Re: new domain setup

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Param R. (pr_at_nospam.com)
Date: 11/05/04


Date: Fri, 5 Nov 2004 00:34:22 -0600

Mike, the IIS websites running on the DC will be for internal use only. Also
lets say I add a second DC in about 2 weeks. Is there anyway I can make it
the Primary DC and demote the current DC to Backup DC?

TIA!

"Miha Pihler" <mihap-news@atlantis.si> wrote in message
news:O30ZPoswEHA.1984@TK2MSFTNGP14.phx.gbl...
> Hi,
>
> You can add as many domain controllers later as you need. You setup a new
> computer running e.g. Windows 2003, you patch it up with all the latest
> updates (before joining it to domain). Once all patched up, join it to
> domain and run dcpromo on it. This will make it new DC. Also make all your
> DCs DNS servers (configure them as Active Directory Integrated DCs).
>
> Again, before running DCpromo or before joining server to domain (or any
> other PC), make sure that they are all patched up.
>
> Personally I am against IIS running on DC (there is no need for it) and in
> case of e.g. IIS security bridge (this could also be due to bad IIS
> configuration) someone could gain access to files on DC or create new user
> account or ...
>
> The only services that I usually allow to run on my DCs are DNS and
> DHCP...
>
> Feel free to post back with any additional questions that you might
> have...
>
> Mike
>
> "Param R." <pr@nospam.com> wrote in message
> news:OxrxcMowEHA.1564@TK2MSFTNGP09.phx.gbl...
>> Hi all, over the next few weeks I have to work on setting up a new domain
>> environment at our data center. All machines will be running 2003. Some
>> web and some standard. The problem is when I am doing the setup I will
>> have 3 servers with me. I will have to set these up and then later go get
>> the 2 other servers which are in a different location. The problem is I
>> eventually want my main Domain Controller to be one of the machines at
>> the other location. It is a more powerful box than the 3 readily
>> available to me. So in theory I will use one of the currently available
>> boxes as a Domain Controller for now until I can go get the other
>> machines. Is it possible to install a box at a later point and make it
>> the main DC? If yes, how would I go about doing so and what do I need to
>> watch out for?
>>
>> Also, I have never installed a DC before. What steps do I need to follow?
>> I will also be installing DNS on the DC boxes. DNS will only be used for
>> internal use, so it is recommended to have DNS integrated with A/D rather
>> than in flat files right? Here are the steps I am thinking:-
>>
>> 1. Boot from CD and do base install.
>> 2. Run DCPROMO
>> 3. Install DNS, IIS & Other Services.
>>
>> Any help here is much appreciated.
>>
>> thanks,
>> Param
>>
>
>



Relevant Pages

  • Re: Global Catalog Location
    ... It *could* be a DNS issue (as you well know it can almost always be a DNS ... I would suggest that the op install the set up Sites in the ADSS ... netdiag /v on all Servers. ... on all of the remote DCs as well as then ...
    (microsoft.public.win2000.active_directory)
  • Re: new domain setup
    ... DCs DNS servers. ... The only services that I usually allow to run on my DCs are DNS and DHCP... ... > Domain Controller for now until I can go get the other machines. ... Boot from CD and do base install. ...
    (microsoft.public.windows.server.setup)
  • Re: New 2003 AD server
    ... complexity, and password history requirements. ... install DNS. ... >servers and create a site and it replicates fine. ...
    (microsoft.public.windows.server.active_directory)
  • Re: New 2003 AD server
    ... > I'm starting with 2003 AD in a test lab with two servers. ... installed os and ran winzard to setup new forest and install DNS. ... trying to create a user in AD to see if it replicates in both servers and I ...
    (microsoft.public.windows.server.active_directory)
  • Re: Help SMPT Errors
    ... FAIL Reverse DNS entries for MX records ERROR: The IP of one or more of your ... it may mean that your DNS servers did not respond fast enough). ... INFO NS records at parent servers Your NS records at the parent servers ... PASS Parent nameservers have your nameservers listed OK. ...
    (microsoft.public.exchange.admin)