Re: DC replacement



"JimyJohn" <JimyJohn@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:24A65B97-318E-4657-8E39-DAD539EDFCEE@xxxxxxxxxxxxxxxx
Herb, thanks for your reply!

Yes there are two DCs and we only need to replace one. The concern is that
when we shut off one of the DCs and the client recieving, say tickets from
that server will error instead of just finding the other DC. I assumed
that
is how it would work, failing over automaticaly, but my friend suggested
that
in his experience clients connected to the shut off server would error
and
require re-logon.

No, likely he has had experience with malfunctioning
DCs which is usually due to DNS problems so that when
one goes down the other isn't really usable.

Even under NT (long before Kerberos tickets) the client
machines would switch over to another DC.

As for replacement plan I thought we could just create a new DC and join
it
into the Forrest/Domain. ASR would work too but thought that was more of a
DR
tool.

A lot of people underestimate the uses of ASR -- it and
"REPAIR installs" are among the best kept OPEN 'secrets'
for recovering, moving, and salvaging Windows machines.

My impression is that you just wanted to replace hardware
with the least network disturbance.

If the DC doesn't do anything else significant you can just
add the other DC as you plan.

Generally, I would do that first -- then remove the departing
one.

Also make sure the departing DC is not taking your (only)GC,
FSMO roles, or a DNS server on which the clients depend.
(Also WINS server fits in here.)



--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]

Thanks again.
Regards, John

"Herb Martin" wrote:

"JimyJohn" <JimyJohn@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DFD9111D-4078-425A-89E8-B8AFF285169E@xxxxxxxxxxxxxxxx
We are to replace the hardward under a 2003 Domain controller.
I think it is in a 2003 forrest and domain. single office, no sites.
There are 2 DCs plus third on a VM.

A friend told me that to replace a DCs would cause logged on users to
get
errors and have to re-logon. Is that true?

It would be nice to make this transparent to Users.

Do you have other DCs online and available (locally)
so that this DC can just be stopped normally?

Authentication will proceed (ticket renews and such too)
with another DC if this one goes down.

If true, is there a way to have a DC stop accepting new logons so this
DC
may be phased out? Possibly a utility to show the what logons a DC is
maintaining currently?

Client machines are designed to find another DC when
their "secure channel" DC disappears. IF this were not
true you would have trouble every time you rebooted a
DC.

Any help would be very much appreiciated.

How are you going to do the transfer?

(ASR might help.)




--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


Regards, John






.



Relevant Pages

  • Re: SYSVOL synchronisation---login script ???
    ... Jetzt hat der Client, standartmaessig ... DCs, die Clients sich an dem anderen DC authentifizieren können. ... Mit zwei DCs ist eben die Ausfallsicherheit gewährt. ... Yusuf Dikmenoglu - MVP Windows Server ...
    (microsoft.public.de.german.windows.server.networking)
  • Re: PINGing the Active Directory Domain
    ... If no DC are in that AD Site, the DCs in the nearest AD site will cover that AD site by registering their records in the DC-less AD site. ... If a client does not know in what site it is in it will ask for a DC in that same domain by querying DNS with: ... By default all DCs in AD domain will register that DNS SRV record. ... It can be really annoying when some client in branch office X is authenticating to a DC in branch office Y, while then WAN links between both branch offices and the datacenter are not that fast. ...
    (microsoft.public.windows.server.active_directory)
  • Re: NT4-2003 Migration = NT and 9X problems
    ... Did you check the PDC Emulaptor work properly in domain? ... Please remove the lmhost file on the client and check what is the 1c record ... on WINS server pointing to. ... > Please make sure that you have point all the DCs and clients to the ...
    (microsoft.public.windows.server.migration)
  • Re: DC replacement
    ... "Herb Martin" wrote: ... Yes there are two DCs and we only need to replace one. ... that server will error instead of just finding the other DC. ... Even under NT the client ...
    (microsoft.public.windows.server.active_directory)
  • Re: Overloading problem after adding 2003 DCs to 2000 domain.
    ... I don't think if all Windows Server 2003 DCs down will cause ... client to authenticate with the DCs outside of this site because: ... Therefore, if Windows Server 2003 DCs are all down, netlogon will try the ...
    (microsoft.public.windows.server.migration)

Quantcast