Jump to content

need some advice urgently failed dc how to stop logons trying to authenticate against


Recommended Posts

Posted

Hi i have a backup domain controller and it has died how can i stop computers from trying to authenticate from it.

 

do i remove the a record from trom dns to stop this or can someone give me an idea of how to stop authentification from this server

 

server 2003

Posted

Thanks for that

 

just a few questions

 

 

I have 2 servers one being my main server and the other is a backup domain controller that has dns and dhcp etc

 

i can log onto the failed domain controller using activ directory recovery mode

 

i should then perform the command

 

Dcpromo /forceremoval

 

this should not break my existing main domain controller is this correct?

 

i will need to perform a metadata cleanup after

 

or as i can actually get onto the failed domain controller should i do something different

Posted

This depends on what state the DC is in. If you can log onto the failed DC then I would try demoting this DC and removing active directory first.

 

See the article below.

Demote a domain controller: Active Directory

 

If you are able to successfully demote the failed DC, you shouldn't need to perform any metadata clean-up this is only usually required if the DC has failed and is not accessible.

You MUST also ensure that you transfer all FSMO roles and make the other DC the global catalogue.

The articles I have previously provided will assist you completing the required tasks.

  • Thanks 1
Posted

My main server is already the GC

 

the failed server was just a backup for the main server as the roles it had are DNS DHCP

 

I think i will bite the bullet tomorrow

Its nice to get the Gotchas out of the way thats why I asked

 

The macs are funny with DNS im pretty sure it is that

 

as i can rebind them and then once they are rebooted the users can not log on........what a pain in the rear i have to rebind again.

 

It kinda sucks

thanks again

Posted (edited)

just checking before i try and demote the old server

my main server holds these roles a does this look ok(well it must be otherwise all our windows network would be down face palm moment)

 

 

Schema master SCHOOLSERVER.mydomain.local

Domain naming master SCHOOLSERVER.mydomain.local

PDC SCHOOLSERVER.mydomain.local

RID pool manager SCHOOLSERVER.mydomain.local

Infrastructure master SCHOOLSERVER.mydomain.local

The command completed successfully.

 

Only thing i could not see was wins role

Edited by round2it
Posted

I don't know if your .local domain is part of this problem, but I've personally seem that cause a load of other problems with Macs. So much so, now I wouldn't touch a .local domain with a 10 foot pole when it comes to Macs. Been there, done that. Never again.

 

That said, you don't have the Macs set to prefer the domain controller that died do you? That is an option and could certainly cause problems. Otherwise, I have never seen Macs have a problem with a missing AD server. Of course, your DNS may be completely stuffed and that could be causing it as well.

 

I strongly suggest diving into the console after logon failures (with a local user) and searching for the username that failed to logon. You should learn quite a lot about the cause of the problem that way. And of course, check DNS resolution to your servers.

  • Thanks 1
Posted

ok

ping fqdn and ip on the mac client both resolve

 

did dcdiag and only errors are from replication this is expected due to dead server. cant demote failed server through recovery mode so i need to clean meta data and stop replication of dns

  • 3 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...