pantscat Posted November 14, 2013 Posted November 14, 2013 Sorry to be late to the party again, but if you're having problems with AD, I would be a little wary about demoting a DC unless it won't have any impact. Have you checked the output of "REPADMIN /SHOWREPS"? Might help...
pantscat Posted November 14, 2013 Posted November 14, 2013 A little bit of further research show that this might be useful for you: Troubleshooting AD Replication error 1396: Logon Failure: The target account name is incorrect. 1
forde52 Posted November 14, 2013 Author Posted November 14, 2013 Thanks for that, I'll take a look now and see what I can come up with! I've attached the results of the repadmin, the new server has no errors but the old one shows quite a few. OldDCReps.txt NewDCReps.txt
pantscat Posted November 14, 2013 Posted November 14, 2013 Hmm looks to me like the answer may be in that KB article. Of course your other option is to just 'ungracefully' trash the old DC - force the new one to take on the roles and then tidy up using ADSI edit.
forde52 Posted November 14, 2013 Author Posted November 14, 2013 I have been thinking about doing that, but the other day when I give the new server the roles and took the network cable out of the old server, everything stopped working. I suppose I didn't do that the correct way but I was interested in seeing what would stop if I were to just remove the old server.
pantscat Posted November 14, 2013 Posted November 14, 2013 Hmm... things shouldn't stop working if done correctly. Are all the client machines using the new DC as their DNS server?
pantscat Posted November 14, 2013 Posted November 14, 2013 Odd then that things would stop working completely. But if Active Directory is still referring to the old DC this could cause a lot of problems. I'd try and fix the problem before going down the destructive route.
forde52 Posted November 14, 2013 Author Posted November 14, 2013 Yeah I agree, It's the fixing of the problem that's proving difficult at the moment sadly .
pantscat Posted November 14, 2013 Posted November 14, 2013 Yes, sorry, didn't mean to patronise. Good luck. Feel free to ask any more questions!
forde52 Posted November 14, 2013 Author Posted November 14, 2013 Haha don't worry you didn't! If I knew what to ask I would. It's confusing me as to why it's not working. If I try to demote the old server from DC using DCPROMO, it tells me that it could not find any other domain controllers for the domain. But if i try to demote the new server from DC I don't get that message and can successfully demote it. It is certainly something with the old server that's wrong.
fiza Posted November 14, 2013 Posted November 14, 2013 If you update something in netlogon on the new DC does it get replicated to the old DC?
forde52 Posted November 14, 2013 Author Posted November 14, 2013 Netlogon is supposed to be a share right? If so the new server doesn't have one.
fiza Posted November 14, 2013 Posted November 14, 2013 If the new server is a DC in the same domain as the old DC then it should have a netlogon share. \\servername\netlogon
forde52 Posted November 14, 2013 Author Posted November 14, 2013 Hmm, this one doesn't. I've just found an artical on how to get the DC to produce one, so i'll do that now and see if anything changes!
forde52 Posted November 14, 2013 Author Posted November 14, 2013 after following this artical, the netlogon share has still not been created. The netlogon service is running though!
sted Posted November 14, 2013 Posted November 14, 2013 before you do ANYTHING with sysvol / netlogon take a copy of it first I had a server where I needed to rebuild it and thank f id copied it off it deleted all my policies in the process 1
forde52 Posted November 14, 2013 Author Posted November 14, 2013 (edited) Good Idea, I'll do that now! Although it doesn't make it easy when explorer crashes when you click on it anywhere (this is on the old server). Edited November 14, 2013 by forde52
fiza Posted November 14, 2013 Posted November 14, 2013 You have probably tried all of this already but a good guide here : itToby: Safely Demote a Windows 2008/r2 Core Domain Controller
edutech4schools Posted November 14, 2013 Posted November 14, 2013 Not wanting to divert you from your replication DNS issues which you probably should sort first but when I had a server that would not demote doing a dc promo I had to make sure DNS nic settings and Wins settings on the old server were only pointing to the old server(noting in line 2 of the dns nic settings), make sure it was not a GC anymore and for some reason disable any extra network cards. Just my 2 pennies worth which you can choose to ignore. 1
forde52 Posted November 14, 2013 Author Posted November 14, 2013 That looks a handy guide so I'll follow that when i attempt to take it off line again. Just going through the Directory Service event log on the old server, and it is full of warnings about KCC, error 1925. I appear to be getting 3 errors at 15Minuite intervals. Looking at ways to resolve it at the moment.
forde52 Posted November 14, 2013 Author Posted November 14, 2013 I had to make sure DNS nic settings and Wins settings on the old server were only pointing to the old server(noting in line 2 of the dns nic settings), make sure it was not a GC anymore and for some reason disable any extra network cards. I might take a look at that actually, I think it still is a GC so i'll remove that now. the DNS is pointing to both old and new, so i'll change that as well and see if anything changes!
edutech4schools Posted November 14, 2013 Posted November 14, 2013 Also, did you adprep forestprep etc. What OS are you going from and too. sorry if you have mentioned this, i skimmed all the posts.
forde52 Posted November 14, 2013 Author Posted November 14, 2013 No worries! It's 2008R2 to 2008R2, so the same OS. The network did run on a 2003R2 DC but I upgraded it to the current 2008R2 server 2 years ago. I did raise the forest and domain function levels to 2008R2 just before I attempted to add this new server into the domain though!
fiza Posted November 14, 2013 Posted November 14, 2013 Not exactly your issue but has the sysvol problem so worth a look at ; 2008 R2 domain controller will not replicate SYSVOL to another controller (after a disaster recovery) 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now