Module 10: Troubleshooting Active Directory, DNS, and Replication Issues.

Slides:



Advertisements
Similar presentations
Course 2786B Module 8: Implementing an Active Directory® Domain Services Monitoring Plan Presentation: 60 minutes Lab: 60 minutes This module helps students.
Advertisements

Course 6425A Module 9: Implementing an Active Directory Domain Services Maintenance Plan Presentation: 55 minutes Lab: 75 minutes This module helps students.
Implementing and Administering AD DS Sites and Replication
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 6 Managing and Administering DNS in Windows Server 2008.
Module 10: Troubleshooting AD DS, DNS, and Replication Issues.
Implementing Domain Name System
Module 5: Creating and Configuring Group Policy
Module 3: Configuring Active Directory Objects and Trusts.
Course 6425A Module 2: Configuring Domain Name Service for Active Directory® Domain Services Presentation: 50 minutes Lab: 45 minutes This module helps.
Implementing High Availability
Understanding Active Directory
1 Chapter Overview Creating Sites and Subnets Configuring Intersite Replication Troubleshooting Active Directory Replication.
Course 6421A Module 7: Installing, Configuring, and Troubleshooting the Network Policy Server Role Service Presentation: 60 minutes Lab: 60 minutes Module.
Module 4 Managing Client Access. Module Overview Configuring the Client Access Server Role Configuring Client Access Services for Outlook Clients Configuring.
Network and Active Directory Performance Monitoring and Troubleshooting NETW4008 Lecture 8.
Module 7: Implementing Security Using Group Policies.
Module 1: Installing Active Directory Domain Services
Module 1: Installing Active Directory Domain Services
Course 6425A Module 9: Implementing an Active Directory Domain Services Maintenance Plan Presentation: 55 minutes Lab: 75 minutes This module helps students.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 7: Active Directory Replication.
Deploying and Managing Windows Server 2012
Module 7: Configuring TCP/IP Addressing and Name Resolution.
Implementing DNS Module D 7: Implementing DNS
Implementing Dynamic Host Configuration Protocol
Module 12: Designing an AD LDS Implementation. AD LDS Usage AD LDS is most commonly used as a solution to the following requirements: Providing an LDAP-based.
Module 5: Isolating Common Connectivity Issues. Overview Determining the Causes of Connectivity Issues Network Utilities That You Can Use to Isolate Connectivity.
Windows Server 2008 R2 Domain Name System Chapter 5.
Module 7: Implementing Sites to Manage Active Directory Replication.
Module 9: Active Directory Domain Services. Overview Describe new features in AD DS List manageability and reliability enhancements in AD DS.
Module 14: Configuring Server Security Compliance
Module 7: Fundamentals of Administering Windows Server 2008.
20411B 8: Installing, Configuring, and Troubleshooting the Network Policy Server Role Presentation: 60 minutes Lab: 60 minutes After completing this module,
Module 9: Configuring IPsec. Module Overview Overview of IPsec Configuring Connection Security Rules Configuring IPsec NAP Enforcement.
Module 4: Planning, Optimizing, and Troubleshooting DHCP
Module 11: Remote Access Fundamentals
Module 12: Implementing an Active Directory ® Domain Services Infrastructure.
Monitoring Windows Server 2012
Module 6: Managing and Monitoring Domain Name System (DNS)
Configuring and Troubleshooting Domain Name System
Labs. Lab Session 1: Administering Windows Server 2008 Exercise 1: Install the DNS Server Role Exercise 2: Configuring Remote Desktop for Administration.
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
11 MANAGING AND MONITORING DNS Chapter 4. Chapter 4: MANAGING AND MONITORING DNS2 DNS MANAGEMENT TOOLS  DNS console  Nslookup  DNSLint  Logging features.
Module 11: Troubleshooting Group Policy Issues. Module Overview Introduction to Group Policy Troubleshooting Troubleshooting Group Policy Application.
Module 4: Configuring and Troubleshooting DHCP
Module 8: Implementing an Active Directory Domain ® Services Monitoring Plan.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Introduction to Active Directory Domain Services
Module 1: Implementing Active Directory ® Domain Services.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
Module 5: Creating and Configuring Group Policies.
Module 4: Configuring Active Directory Sites and Replication
Module 4: Configuring Active Directory Sites and Replication.
Module 7: Implementing Security Using Group Policy.
Module 10: Windows Firewall and Caching Fundamentals.
Module 9 Planning and Implementing Monitoring and Maintenance.
Module 3 Planning for Active Directory®
Introduction to Active Directory
Module 6: Configuring User Environments Using Group Policies.
11 WORKING WITH ACTIVE DIRECTORY SITES Chapter 3.
Global Catalog and Flexible Single Master Operations (FSMO) Roles BAI516.
Unit 4 NT1330 Client-Server Networking II Date: 1/13/2016
Module 4: Configuring Active Directory ® Domain Sevices Sites and Replication.
Module 14: Advanced Topics and Troubleshooting. Microsoft ® Windows ® Small Business Server (SBS) 2008 Management Console (Advanced Mode) Managing Windows.
Module 11: Configuring and Managing Distributed File System.
Module 11: Troubleshooting Group Policy Issues. Module Overview Introduction to Group Policy Troubleshooting Troubleshooting Group Policy Application.
Module 2: Implementing an Active Directory Forest and Domain Structure.
Monitoring Windows Server 2012
Active Directory Replication
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Presentation transcript:

Module 10: Troubleshooting Active Directory, DNS, and Replication Issues

Module Overview Troubleshooting Active Directory Domain Services Troubleshooting DNS Integration with AD DS Troubleshooting AD DS Replication

Lesson 1: Troubleshooting Active Directory Domain Services Introduction to AD DS Troubleshooting Discussion: How to Troubleshoot Active Directory Domain Services Issues Troubleshooting User Access Errors Demonstration: Tools for Troubleshooting User Access Errors Troubleshooting Domain Controller Performance Issues

Introduction to AD DS Troubleshooting Active Directory troubleshooting begins when: Users report authentication or authorization errors Active Directory related events appear in the Event Viewer Domain controller performance is degraded An alert is generated by a monitoring system Data is not being replicated between domain controllers

Discussion: How to Troubleshoot Active Directory Domain Services Issues What steps would you take to troubleshoot an Active Directory issue? What tools would you use? How would you verify that your solution worked?

Troubleshooting User Access Errors User access errors may be the result of: Network access errors Authentication errors Authorization errors To address user access errors, verify: Network connectivity Time synchronization Domain controller availability User account and user lockout settings Group memberships

Demonstration: Tools for Troubleshooting User Access Errors In this demonstration, you will see how to troubleshoot user access errors using the Windows tools

Troubleshooting Domain Controller Performance Issues Most common performance issues include: High CPU utilization High network utilization To resolve performance issues: Identify the processes with high CPU utilization Move applications or services to another server Monitor application specific network traffic Distribute Active Directory and DNS roles across multiple servers Review and modify the replication topology Deploy domain controllers with 64 bit hardware

Lesson 2: Troubleshooting DNS Integration with AD DS Overview of DNS and AD DS Troubleshooting Troubleshooting DNS Name Resolution Troubleshooting DNS Name Registration Troubleshooting DNS Zone Replication

Overview of DNS and AD DS Troubleshooting Troubleshoot the integration of DNS and Active Directory when: Users cannot log on to Active Directory Active Directory replication is failing Active Directory installation fails To troubleshoot DNS and Active Directory integration, verify: DNS client and server configurations DNS name registration DNS zone replication

Troubleshooting DNS Name Resolution DNS name resolution may fail due to: Network connectivity issues Client configuration errors DNS server availability Name registration or DNS replication issues To troubleshoot DNS name resolution: Test network connectivity by pinging the DNS server by IP address Use IPConfig to examine the client configuration Use NSLookup to verify server availability Flush the DNS cache Use NSLookup to verify SRV records

Troubleshooting DNS Name Registration DNS name registration may fail due to: Client configuration errors DNS server availability DNS zone configuration To troubleshoot DNS name registration: Verify that the client is configured to register in DNS Test DNS server availability Verify that the DNS zone is configured for dynamic updates Test DNS by using the DCDiag /Test:DNS command Register the SRV records by restarting the Netlogon service

Troubleshooting DNS Zone Replication Investigate DNS zone replication issues when: DNS-related issues are specific to certain DNS server clients Zone information is not consistent on different DNS servers DNS server availability Name registration or DNS replication issues Troubleshoot Active Directory replication for Active Directory integrated zones To troubleshoot standard zone transfer issues: Verify network connectivity Verify primary server and secondary server configuration Verify Start of Authority record Verify zone transfer configuration

Lesson 3: Troubleshooting AD DS Replication AD DS Replication Requirements Common Replication Issues What Is the Repadmin Tool? What Is the DCDiag Tool? Identifying the Cause of Replication Errors Discussion: Troubleshooting Inter-Site AD DS Replication Issues Troubleshooting Distributed File Replication Issues

AD DS Replication Requirements Active Directory replication requires: Routable IP infrastructure DNS name resolution RPC or SMTP connectivity between domain controllers Kerberos v5 authentication LDAP connectivity to install new domain controllers File Replication Service or Distributed File System Replication

Common Replication Issues Replication greatly increases network traffic Possible causes Replication does not finish or occur Replication is slow Client computers receive a slow response Symptom Sites not connected by site links No bridgehead server in the site group No domain controller online in client site Not enough domain controllers Inefficient site topology and schedule Insufficient bandwidth Incorrect site topology

What Is the Repadmin Tool? Use the Repadmin command-line tool to: View and manually create the replication topology Force replication events between domain controllers View the replication metadata Syntax: repadmin command arguments [/u:[domain\]user pw:{password|*}]

What Is the DCDiag Tool? Use the Dcdiag command-line tool to: Analyze the state of a domain controller and report any problems Perform a series of tests to verify different areas of the system Syntax: dcdiag command arguments [/v /f:LogFile /ferr:ErrLog ]

Identifying the Cause of Replication Errors System monitor NTDS counters Testing method Sites are not connected by site links No bridgehead server in the site Inefficient site topology and schedule Possible causes Dcdiag /test:Topology Repadmin /bridgeheads Repadmin /latency No domain controller online in the site Dcdiag /test:Replication Dcdiag /test:Connectivity Not enough domain controllers Incorrect site topology Active Directory Sites and Services Repadmin /latency V Dcdiag /test:Intersite

Discussion: Troubleshooting Inter-Site AD DS Replication Issues What steps would you take to troubleshoot an Active Directory replication issue? How would you verify that your solution worked?

Troubleshooting Distributed File Replication Issues Windows Server 2008 uses FRS or DFSR to replicate the SYSVOL directory between domain controllers Both FRS and DFRS require LDAP and RPC connectivity between domain controllers Use Ntfrsutl and FRSDiag to troubleshoot FRS replication Use DFSRAdmin to troubleshoot DFRS replication

Lab: Troubleshooting Active Directory, DNS, and Replication Issues Exercise 1: Troubleshooting Authentication and Authorization Errors Exercise 2: Troubleshooting the Integration of DNS and AD DS Exercise 3: Troubleshooting AD DS Replication Logon information Virtual machine NYC-DC1, NYC-CL1 User nameAdministrator Password Pa$$w0rd Estimated time: 75 minutes

Lab Review If the Los Angeles office was configured as a separate site, what additional steps would you need to take to troubleshoot Scenario #5? What AD DS troubleshooting issues do you think you will need to deal with most often in your organization?

Module Review and Takeaways Considerations Tools Review questions

Beta Feedback Tool Beta feedback tool helps:  Collect student roster information, module feedback, and course evaluations.  Identify and sort the changes that students request, thereby facilitating a quick team triage.  Save data to a database in SQL Server that you can later query. Walkthrough of the tool

Beta Feedback Overall flow of module:  Which topics did you think flowed smoothly, from topic to topic?  Was something taught out of order? Pacing:  Were you able to keep up? Are there any places where the pace felt too slow?  Were you able to process what the instructor said before moving on to next topic?  Did you have ample time to reflect on what you learned? Did you have time to formulate and ask questions? Learner activities:  Which demos helped you learn the most? Why do you think that is?  Did the lab help you synthesize the content in the module? Did it help you to understand how you can use this knowledge in your work environment?  Were there any discussion questions or reflection questions that really made you think? Were there questions you thought weren’t helpful?