Re: newbie questions



"s" <s@xxxxxxxxxxxxxx> wrote in message
news:1163526669.838874.172040@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I am an absolute newbie to Active Directory and System administration
in general. I have read Active Directory 2nd edition by O Reilly. Can
anybody please give some ideas for a total starter? Should I read more
or should I start experimenting?

Both, but if you have to pick on then experimenting.

You have absorbed a lot of facts in reading that (very good)
book but you now need to apply it.

You need to do a DCPromo on a TEST domain -- i.e.,
one you do NOT intend to use for production and then
try a lot of things. If you don't tear it up and need to
re-install then you aren't trying hard enough.

Bend it, break it, fold it, mutilated it. Both the DC and
Domain.

Your goal is to make as many mistakes NOW as you
can and to learn how to fix them or (better) to avoid
them in the future.

I am going through group archives
which is helping me a lot.

That's good too. Probably the best resource you aren't
mentioning is the BUILT-IN HELP which is excellent.

A good place to start is with the search:

[ checklist Active Directory ]

Or

[ checklist DNS ]

Also, are there any specific points a newbie should be aware of?

A key point: Practically all AD replication and authentication
problems are REALLY DNS issues at heart (assuming you have
basic network functionality.)

Whenever you suspect a DC replication or client authentication
problem IMMEDIATELY THINK: DNS, DNS, DNS*

Your help and time would be highly appreciated.

Sure we are happy to help but generally you have to ask
(specific) questions and that means you have to try things
and then ask about problems and design choices.

What is your ultimate goal with AD? Admin a real domain
you already own (e.g., upgrade from NT), get a job, just
curious, get a promotion where there is already an AD
domain, etc.?

Here is some brief stuff on DNS for AD (that practically
everyone messes up in the earlier learning stages):

1) Dynamic for the zone supporting AD
2) All internal DNS clients NIC\IP properties must specify SOLELY
that internal, dynamic DNS server (set.)
3) DCs and even DNS servers are DNS clients too -- see #2
4) If you have more than one Domain, every DNS server must
be able to resolve ALL domains (either directly or indirectly)

netdiag /fix

....or maybe:

dcdiag /fix

(Win2003 can do this from Support tools):
nltest /dsregdns /server:DC-ServerNameGoesHere
http://support.microsoft.com/kb/q260371/

Ensure that DNS zones/domains are fully replicated to all DNS
servers for that (internal) zone/domain.

Also useful may be running DCDiag on each DC, sending the
output to a text file, and searching for FAIL, ERROR, WARN.

Single Label domain zone names are a problem Google:
[ "SINGLE LABEL" domain names DNS 2000 | 2003 microsoft: ]


--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]

Thanks a lot.



.



Relevant Pages

  • Re: DHCP Clients getting DNS lookup failures
    ... It sounds to me like you had a DNS issue but you fixed it, ... The DNS server has encountered a critical error from the Active ... Check that the Active Directory is functioning properly. ... Active Directory for this zone and is unable to load the zone without ...
    (microsoft.public.windows.server.sbs)
  • Re: event 4015 and 4004 on W2K2 DC
    ... How is DNS setup, Active directory integrated zones? ... Check that you have configured the forwarders tab on all DNS server properties in the DNS management console, pointing to your ISP's DNS server and of course all clients have to know the second DNS servers ip. ... Directory for this zone and is unable to load the zone without it. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Split-Brain DNS
    ... > What do I need to do to setup split-brain DNS for the company? ... > external DNS server I have setup on our DMZ, ... Deploying and Designing Active Directory [DNS Design, Migration, Cert Auth, ... Download details Windows Server 2003 Active Directory Branch Office Guide: ...
    (microsoft.public.windows.server.dns)
  • [LONG - PLS HELP] Issues on DNS
    ... Active Directory successfully replicated using the NetBIOS ... or fully qualified computer name of the source domain controller. ... DNS Server: ... The DNS server was unable to open zone mydomain.local in the Active ...
    (microsoft.public.windows.server.dns)
  • Re: DNS Error 4011 on Active Directory-Integrated DNS
    ... Integrated DNS, and I've recently been getting the following error ... Active Directory is functioning properly and add or update this ... DOMAIN\Administrators -- Full Control ... The DNS server seems to function properly, but I'd like to fix this ...
    (microsoft.public.windows.server.dns)

Loading