Jump to content

Recommended Posts

Posted

Hi all,

 

Here's the scenario, any help would be much appreciated -

 

2 x 2008 R2 Servers configured as Domain Controllers, the one DC has all roles.

 

The DC with all the roles was restored, however although it appears to be working, it is/isn't working fully and likewise clients connecting to it.

 

On the Secondary DC, AD looks normal as does Sysvol. On the Primary DC, Sysvol does not look normal, but is retrieving AD and GPOs from the Secondary DC.

 

DHCP and DNS are working OK.

 

Clients are unable to map all drives hosted on the restored DC (as far as I can gather), as the computer account SID has changed.

 

Any ideas how I can resolve this would be much appreciated!

Posted

Is the replication in Sysvol 100% working? If you stick a text file in the Netlogon folder on one does it appear on the other and vice versa?

 

On a client can you get to the share using the ip address eg: \\192.168.1.1\share

  • Thanks 2
Posted

I wouldn't spend a huge amount of time trying to fix the DC that's playing up. I'd get the roles transfered to the other, and switch it off. Check, test, perform a magic dance of hope, and if everything is working with just one DC, build the other from scratch. My experience with 2008 R2 is that it's a great OS, but DFS-R doesn't work as well as it should and if it falls over it's best left down.

 

If you do want to continue error checking, look at the system logs for any issues with the JET database causing replication errors. The instructions to fix this are contained within the log if so.

 

Are the mapped drives actually mapping to the restored DC (to a share on it)? If so this obviously complicates things a little. You can still demote this machine as a DC if so, strip it of all AD roles, then build it back in.

  • Thanks 1
Posted

No Sysvol isn't replicating correctly.

 

I can transfer the PDC and Infrastructure roles. I can't do the remaining three as the FSMO holder cannot be contacted.

Posted
Thank you, that worked like a charm! :) Of all the years I've worked in IT, I've never exercised such drastic measures! It's something I probably last looked at in the Windows 2000 days (showing my age)! Thanks again guys! :)
Posted (edited)

Had to do a similar thing just the other week.

 

Our second DC went down a few months back. Shouldn't of had any roles assigned to it, was just a secondary.

 

Came in the other morning to find nothing working, checked the DC and it was full of errors.

Jist of it was, it couldn't communicate with the other for so long that it decided to refuse any logins.

 

Went into AD and deleted the second offline DC and it goes through all the warning and it asks if the other server will be permanently offline so it can seize the roles forcefully without the other server needing to be on.

Only takes a moment to do.

 

With two DC's i dont think i would ever restore one, causes to many issues with syncing and stuff.

Best to start it up in offline mode, grab your data and run.

 

Just re-read and recheck 1 million times that your deleting the right one. Then check again.

Edited by DCUK6

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...