AD replication issue

Shahin Mortazave 491 Reputation points
2022-01-14T14:24:22.013+00:00

Our domain is single level and environment is spread across multiple remote sites and each remote site has its own Site and subnet in AD. Today we add a new remote office as site to our AD in our HQ and create a subnet for it. The new site and HQ have a Site2Site IPSEC VPN connections and we did promote a new server 2019 in the new site to a DC for this site and everything went ok.
Now when check the AD site and services on the HQ dc I can see that the new site has an NTDS settings object and this object has only one automatically generated object that points to and DC in one of the remote Offices and not to any DC in HQ! the DC in HQ has all of the FSMO rules.
How can we force this new DC to replicate with the HQ DC and not the one in different remote site? I did manually add a connection to the NTDS settings on the DC in the new site that points to the HQ DC but when run the replication manually get this message:
165153-image.png

Any suggestion on how to get the replication on the new server up and running?

Thanks

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2022-01-14T14:36:21.713+00:00

    The bridgehead server selections and site links should be automatic.
    https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/replication/active-directory-replication-concepts#BKMK_7

    if you have a need to alter the design read on here.
    https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/creating-a-site-link-bridge-design

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  2. Limitless Technology 40,076 Reputation points
    2022-01-17T10:52:04.087+00:00

    Hello ShahinMortazave,

    Thank you for your question and reaching out.

    I can understand you are facing AD replication.

    Please note that as you have Added manually connection in NTDS settings then It should be automatically Replication from your HQ DC due KCC service which is responsible to adjust the connections. Also , Please verify Cost value for site link should be according to your speed of network.

    KCC :
    The KCC is a built-in process that runs on all domain controllers and generates replication topology for the Active Directory forest. The KCC creates separate replication topologies depending on whether replication is occurring within a site (intrasite) or between sites (intersite). The KCC also dynamically adjusts the topology to accommodate the addition of new domain controllers, the removal of existing domain controllers, the movement of domain controllers to and from sites, changing costs and schedules, and domain controllers that are temporarily unavailable or in an error state.

    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc755326(v=ws.10)

    I will also suggest to verify AD replication health using Active Directory Replication Status Tool
    https://www.microsoft.com/en-in/download/details.aspx?id=30005

    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc755326(v=ws.10)

    --------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.