Group Policy Replication
Discussion
Trying to update all the PCs at work using SUS and Group policy. I have a probelm in that the Group policy hasn't been replicating correctly between the domain controllers and as such one of the controllers is dishing out an old policy.
I'm having a play with the Replmon tool but is there an easy way of forcing a replication immediately or can I just copy the correct policies in to the sysvol folder?
While I'm at is does anyone know a way of forcing a quicker SUS update rather than waiting the 17-22 hrs?
Any help appreciated
I'm having a play with the Replmon tool but is there an easy way of forcing a replication immediately or can I just copy the correct policies in to the sysvol folder?
While I'm at is does anyone know a way of forcing a quicker SUS update rather than waiting the 17-22 hrs?
Any help appreciated
I think there is tool call gplforce.exe/gplupdate.exe or the like that you can run on the other DC and it will pull the latest files down from the other DC. Why the other server isnt replicating i dont know. Is it a new server or has it worked properly previously ?
For the SUS updates - are you talking about replicating the sus server, or dishing out the sus updates to the clients ?
What OS are the servers running - are they both the same ?
Steve
>> Edited by Lockstock2sb on Friday 31st December 12:00
For the SUS updates - are you talking about replicating the sus server, or dishing out the sus updates to the clients ?
What OS are the servers running - are they both the same ?
Steve
>> Edited by Lockstock2sb on Friday 31st December 12:00
BliarOut said:
Active directory sites and services. Drill down and find the link in question, right click and select replicate now (I think!)
Check the event viewer afterwards. Pay particular attention to DNS, that's often the trouble.
It works like this: Group Policies are stored in 2 seperate locations and each is replicated amongst domain controllers using different mechanisms.
Some of the information is stored in the Active Directory itself (the settings), the rest is stored in SYSVOL (the templates).
You cannot simply copy the files between sysvol folders for this reason; one half of the policy would be new and the other old.
GPUPDATE is a tool used on Windows 2003 and XP to update the local machine with a copy of a policy from a DC, and will have no effect between DC's
AD Sites and Services will replicate the AD portion of the policy, but not the SYSVOL info (which is done using FRS (the file replication service).
So, the first thing to do is to work out what isn't working.
You could also do with checking the event logs for NTDS replication errors and also FRS errors.
Darren
ErnestM said:
Make sure all of your servers are synching TIME as well. Believe it or not, that causes some synchronization problems. The default is for your PDC to be the network time server. I have had better luck synching time with an external time source (Atomic clock, Colorado)
![]()
ErnestM
Not necessarily. Each machine synch's automatically with the PDC in its domain (and in turn each PDC synch's with the PDC in it's parent domain). It's useful to synch the 'top of the tree' with an external time source.
The reason time issues cause a problem is because the authentication protocol used (Kerberos) only allows a 5 minute difference between send and recieve times (for fear of encryption decoding and subsequent tampering). That can also be changed by group policy (but that's not much use when it's broken
). D
>> Edited by _DeeJay_ on Friday 31st December 13:52
Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff


