Robert 的个人资料Robert's World照片日志列表更多 工具 帮助

Burleson Robert

职业
地点
兴趣
Robert Burleson is a Senior Consultant for Catapult Systems (a Microsoft Gold Partner headquartered in Austin, Texas). Robert’s13 years of Infrastructure experience include working with medium to large companies in the retail, education, healthcare, distribution, transportation, and energy industries. Robert is a PMP, and has certifications including MCITP in Exchange Messaging, MCSE, CCNA, CCDA, Novell CNE, A+, Network+, and Citrix. Robert spent 8 years as a Sheriff’s Deputy prior joining the ranks of the Professional Geeks. The views and opinions discussed in this blog are my own and do not necessarily reflect the views and opinions of my employer.
Thanks for visiting!
请稍候...
很抱歉,您输入的评论太长。请缩短您的评论。
您没有输入任何内容,请重试。
很抱歉,我们当前无法添加您的评论。请稍后重试。
若要添加评论,需要您的家长授予您相应权限。请求权限
您的家长禁用了评论功能。
很抱歉,我们当前无法删除您的评论。请稍后重试。
您已超过了一天之内允许提供的评论数上限。请在 24 小时后重试。
因为我们的系统表明您可能在向其他用户提供垃圾评论,您的帐户已禁用了评论功能。如果您认为我们错误地禁用了您的帐户,请联系 Windows Live 支持部门
完成下面的安全检查,您提供评论的过程才能完成。
您在安全检查中键入的字符必须与图片或音频中的字符一致。

Robert's World

8月14日

Data Protection Manager (DPM) 2007 issue on Domain Controllers

August 13

 

Data Protection Manager (DPM) 2007 issue on Domain Controllers

Be very careful when deploying DPM to multiple domain controllers in an environment.

Lesson Learned:

When installing Data Protection Manager (DPM) agents onto Active Directory Domain Controllers (DC), the following needs to occur.

1. Agent MUST be installed on each DC, ONE AT A TIME.

2. After EACH installation, you MUST run replication using the repadmin /syncall command to force replication

3. Failure to do this will cause major issues….

Why:

When the agent is installed on a domain controller it creates two Domain Local Security Groups in the Users Organizational Unit (OU): DPMRADCOMTrustedMachines and DPMRADmTrustedMachines. If you do not replicate after EACH DC Agent installation, the SID’s on these groups get hosed. This can be checked by going into the Members of these groups and determining if the DPM Servername has been changed to DUPLICATE$. If you see this, life just got quite a bit uglier.

How to Fix it:

1. Remove the DPM Agent using Add/Remove programs

2. Remove the above Security groups from Active Directory

3. Using the DPM Console, remove the Domain Controllers using the remove agent utility. You will get a pop up stating that the system in question does not appear to have the agent installed and would you like to remove it from the DPM Database. Yes, you do.

4. At this point, you may resume installing your DC’s. One at a time, as directed above.

Recommendation:

Always install the Domain Controller DPM agents first. Otherwise, you get to spend your nights uninstalling ALL the Agents from every server in the DPM environment and starting over… that’s not my definition of fun.

By the way, it appears that at this point in time none of this information is addressed in the Installation and Configuration guide. Searching for resolutions to this issue, there isn’t a lot out there for DPM 2007 so be aware!

 

 
没有相册。