Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

DC replication and ISA2004

Thread Tools
 
Search this Thread
 
Old 21 June 2006, 08:43 AM
  #1  
markr1963
Scooby Regular
Thread Starter
 
markr1963's Avatar
 
Join Date: Jun 2002
Location: Perth, Western Australia
Posts: 1,866
Likes: 0
Received 0 Likes on 0 Posts
Default DC replication and ISA2004

Got a client that has a couple of w2k3 DCs at their main site and another at their DR site. They have ISA2004 at both ends of the WAN. Replication works fine from the main site to DR but not the other way. I have a site visit planned but before I go can anyone give me a heads up as to what to look for?

TIA

Mark
Old 21 June 2006, 09:19 AM
  #2  
David_Wallis
Scooby Regular
 
David_Wallis's Avatar
 
Join Date: Nov 2001
Location: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Posts: 15,239
Likes: 0
Received 1 Like on 1 Post
Default

Check subnets are configured correctly in AD.
Check the eventlog on both DC's
DCDIAG
NETDIAG

Check RPC traffic can pass in both directions.

David
Old 21 June 2006, 09:49 AM
  #3  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Default

Check that both ISA 2004 boxes are on the same SP. It's more than likely the rulebase on the remote site isn't allowing the traffic back down the VPN (I'm assuming there is a VPN tunnel). It might be a VPN SA mis-match.
Old 21 June 2006, 11:39 AM
  #4  
Kieran_Burns
Scooby Regular
Support Scoobynet!
iTrader: (1)
 
Kieran_Burns's Avatar
 
Join Date: Jul 2004
Location: There on the stair
Posts: 10,208
Likes: 0
Received 0 Likes on 0 Posts
Default

The VPN tunnel wouldn't be created at all if there was a config issue.

The point about the reciprocated rules seems to be the best bet - you need to ensure all the Domain traffic is allowed through in both directions. Check your protocol list, your allowed nodes in both directions (remember that the rule used is session based, so whichever Server initiates the replication needs to be accomodated)

I hate to say this, but kick off a monitor session and look at all traffic inbound from that remote network, you should be able to see all traffic that is rejected. Don't forget to turn the monitoring off as it doesn't half hammer the server
Old 21 June 2006, 12:17 PM
  #5  
markr1963
Scooby Regular
Thread Starter
 
markr1963's Avatar
 
Join Date: Jun 2002
Location: Perth, Western Australia
Posts: 1,866
Likes: 0
Received 0 Likes on 0 Posts
Default

Many thanks, guys
Old 21 June 2006, 04:48 PM
  #6  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Default

It's possible to have a VPN tunnel up but only passing traffic in one direction.
Old 21 June 2006, 05:11 PM
  #7  
olliecampbell
Scooby Regular
iTrader: (3)
 
olliecampbell's Avatar
 
Join Date: Aug 2003
Location: AL4 | W1B
Posts: 2,699
Likes: 0
Received 0 Likes on 0 Posts
Default

rpcping
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
stamina_daddy
ScoobyNet General
8
06 October 2015 12:13 PM
Puff The Magic Wagon!
Computer & Technology Related
5
18 August 2004 11:16 AM
ozzy
Computer & Technology Related
7
16 January 2004 12:04 AM
IanW
Computer & Technology Related
3
02 September 2003 03:55 PM
ChristianR
Computer & Technology Related
4
28 February 2003 12:45 PM



Quick Reply: DC replication and ISA2004



All times are GMT +1. The time now is 09:51 AM.