AD DS Replication Problem EventID 1864

Dimitri Karapetian 1 Reputation point
2021-02-15T08:44:29.253+00:00

Hi everyone, i have problem in my environment, we are using 4 domain controllers and in 2 domain controller in event day, every 24 hours give error EventID 1864.

CN=Schema,CN=Configuration,DC=AGH,DC=com

CN=Configuration,DC=AGH,DC=com

DC=AGH,DC=com

This directory server has not recently received replication information from a number of directory servers. The count of directory servers is shown, divided into the following intervals.

More than 24 hours:
1
More than a week:
1
More than one month:
1
More than two months:
1
More than a tombstone lifetime:
0
Tombstone lifetime (days):
372

Directory servers that do not replicate in a timely manner may encounter errors. They may miss password changes and be unable to authenticate. A DC that has not replicated in a tombstone lifetime may have missed the deletion of some objects, and may be automatically blocked from future replication until it is reconciled.

To identify the directory servers by name, use the dcdiag.exe tool.
You can also use the support tool repadmin.exe to display the replication latencies of the directory servers. The command is "repadmin /showvector /latency <partition-dn>".

also i tried to check with this commands:

repadmin /kcc

repadmin /replsummary

repadmin /syncall

always received "passed test"
i cannot understand where is problem?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,557 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,121 questions
0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. Dave Patrick 426.4K Reputation points MVP
    2021-02-15T13:27:11.54+00:00

    If a domain controller has tombstoned the recommended (and only) solution is to demote, reboot, promo it again.

    --please don't forget to Accept as answer if the reply is helpful--


  2. Dave Patrick 426.4K Reputation points MVP
    2021-02-15T13:54:55.72+00:00

    I'd also check the required ports are flowing between sites.
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts
    https://www.microsoft.com/en-us/download/details.aspx?id=24009

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  3. Fan Fan 15,311 Reputation points Microsoft Vendor
    2021-02-16T06:34:07.937+00:00

    Hi,
    Try the methods for Troubleshoot Active Directory replication error 8614:
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/replication-error-8614

    Best Regards,


  4. Dave Patrick 426.4K Reputation points MVP
    2021-02-16T09:45:02.297+00:00

    Have you tried moving roles off, demote, reboot, promo it again?

    --please don't forget to Accept as answer if the reply is helpful--


  5. Dave Patrick 426.4K Reputation points MVP
    2021-02-16T13:31:38.667+00:00

    Then I'd check the required ports are flowing between them.
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts
    https://www.microsoft.com/en-us/download/details.aspx?id=24009

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments