Skip to content

SYSVOL DFSR Troubleshooting

Active Directory's SYSVOL folder contains critical Group Policy Objects (GPOs) and scripts, and its replication across domain controllers (DCs) is essential for consistent policy application. DFS Replication (DFS-R) replaces the legacy File Replication Service (FRS) for SYSVOL replication, ensuring efficient, secure, and reliable synchronization. This section covers configuring DFS-R for SYSVOL and troubleshooting common issues.

Configuring SYSVOL DFS Replication

1. Prerequisites

  • All DCs must run Windows Server 2008 or later (FRS is deprecated in newer versions).
  • Ensure DFS-R is enabled and the DFS Replication service is running on all DCs.
  • Verify network connectivity and firewall rules allow DFS-R traffic (ports 445, 389, 636).

2. Create the DFS Replication Group

  1. Open DFS Management (dfsrmig tool or Server Manager > File Services).
  2. Right-click DFS Replication, select New Replication Group.
  3. Configure the replication group:
  4. Name: SYSVOL
  5. Scope: Choose "Domain" for domain-wide replication.
  6. Members: Add all DCs to the replication group.
  7. Replication Scheduling: Set bandwidth limits and schedules (e.g., "Always" for critical SYSVOL traffic).
  8. Conflict Resolution: Set the "Last Writer Wins" or "Oldest Writer Wins" policy.

3. Configure SYSVOL Folder

  • Ensure the SYSVOL folder is shared and configured for DFS-R:
    Set-ItemProperty -Path "HKLM:\System\CurrentControlSet\Services\DFSR" -Name "SYSVOLReplication" -Value 1
    
  • Verify permissions: The SYSTEM account must have full control over SYSVOL.

4. Validate Configuration

  • Use repadmin /replsum to check replication status:
    repadmin /replsum
    
  • Confirm all DCs are listed in the DFS Replication Monitor under DFS Replication > Replication Groups.

Troubleshooting SYSVOL DFS Replication

1. Common Issues and Diagnostics

  • Replication Failures: Check DFSR event logs (Event Viewer > Applications and Services Logs > Microsoft > Windows > DFSR).
  • Event ID 13517: "The target computer is not a member of the replication group."
  • Event ID 13518: "The source computer is not a member of the replication group."
  • Slow Replication: Use repadmin /replsum to identify stalled transfers or bandwidth limits.
  • Permission Errors: Ensure the SYSTEM account has full control over SYSVOL and DFS-R service accounts have proper permissions.

2. Tools for Diagnosis

  • repadmin: Check replication status and metadata:
    repadmin /replsum
    repadmin /repl /ec /sc
    
  • dcdiag: Validate DC health and replication:
    dcdiag /v
    
  • DFS Replication Monitor: Open DFS Management > DFS Replication > Replication Groups > [Group Name] > Members to view sync status.

3. Resolving Specific Errors

  • Error 13517/13518: Ensure all DCs are added to the replication group and the DFSR service is running.
  • Conflict Resolution: Use dfsrmig to migrate from FRS to DFS-R if needed:
    dfsrmig /?
    
  • Firewall Rules: Allow DFS-R traffic via Group Policy or firewall settings.

Key takeaways

  • Configure DFS-R for SYSVOL via DFS Management, ensuring all DCs are in the replication group and permissions are correct.
  • Use repadmin, dcdiag, and DFSR event logs to monitor and troubleshoot replication issues.
  • Regularly validate replication status with repadmin /replsum and address conflicts using appropriate resolution policies.
  • Ensure network connectivity and firewall rules support DFS-R traffic for seamless replication.