Score:0

Active Directory Sync - RPC Server Unavailable Error, but all services and network protocols are fine

nu flag

Background: 4 Windows Server 2016 domain controllers at 4 different sites. Sites are connected by S2S IPSec connections. The one site moved and the server in this site broke down, so we had to restore the server to a new Hyper-V instance. Everything went fine and all looks 100% again... However:

Problem: When running AD sync on this restored AD, I get RPC Server Not Available errors for all servers, and sometimes the status changes to Error 172: Network Error. I have checked all services required for AD, as well as all network protocols and did port testing as well; everything checks out.

I am not sure what could be causing this - does anyone have any ideas?

cn flag
`did port testing` what ports?
Francois Botha avatar
nu flag
135 and 53 on all servers.
cn flag
RPC requires ports tcp/135 and tcp/49152 through tcp/65535. You need to ensure *all* of those ports are opened, and perform a netmon packet capture to confirm what port(s) are being attempted to what addresses. https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/service-overview-and-network-port-requirements https://learn.microsoft.com/en-US/troubleshoot/windows-server/networking/default-dynamic-port-range-tcpip-chang
Francois Botha avatar
nu flag
Thank you, Greg. I will check that now and test if this is causing the problem. The DC did replicate fine before the restore, but this is a good suggestion and I will report back on the outcome. I appreciate your input.
Francois Botha avatar
nu flag
I have tested this with the selected ports open, but unfortunately, I still get the error. 2x of the servers fail 5/15 sync services.
cn flag
What does the netmon capture show?
Score:0
nu flag

Update: The problem is sort of fixed. I rechecked the NTDS entries for each server and made sure that all other servers are listed. I then re-ran the sync manually from the primary AD and all passed for all servers!

I do however get the following status on the 'repadmin /replsummary' for two of the servers (even though the sync was successful on all items):

Source:

       1                10m:25s    0 /  15    0
       2                52m:41s    0 /  15    0
       3            21h:56m:09s    5 /  15   33  (1722) The RPC server is unavailable.
       5            21h:54m:08s    5 /  15   33  (1722) The RPC server is unavailable.

Destination:

       1                14m:24s    0 /  15    0
       2                09m:02s    0 /  15    0
       3            21h:54m:14s    5 /  15   33  (1722) The RPC server is unavailable.
       5            21h:56m:20s    5 /  15   33  (1722) The RPC server is unavailable.
us flag
You should check the Directory Service log for any related replication errors. The RPC message could be a symptom of another issue.
Francois Botha avatar
nu flag
Thank you, I will check this and report any findings.
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.