Top Banner
13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure Lesson 13: Monitoring Active Directory Performance Introduce Active Directory performance monitoring tools Monitor Active Directory performance counters Create Performance Logs and Alerts Identify Active Directory support tools Monitor the File Replication Service Resolve replication errors Goals
56

13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

Dec 20, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.1 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Introduce Active Directory performance monitoring tools

Monitor Active Directory performance counters

Create Performance Logs and Alerts

Identify Active Directory support tools

Monitor the File Replication Service

Resolve replication errors

Goals

Page 2: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.2 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Periodically monitoring the Windows Server 2003 Active Directory performance

Helps you anticipate problems

Allows you to take preventive measures

Maintains efficient functioning of the network

(Skill 1)

Introducing Active Directory Performance-Monitoring Tools

Page 3: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.3 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Use performance monitoring tools

To collect baseline data, which statistically shows the load placed on your resources over time

To troubleshoot problems

Use information obtained from performance monitoring tools

Diagnose and solve performance bottlenecks and problems

To understand the effects of Active Directory performance on the hardware resources of a computer

Introducing Active Directory Performance-Monitoring Tools (2)

(Skill 1)

Page 4: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.4 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-1 Comparing current data with the baseline data

(Skill 1)

Page 5: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.5 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-2 The Directory Service Event log

(Skill 1)

Page 6: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.6 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Widely used tools for monitoring Active Directory performance

Performance Console

System Monitor

Performance Logs and Alerts tools

Event Viewer

Introducing Active Directory Performance-Monitoring Tools (3)

(Skill 1)

Page 7: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.7 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

System Monitor

Used to view a graphical real-time representation of the performance of the resources on a computer or network

Data captured by the System Monitor is displayed as a chart, a histogram, or a report

Introducing Active Directory Performance-Monitoring Tools (4)

(Skill 1)

Page 8: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.8 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-3 The System Monitor

(Skill 1)

Page 9: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.9 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Performance Logs and Alerts tool

Records the performance of resources in logs

Used to configure alerts

An alert is configured to perform specific actions

An alert is activated when a threshold value set by an administrator has been met

Introducing Active Directory Performance-Monitoring Tools (5)

(Skill 1)

Page 10: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.10 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-4 The Performance Logs and Alerts snap-in

(Skill 1)

Page 11: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.11 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Event Viewer

Contains messages generated by applications and the operating system in different Event logs

The logs help in understanding problems relating to applications, services, and the operating system

Introducing Active Directory Performance-Monitoring Tools (6)

(Skill 1)

Page 12: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.12 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Event logs

Application log

Security log

System log

Directory Service log

DNS Server log

File Replication Service log

Introducing Active Directory Performance-Monitoring Tools (7)

(Skill 1)

Page 13: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.13 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Application log stores information, errors, or warnings generated by the applications on a computer

Security log

Stores auditing entries

After you configure auditing, use this log to track users who are trying to access objects for which they do not have permissions, among other auditing activities

Introducing Active Directory Performance-Monitoring Tools (8)

(Skill 1)

Page 14: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.14 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

System logStores information, errors, or warnings

generated by the operating system

If you are having trouble starting a service, such as the Task Scheduler, study this log to identify the cause of the problem

Introducing Active Directory Performance-Monitoring Tools (9)

(Skill 1)

Page 15: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.15 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-5 The System Event log

(Skill 1)

Page 16: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.16 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Directory Service log

Stores information, errors, or warnings generated by Active Directory

Available only on domain controllers

DNS Server log stores information, errors, or warnings generated by the Domain Name System (DNS) server

Introducing Active Directory Performance-Monitoring Tools (10)

(Skill 1)

Page 17: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.17 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

File Replication Service log

Stores information, errors, or warnings generated by the File Replication Service

This service is used to replicate the shared system volume (Sysvol) folder

Introducing Active Directory Performance-Monitoring Tools (11)

(Skill 1)

Page 18: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.18 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-6 The File Replication Service Event log

(Skill 1)

Page 19: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.19 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Event logs record five types of messages

Information

Warning

Error

Failure

Success

Introducing Active Directory Performance-Monitoring Tools (12)

(Skill 1)

Page 20: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.20 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Performance console metrics

Performance objects are any system resource, such as memory, a disk, a processor, or a network interface, whose performance one can monitor

Performance counters are performance measures for the object that can be calculated and related as numeric figures

Monitoring Active Directory Performance Counters

(Skill 2)

Page 21: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.21 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Directory Replication Agent (DRA) counters

Largest group of Active Directory-related performance counters

Many of the counters refer to either bytes compressed or bytes not compressed

Record the inbound or outbound replication data sent to or received from other sites

Monitoring Active Directory Performance Counters (2)

(Skill 2)

Page 22: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.22 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Directory Replication Agent (DRA) counters

On some networks, a byte count may not be a valid measure of replication performance

The number of Active Directory objects that have been replicated reflect replication performance

Monitoring Active Directory Performance Counters (3)

(Skill 2)

Page 23: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.23 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Active Directory performance counters for NTDS

Directory Replication Agent (DRA) Inbound Bytes Total/sec

DRA Inbound Full Sync Objects Remaining

DRA Inbound Objects Applied/sec

DRA Inbound Object Updates Remaining in Packet

DRA Pending Replication Synchronizations

Lightweight Directory Access Protocol (LDAP) Client Sessions

LDAP Bind Time

Monitoring Active Directory Performance Counters (4)

(Skill 2)

Page 24: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.24 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Different performance objects and counters are used to monitor hardware resources

Memory

Processor

Hard Disk

Network

Monitoring Active Directory Performance Counters (5)

(Skill 2)

Page 25: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.25 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-7 The Add Counter dialog box

(Skill 2)

Page 26: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.26 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-8 Monitoring Active Directory performance

(Skill 2)

Page 27: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.27 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Performance Logs and Alerts snap-in

Used to collect and record data specific to hardware resources and services

Used to create

Counter logs

Trace logs

Alerts

Creating Performance Logs and Alerts

(Skill 3)

Page 28: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.28 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Counter logs

Use performance objects and performance counters to record data

About hardware resources

About Active Directory

Can be configured to record the statistics for performance counters to collect Active Directory baseline performance data

Creating Performance Logs and Alerts (2)

(Skill 3)

Page 29: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.29 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-9 A counter log

(Skill 3)

Page 30: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.30 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Trace logs

Record data only when an event supported by an operating system or an application occurs

Used to study the effects of hardware resources on the performance of Active Directory

Creating Performance Logs and Alerts (3)

(Skill 3)

Page 31: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.31 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-10 Creating a trace log

(Skill 3)

Page 32: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.32 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Alerts

Actions triggered when a resource or service-related performance counter either surpasses or falls below a specified threshold value

Generally based on baseline data you have collected

Deviations indicate problems with Active Directory performance or problems with various system resources

Creating Performance Logs and Alerts (4)

(Skill 3)

Page 33: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.33 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-11 The New Log Settings dialog box

(Skill 3)

Page 34: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.34 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-12 Creating a counter log

Page 35: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.35 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-13 Adding performance counters

Page 36: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.36 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-14 The new counter log in the Performance console

Page 37: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.37 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Support tools for monitoring and troubleshooting Active Directory performance

Identifying the Active Directory Support Tools

(Skill 4)

Sdcheck.exe

Nltest.exe

Acldiag.exe

Dsacls.exe

Ldp.exe

Replmon.exe

Repadmin.exe

Dsastat.exe

Page 38: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.38 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Ldp.exe

Graphical tool that provides information about objects

Other functions

Connect to domains

Search, modify, add, delete, and bind to LDAP-compatible directories

Troubleshoot problems with Active Directory

Identifying the Active Directory Support Tools (2)

(Skill 4)

Page 39: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.39 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Replmon.exe

Graphical tool providing various reportsReplication status and topology

Performance of domain controllers

Changes that have not replicated from a specified domain controller

Other functionsTroubleshoot replication-related problems

Force synchronization between domain controllers

Identifying the Active Directory Support Tools (3)

(Skill 4)

Page 40: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.40 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-15 The Active Directory Replication Monitor

(Skill 4)

Page 41: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.41 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Repadmin.exe

Command-line tool to diagnose replication problems

Functions

Modify and view replication topologies

View replication information

Force replication between domain controllers

Identifying the Active Directory Support Tools (4)

(Skill 4)

Page 42: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.42 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-16 Repadmin.exe

(Skill 4)

Page 43: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.43 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Dsastat.exe

Command-line tool to diagnose replication problemsCompares Active Directory replicas on various domain

controllers

Compares global catalog servers in a forest

Provides capacity statisticsMegabytes per server

Objects per server

Megabytes per object class

Attributes of replicated objects

Identifying the Active Directory Support Tools (5)

(Skill 4)

Page 44: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.44 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Sdcheck.exe

Command-line tool that lists the security descriptors for Active Directory objects

Discretionary Access Control List (DACL)

System Access Control List (SACL)

Verifies the successful propagation of changes made to the DACLs of objects

Identifying the Active Directory Support Tools (6)

(Skill 4)

Page 45: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.45 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-17 The Security Descriptor Check utility

(Skill 4)

Page 46: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.46 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Nltest.exe

Command-line tool used to perform network administrative tasksCheck the status of trust relationships between domains

Check the connectivity and flow of traffic between domain controllers and computers in a network

Obtain a list of the primary domain controllers on the network

Check domain controller replication

Force a remote shutdown

Obtain data about Active Directory objects

Identifying the Active Directory Support Tools (7)

(Skill 4)

Page 47: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.47 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-18 Nltest.exe

(Skill 4)

Page 48: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.48 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Acldiag.exe is a command-line tool used to diagnose and troubleshoot problems related to permissions set on Active Directory objects

Dsacls.exe

Command-line tool used to manage ACLs

Used to query and modify security attributes of Active Directory objects to troubleshoot problems relating to permissions

Identifying the Active Directory Support Tools (8)

(Skill 4)

Page 49: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.49 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

File Replication Service (FRS)

Ensures that the Sysvol folder is automatically replicated between domain controllers

Is responsible for all automatic replication of Dfs replicas

Key service in Active Directory

FRS failure can have disastrous effects

Several tools are available for monitoring FRS

Monitoring the File Replication Service

(Skill 5)

Page 50: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.50 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Monitoring FRS

File Replication Service log

Should be closely monitored

Most common problems of FRS are logged as errors in the FRS log

Lists of common FRS problems, the Event IDs associated with them, and their solutions are downloadable

Monitoring the File Replication Service (2)

(Skill 5)

Page 51: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.51 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

FRS-specific performance counters

FRSReplicaConn Bindings in Error

FRSReplicaConn Communication Timeouts

FRSReplicaSet Bindings in Error

FRSReplicaSet KB of Staging Space Free

FRSReplicaSet Packets Received in Bytes

FRSReplicaSet Packets Sent in Bytes

Monitoring the File Replication Service (3)

(Skill 5)

Page 52: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.52 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Microsoft tools to monitor and track FRS problems

Ultrasound

Downloadable tool used to monitor the health status of FRS replication sets

Can be configured to send an e-mail notification in case of a problem

FRSDiag

Downloadable graphical tool

Can take snapshots of the replication state and run tests against the service

Monitoring the File Replication Service (4)

(Skill 5)

Page 53: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.53 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Microsoft tools to monitor and track FRS problems

Ntfrsutl.exe

Command line utility included with Windows 2003 Server

Used to take snapshots of the replication state

Sonar

Downloadable command line utility

Used to monitor the status of FRS

Monitoring the File Replication Service (5)

(Skill 5)

Page 54: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.54 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Figure 13-19 Ntfrsutl.exe

(Skill 5)

Page 55: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.55 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

You must be able to diagnose and resolve the more commonly experienced replication errors

Slow replication is the most common problem

Causes of replication latencyLink speed

Available bandwidth

Replication topology

Replication timers

Disabled Web sites

Overloaded domain controllers

Resolving Replication Errors

(Skill 6)

Page 56: 13.1 © 2004 Pearson Education, Inc. Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.

13.56 © 2004 Pearson Education, Inc.

Exam 70-294 Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure

Lesson 13: Monitoring Active Directory Performance

Common replication errors

Event ID 1311 shown in the Directory Service Log

Event ID 1265 and the error “RPC Server is Unavailable” shown in the Directory Service Log

“Access is denied” message when attempting to force replication

Resolving Replication Errors (2)

(Skill 6)