Skip to content

Resolving Replication Errors

Active Directory replication issues can disrupt directory services, leading to inconsistencies, latency, or complete failure. This guide provides actionable steps to diagnose and resolve common replication errors using native tools like repadmin, dcdiag, and the Active Directory Sites and Services console. Follow a structured approach to isolate root causes and restore healthy replication.


Replication Failures

1. Identify Failed Replication Partners

Use repadmin /replsum to get a summary of replication status across all domains:

repadmin /replsum
Look for entries marked "Replication Failure" or "No Contact". For detailed analysis:
repadmin /replicate <SourceDC> <DestinationDC> <NCName>
Replace <SourceDC> and <DestinationDC> with the domain controller names, and <NCName> with the naming context (e.g., DC=DomainDNSZones).

2. Force Replication

If a specific replication failure is identified, force replication using:

repadmin /forcereplication <DestinationDC> <SourceDC> <NCName>
This is useful for urgent fixes but should be used sparingly to avoid overloading the network.

3. Diagnose with dcdiag

Run domain controller diagnostics to check replication health:

dcdiag /test:replications
This tool identifies issues like missing replication metadata or communication failures between DCs.


Replication Latency

1. Check Latency with repadmin

Use repadmin /replsum to view replication latency. Focus on the "Last Attempt" and "Last Success" timestamps. A delay of more than 15 minutes may indicate a problem.

2. Verify Network Connectivity

Ensure DCs can communicate over the network:

Test-NetConnection <DestinationDC> -Port 389
Check for firewall rules blocking LDAP (port 389) or RPC (port 593).

In Active Directory Sites and Services, verify that site links are configured correctly. Ensure the "Bridge all site links" option is enabled and that site link costs are balanced to avoid suboptimal replication paths.


Inconsistent Data

1. Detect Inconsistencies with dcdiag

Run:

dcdiag /test:replications /verbose
Look for errors like "Replication failure" or "Inconsistent data". This tool also checks for conflicts in the directory.

2. Check Event Logs

Review the System and Directory Services logs on affected DCs for errors related to replication (e.g., event ID 13517 for replication failures).

3. Validate Replication Metadata

Use the Active Directory Replication Metadata tool in the ADSI Edit snap-in to check for corrupted or conflicting replication metadata. Ensure that the "Replication Metadata" tab shows consistent timestamps across DCs.


RPC Server Unavailable Errors

1. Verify RPC Service Status

Ensure the Remote Procedure Call (RPC) service is running on all DCs:

Get-Service RpcSs
Restart the service if necessary:
Restart-Service RpcSs

2. Check Firewall Rules

Ensure that the firewall allows RPC traffic (port 593). Use:

netsh advfirewall firewall show rule name="RPC"
If missing, create a rule to allow RPC traffic.

3. Test DNS Resolution

Use nslookup to verify that DCs can resolve each other’s names:

nslookup <DCName>
Ensure DNS records (A, SRV, and CNAME) are correctly configured and registered.


1. Validate DNS Configuration

Ensure DCs are correctly registered in DNS:

dnscmd /enlistdscname <DCName>
Check for SRV records in the _ldap._tcp.PDC._msdcs and _ldap._tcp.dc._msdcs zones.

2. Force DNS Registration

If DNS records are missing, force registration:

dnscmd /zoneadd <ZoneName> /dsprimary
dnscmd /zonereset <ZoneName>


Key takeaways

  • Use repadmin and dcdiag as primary diagnostic tools for replication issues.
  • Prioritize network and DNS health, as they are common root causes.
  • Force replication sparingly and only for critical failures.
  • Monitor latency and ensure site link configurations are optimized.
  • Regularly review event logs and replication metadata for early detection of inconsistencies.