Jump to content

Recommended Posts

Posted
also check server options

 

If your old DC's are listed in server options then remove them. You don't necessarily need any options configured in there. Your new DC's do however need to be in your scope options

Posted
If your old DC's are listed in server options then remove them. You don't necessarily need any options configured in there. Your new DC's do however need to be in your scope options

 

In Server Options, the new DC's, the old DC's and the server 2000 DC's that preceded those are in as well! I'll clean those up.

 

In Scope Options, the new DC's and the old DC's are in.

Posted
I think I know what is going on. Just quickly read through the thread and not 100% sure if this as been checked yet, doesn't look like it. Did you say you haven't demoted the old servers, just switched them off?

 

In DNS take a look under -> \Forward Lookup Zones\_msdcs.\dc\_sites\_tcp and tell me what you see. I suspect your old servers are still listed here, and under other subtrees in _msdcs. Mainly because the old servers are not demoted to DNS/AD still thinks they are valid domain controllers.

 

The clients are asking to communicate with a DC, they don't care which. DNS is responding randomly with what it thinks is still a valid DC, but the DC it chooses is switched off - thus the problem.

 

I'd demote the old DC's and make sure the _msdcs subtrees are properly cleaned up, then see if your problems still persist after that.

 

Thanks very much. I've been loathe to demote anything until I managed to get logons working when they couldn't contact the problematic old DC. If it's precisely because they can't contact the old DC that is causing the problem, I might have to bite the bullet (in the summer holidays) and demote both old DC's.

Posted
Here's the broken attachment...

 

[ATTACH=CONFIG]30797[/ATTACH]

 

That seems to be normal behaviour from what I can see...

Tried it on a couple of domains, and did a google search to confirm.

Posted

I agree with most comments here - the issue is most likely DNS, and/or Global Catalogue related. It's also possible the 2003 > 2012 DC promotion/transfer wasn't clean, hence why you're getting these random issues, despite the roles appearing to transfer correctly.

 

Generally speaking however, the FSMO roles do not transfer if DNS is duff or mis-configured, as it won't be able to resolve the new 2012 DC.

 

Make sure DNS can replicate to each server - in turn view the Properties of each Zone - Forward and Reverse on each server.

 

Also, if you look in Active Directory, it will tell you if your 2003 box is still a Global Catalogue. I suspect this is most likely the problem. You only generally need to control DNS using GPOs when you're using Trusts, otherwise DHCP Server is sufficient for a simple/basic domain.

  • Thanks 1
Posted
I agree with most comments here - the issue is most likely DNS, and/or Global Catalogue related. It's also possible the 2003 > 2012 DC promotion/transfer wasn't clean, hence why you're getting these random issues, despite the roles appearing to transfer correctly.

 

Generally speaking however, the FSMO roles do not transfer if DNS is duff or mis-configured, as it won't be able to resolve the new 2012 DC.

 

Make sure DNS can replicate to each server - in turn view the Properties of each Zone - Forward and Reverse on each server.

 

Also, if you look in Active Directory, it will tell you if your 2003 box is still a Global Catalogue. I suspect this is most likely the problem. You only generally need to control DNS using GPOs when you're using Trusts, otherwise DHCP Server is sufficient for a simple/basic domain.

 

DNS replication seems to be fine and transferring around all of the boxes. The FSMO roles all transferred without a hitch.

 

The 2003 boxes are still Global Catalogue servers in AD. All signs seem to point to me needing to remove them from GC, from DNS, and demote them. We're not pushing any DNS settings through GPO.

Posted
Have you set one of the new DCs to be a global catalog?

 

Unless you have a very good reason, ideally all DC's should host a copy of the Global Catalog. If for no other reason than backup, redundancy, fail over. But also because there rules as to where FSMO roles should be placed in relation to each other and the GC (WindowsDevCenter.com) that are totally negated if all DC hold the GC - ie, it's simpler to set up all FMSO roles on one master primary DC.

  • Thanks 1
  • 1 month later...
Posted

Hi all,

 

Can I just say a massive thankyou to everyone who contributed to this thread. It's the first day of our summer break, so I've taken the plunge and demoted the two old DC's. I removed them from the Global Catalogue, had to uninstall certificate services from one DC (it wasn't being used anywhere) and then ran DCPROMO on both servers. I then removed them from DHCP and all seems fine. Logged on over 100 PC's 4 or 5 times and apart from a bit of slowness logging on for a couple, the logon scripts are all processing.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...