site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
469
Share Topic
Posting?
Post a:
Post a:
AuthorAll Replies


elwoodblues
Elwood Blues
Premium
join:2006-08-30
HarperLand
Reviews:
·Cybersurf Intern..

W2K8 DC in W2K3 Domain/Forest

I've just walked into this project the previous person left it hanging, and now I have to clean it up.

So the client has a W2K3 server as their DC, the previous person bought them a new server and made it a W2k8 R2 DC, or did they?

Both servers are setup as GC's both servers show in the AD as domain controllers.

However I noticed that the Sysvol and netlogon shares are not on the W28R2 server when I type in //w2k8r2 server.

It also fails DCDIAG , something along the lines of advertising(sorry don't have access this very moment and working from memory).

The W2K3 box has a DNS pointing to 127.0.0.1 ? while the W2K8R2 server has it pointing to it's primary address and the W2K3 server.

The W2K3 Server has a domain functional level of Windows 2003 but a forest level of 2000 (don't recall if mixed or native).

My plan of attack was to role back the DC role from the W2K8 box and do it again , in case there were warnings and somebody ignored them.

Or is my issue that the Forest level is too low?
--
No, I didn't. Honest... I ran out of gas. I... I had a flat tire. I didn't have enough money for cab fare. My tux didn't come back from the cleaners. An old friend came in from out of town. Someone stole my car. There was an earthquake.......


The WeaseL
Premium
join:2001-12-03
Minnesota

A Windows 2000 forest level should be fine to deploy an R2 domain controller.

I would do what you plan to do. Take the bad DC out, nuke and start over.
--
How lucky am I to have known someone who is so hard to say good-bye to.


tomdlgns

join:2003-03-21
Chicago, IL

reply to elwoodblues
if you dont use 127.0.0.1, you would be using the ip of the DNS server. in this case, using its own ip is the same as 127.0.0.1 since it is the primary DNS server.

the second entry should be the 2k8 box IP.

on the 2k8 box

primary should be the 2k3 box and secondary should be the 2k8 box, or on that server, 127.0.0.1

i have always used the actual IPs and not 127.0.0.1, but it should work....actually, it is working, based off of what you posted.



DarkLogix
Premium
join:2008-10-23
Baytown, TX
kudos:3

Normally when setting up a DC I point primary DNS to an already existing DC, but then after DCpromo I change it to 127.0.0.1 because it should always be able to hit 127.0.0.1 even if the cable is unplugged but if the cable is unplugged the actual IP might not work (partly seems to depend on OS and nic driver)

pre-dcpromo it needs to be pointed to a DNS server for the domain but post DCpromo it can use itsself


lorennerol
Premium
join:2003-10-29
Seattle, WA

reply to elwoodblues
Just had this issue at a client: Setup a new 2008 R2 server, DCPromo, no netlogon and sysvol shares.

Have had it happen one other time, too.

1. Make sure DNS is setup and working correctly on both DCs.
2. Make sure FRS is running on both DCs (this is how the sysvol is copied from one to the other.
3. Check the 2008 R2 box to make sure the sysvol is there.

The sysvol and netlogon shares are not created until both DCs agree that sucessful replication has taken place. If that's stalled or failed for some reason, you can use the burflags registry key to set the orginal DC as authoritative and the new DCs as in need of a full replication. The former is a D2 reg setting and the latter is D4.

A number of KB articles address this, though I found them all a bit lacking for specifics, so here's what I did that worked:

Stop FRS on both DCs.
Set the burflag key to D2 on the source/authoritative DC.
Set the burflag key to D4 on the new DC.
Start FRS on the source DC
Start FRS on the new DC

Watch the event logs for errors. If none, the sysvol should replicate. After replication you may need to restart the netlogon service on the new DC for the netlogon share to be created.



DarkLogix
Premium
join:2008-10-23
Baytown, TX
kudos:3

I actually forgot the exact process that I use for 2008R2 but heres what I think I had worked out
1a. Set DNS to point at pre-existing DC
1b. join domain
2. install DNS
3. ensure all updates are applied (you remember that DNS mess last year right)

4. open an admin command prompt and run dcpromo
5. follow the setps and note any errors, also check teh GC checkbox (unless you plan it to become the Infrastructure master)

6. reboot
7. point DNS at itsself


Monday, 04-Jun 02:54:23 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics