Jump to content

Recommended Posts

Posted

Hi, I have been experiencing trouble in adding an additional server 2012 dc to run Sophos Enterprise console antivirus.

 

My main DC is running well with the following IP details:

IP:10.75.44.10

Sub: 255.255.255.0

GW: 10.75.44.1

DNS1: 127.0.0.1

DNS2: 172.30.178.53 (LGFL DNS server)

This server has DNS and DHCP server configured

 

I added a second DC with the following static IP details:

IP:10.75.44.11

Sub: 255.255.255.0

GW: 10.75.44.1

DNS1: 10.75.44.10

 

Server 2 joined the domain with no problems. I continued to spend the day adding systems to the domain and in the afternoon discovered that the active directories between the two systems had not synced. After rebooting and trying various things online, it seemed that they were just not communicating correctly.

 

Can anyone tell me where I am going wrong as I can't see a problem with my IP details.

Firewall is off. I have even tried DHCP on the secondary DC as the first server is a DHCP server.

 

I was getting errors such as the following:

KCC could not add this REPLICA LINK due to error

The target principal name is incorrect.

Posted
You should only have internal addresses as your dns servers. Each server should have the other as its primary and itself as secondary. Also run a dcdiag test to show any other issues

 

Thanks for your reply. I ended up removing the second DC as it was causing chaos when adding client machines to the network. Well over 20 went onto the second DC and I could not get them over to the first one, so had to remove them all and re-join.

 

I will bear this in mind when I re-add the second server as a DC as I need to do this for the Antivirus software.

 

Do I need to edit the DNS settings at all or leave them as they are?

The main server has the two external LGFL DNS IP numbers as its forwarders? I had not even installed DNS server on the second server, is that correct?

Posted
Don't add the Sophos EC to a domain controller, that's a big mistake (from experience!) You want it on its own server or VM.

 

Ok, that can be done, but how would I then deploy it to a domain it is not on?

Posted
Make the server a member of the domain. Not a Domain Controller though.

 

Ok, so join it as though it were a client computer just like any other?

Didn't realise I could do that?

Posted
Yep. Not all servers need to be domain contollers. Just join it to the domain as you would a normal pc. It is good practice to have two domain controllers. But domain contoller should only host ad, dns and dhcp. Id avoid adding anything else and use member servers instead
  • Thanks 1
Posted
Yep. Not all servers need to be domain contollers. Just join it to the domain as you would a normal pc. It is good practice to have two domain controllers. But domain contoller should only host ad, dns and dhcp. Id avoid adding anything else and use member servers instead

 

Thanks, that is really helpful. I have added it as a domain member and created a new OU for it called secondary servers. I would like it to manage WSUS too, so I have given it a separate OU so I can configure its firewall settings etc.

So far, so good. Just need to get Sophos on next.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...