указано 127.0.0.1 . вопрос — а как тогда настраивать ДНС на втором контроллере домена?
IT crowd. старый добрый троллинг.
-
ViT
veteran
Сообщений: 1934
10.11.08 11:44Ответ на сообщение Re: ошибка 1925 при репликации AD на двух DC пользователя whiplash
на первом DC указывай
как первый DNS — настоящий IP этого сервера,
как второй DNS — настоящий IP второго DNS сервера.Соответственно так-же и на втором DC
Потом для начала перезгрузи DNS сервис на первом DC — и посмотри что получится… возможно все заработает.
Если нет, то после этого можешь первый и второй DC перезагрузить — оно должно само что надо зарегистрировать при этом.
А можешь взять утилиту nltest и ей перерегистрировать, либо найти файл C:WindowsSystem32confignetlogon.dns на первом и втором DC и проверить что описанные в этом файлике записи в DNS есть.
удач.
/Нет денег на Зубару?! Зубилы — дёшево, 2км вперед по трассе!!!
Исправлено пользователем ViT (10.11.08 11:45)
-
10.11.08 12:11Ответ на сообщение Re: ошибка 1925 при репликации AD на двух DC пользователя ViT
то есть на двух виндовых ДС — вообще не указывать 0.4 ДНС сервер на фрихе?
1 ДС
0.5
0.202 ДС
0.20
0.5а при этом на всех виндовых рабочих станциях у нас настройки такие —
1 ДНС 0.4 на фрихе
2 ДНС 0.5 PDCтам на фрихе ничо менять не придется?
IT crowd. старый добрый троллинг.
-

10.11.08 14:06Ответ на сообщение Re: ошибка 1925 при репликации AD на двух DC пользователя whiplash
ИМХО лучше было бы на DC и на первом и втором указать в качестве DNS 0.5 и 0.20
Зона должна быть интегрирована в AD.
На рабочих станциях я бы тоже указал DNS, которые находятся на DС, чтобы не было проблем с динамической регистрацией рабочих станций в DNS. -

10.11.08 14:08Ответ на сообщение Re: ошибка 1925 при репликации AD на двух DC пользователя Barlog
Если DNS на фряхе используется для резольвинга внешних адресов, то проще будет настроить DNS на контроллерах на форвардинг запросов к DNS-у на фряхе и на клиентах прописывать только DNS-ы, которые на контроллерах.
-
25.11.08 23:08Ответ на сообщение Re: ошибка 1925 при репликации AD на двух DC пользователя Barlog
кстати, курю вот это
тут и тут
как все же лучше — перекрестно или каждый сам для себя первичный и вторым указан другой?
и еще — на вторичном лучше делать основную зону или дополнительную?
IT crowd. старый добрый троллинг.
-
26.11.08 00:57Ответ на сообщение Re: ошибка 1925 при репликации AD на двух DC пользователя whiplash
1. В ветке все ж плюсы минусы описаны. МЛМ если два контроллера то лучше перекресно, если более то варианты
2. Зачем секондари, если зона в ад сохранена, ставь на втором дц днс, и ни какой настройки не надо, он сам из ад притянет зону как праймари. -

26.11.08 14:09Ответ на сообщение Re: ошибка 1925 при репликации AD на двух DC пользователя whiplash
Однозначного ответа нет.
Только что значит первичная и вторичная зоны, когда разговор ведется о зоне, которая должна быть интегрированной в AD?
Перейти в форум
Active Directory Event Warning 1925 & error 1168 tory and DNS error 4010 & 4000
Please mention the ad replication troubleshooting step by step..
Also mention how to get diagnose the event error ids.
what is the difference in replications dc=adc and adc=rodc
Read these next…

WINDOWS 10 «glitch» — file explorer
Windows
Hi.I have been experiencing a black line (glitch) on my file explorer which comes for milliseconds then it goes away. See screen grab. Is there anyone who has experienced such and how were they able to solve it?Thank you.

Are you updating workstations to Windows 11?
Windows
Has anyone started updating workstations on a AD domain to Windows 11? what type of issues are you facing?What is the user reaction been?Thanks!

Snap! — Psyche Probe, DIY Gene Editing, RaiBo, AI handwriting, Metric Pirates
Spiceworks Originals
Your daily dose of tech news, in brief.
Welcome to the Snap!
Flashback: January 27, 1880: Thomas Edison receives patent for the Electric Lamp. (Read more HERE.)
Bonus Flashback: January 27, 1967: Apollo 1 Tragedy (Read more HERE.)
You …

NEC Inmail Email doesn’t Change
Collaboration
Hey Everyone,Recently a client of mine wanted to change the email to their QA extension to her email as to help keep voicemails consolidated instead of spread out among different emails. Normally this wouldn’t be a huge deal. Logged in to to Webpro, hoppe…

I inherited some really cool equipment. I just have no clue how to use it!
Hardware
So I’ve got some switches, and some servers. The switches seem pretty straight forward, plug in packet go zoom, but I have no clue how these servers work. They’re headless rack servers. I know there must be a way to get some kind of UI going with a monito…
Good afternoon r/activedirectory, I have 4 AD LDS instances: 2 in Production, 2 in a DR environment. The DR AD LDS instances were replicated from Production. They sit in different networks, but are joined to the same domain. I was able to replicate the instances successfully, however, it seems that these replicated DR AD LDS instances cannot write to the Production AD LDS instances.. I am able to write to Production instances, and they will update DR instances — but not vice versa… I receive the following errors every second from my DR instances: The attempt to establish a replication link for the following writable directory partition failed.
**Directory partition:**
CN=Configuration,CN={XXXXXX-XXXX-XXXX-XXXX}
**Source directory service:**
CN=NTDS Settings,CN=PRODSERVER$INSTANCE,CN=Servers, CN=Default- First-Site-Name,CN=Sites,CN=Configuration,CN={XXXXXX-XXXX- XXXX}
**Source directory service address:
PRODSERVER:c5e47ced-f4d2-4491-bc9d-2e184431a07d
Intersite transport (if any):
This directory service will be unable to replicate with the source directory service until this problem is corrected.
**User Action**
Verify if the source directory service is accessible or network connectivity is available.
**Additional Data**
**Error value:**
1726 The remote procedure call failed.
Any input on this? Has anyone else experienced this issue?
Hello All —
Another member of my team set up a new DC for a domain that we support which is located off site on a different subnet than the other ones. From what I hear, it worked fine for a couple of days, but today, users could not authenticate or retrieve profiles from it. I’m receiving the two errors below every few minutes (attached screen shot #3):
——————————————————————————-
NTDS Replication — Category = DS RPC Client (attached screenshot #1)
Error 1645
Active Directory did not perform an authenticated remote procedure call (RPC) to another domain controller because the desired service principal name (SPN) for the destination domain controller is not registered on the Key Distribution Center (KDC) domain controller that resolves the SPN.
Destination domain controller:
a2854d9e-e5d3-417c-a31d-6eb34b6c55f5._msdcs.DOMAINABC.LOCAL
SPN:
E3514235-4B06-11D1-AB04-00C04FC2DCD2/a2854d9e-e5d3-417c-a31d-6eb34b6c55f5/PSBOC.LOCAL@DOMAINABC.LOCAL
User Action
Verify that the names of the destination domain controller and domain are correct. Also, verify that the SPN is registered on the KDC domain controller. If the destination domain controller has been recently promoted, it will be necessary for the local domain controller’s computer account data to replicate to the KDC before this computer can be authenticated.
————————————————————
NTDS Replication — Category = Knowledge Consistancy (attached screenshot #2)
Error 1925
The attempt to establish a replication link for the following writable directory partition failed.
Directory partition:
DC=DOMAINABC,DC=LOCAL
Source domain controller:
CN=NTDS Settings,CN=OPS-DC,CN=Servers,CN=RemoteSite1,CN=Sites,CN=Configuration,DC=DOMAINABC,DC=LOCAL
Source domain controller address:
a2854d9e-e5d3-417c-a31d-6eb34b6c55f5._msdcs.DOMAINABC.LOCAL
Intersite transport (if any):
This domain controller will be unable to replicate with the source domain controller until this problem is corrected.
——————————————————————————-
Also, I don’t know if it’s related, but am getting this error in the DNS Server event log:
Source = DNS — Category = None
Event ID 4515
The zone PSBOC.LOCAL was previously loaded from the directory partition MicrosoftDNS but another copy of the zone has been found in directory partition DomainDnsZones.PSBOC.LOCAL. The DNS Server will ignore this new copy of the zone. Please resolve this conflict as soon as possible.
If an administrator has moved this zone from one directory partition to another this may be a harmless transient condition. In this case, no action is necessary. The deletion of the original copy of the zone should soon replicate to this server.
If there are two copies of this zone in two different directory partitions but this is not a transient caused by a zone move operation then one of these copies should be deleted as soon as possible to resolve this
—————————————————————
I’ve done a bit of research and so far have tried to:
— Flush, then register DNS then restarting NETLOGON.
— Restart
— Verify that system time is correct
— Created an InterSite Transport from one of the existing servers to the remote site one. I really don’t know much about this so may have done it wrong.
Please help! — Thanks!
1.png
2.png
3.png
4.png