Domain Controllers having issues replicating within only one specific region

Kyle 1 Reputation point
2020-12-07T16:50:54.157+00:00

Hello, I am taking over managing the AD for our team. The previous individual that was responsible for this has moved and is no longer reachable. We use several regions in AWS, and have basic services on each region such as AD Domain Controller, mail services, projects, etc. Last week I spun up a new Windows Server 2019 machine on each region, and set each up as a Domain Controller. The plan was to take town the old 2016 DC servers once the new 2019 machines are up and running. They all worked fine, except for one single region. Upon inspection, it would appear the old 2016 DC in this same region was never working right to begin with when it was setup by a previous member a few years ago. This region isn't used for much which is why this was never spotted until now.

Within the broken region, both Domain Controllers, on 2016 and 2019 can communicate with each other just fine. If I create a new server within that region, and join it to the domain, it says it joined to the domain, but it will only appear on those two Domain Controllers. I can not replicate this in any other region.

When running repadmin /replsummary on the new 2019 DC, it shows all success except for two servers, which are the main two domain controllers located physically in the office. The error message is "experienced the following operational errors trying to retrieve replication information". These both have error code 58. The DNS on the DCs in the broken region are the IPs of those two machines, the same setup as every other region.

The firewall has been updated, and temporarily opens all communication between all internal resources. I can confirm traffic is going through this rule, so there should be nothing on the network firewall preventing access. Is there something on the Windows Firewall itself that needs to be updated, or added, even though no other region did?

I have alot of information I can share, but I am not sure what would be most beneficial. I am fairly new to AD, and this has been a learning experience for me. Please let me know what other information would be useful to share. I have been in contact with Microsoft Support, but it has been more then one week and have only been told that they are looking into it and will get back to me soon. After a week of the same messages I am loosing hope that they will help resolve this. I would greatly appreciate anyone's help in trying to resolve this.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,442 questions
Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,367 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,076 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,816 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Dave Patrick 426K Reputation points MVP
    2020-12-07T17:01:10.047+00:00

    I'd check the required ports are flowing between sites.
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts
    https://www.microsoft.com/en-us/download/details.aspx?id=24009

    also check the event logs for errors since last boot.

    --please don't forget to Accept as answer if the reply is helpful--

    1 person found this answer helpful.

  2. Dave Patrick 426K Reputation points MVP
    2020-12-07T18:39:53.043+00:00

    I spun up a new Windows Server 2019 machine

    How long has the problem been going on? Has tombstone expired? Might try standing up a new one but be sure to use another active healthy domain controller for DNS on connection properties.

    --please don't forget to Accept as answer if the reply is helpful--

    1 person found this answer helpful.

  3. Dave Patrick 426K Reputation points MVP
    2020-12-07T19:11:24.213+00:00

    likely been going on since this region was created a few years ago

    Try standing up a new one but be sure to use another active healthy domain controller for DNS on connection properties.

    --please don't forget to Accept as answer if the reply is helpful--

    1 person found this answer helpful.

  4. Dave Patrick 426K Reputation points MVP
    2020-12-07T19:17:46.163+00:00

    Sounds like the site has no connectivity. You can also start a case here with product support.
    https://support.serviceshub.microsoft.com/supportforbusiness

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  5. Vicky Wang 2,646 Reputation points
    2020-12-10T09:21:56.44+00:00

    Hi,

    Just checking in to see if the information provided was helpful.

    Please let us know if you would like further assistance.

    Best Regards,
    Vicky

    0 comments No comments