Jump to content

Recommended Posts

Posted

Hi,

 

I had an issue with our DC running server 2008 R2 and unfortunately without thinking after if blue screened restored a snapshot via VMware. This has caused issues with replication and its our primary dc with all the fsmo roles. I have another DC and its still up and working an can access Active Directory and things look ok for now. This has caused it to go into a state of USN rollback and stopped replication. I have turned the server off at the moment.

 

I do have a full backup for each of the servers via veeam.

 

My question is do I

1. Seize all the FSMO roles and move them to the working dc and then do a meta cleanup etc? (any links of helpful documents would be appreciated) Server 2008

2. Try and do a full restore via veeam for one or both the servers?

 

I need to make sure the password for the local servers is correct(can i change this and the dsrm password)

 

Thank you in advance

Posted (edited)

These are usually MS steps on this: https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/detect-and-recover-from-usn-rollback#recover-from-a-usn-rollback

 

It depends if you have a live DC it would be more risky to restore both unless you need to for a major incident. That how I would see it. It also depends on the how much changes their has been since the backup. If I was in the situation I would do option 1. Also server 2008 r2 is out of support unless you have an agreement with MS.

Edited by willtech
  • Thanks 1
Posted

Yeah I too would go with option 1, minimum change as possible here initially. Once the remaining DC has all the roles and you have cleaned up the meta data look at introducing a new DC on the most recent OS and then get replication working between those (There may well be some intermediate steps involved in getting this working, depending on your current configuration) then migrate the FSMO roles to that new DC and remove the 2008 x DC and rebuild a new one on the same OS.

 

You have learned the hard way round when restoring a DC here, if you have a functional DC then you should try not to restore a bust DC, "'Treat your servers like cattle not pets." to quote Jeffery Snover.

  • Thanks 1
Posted

Thanks for the reply

 

I have veeam backup and replication and I have restored the server using a non- authoritative restore. It was looking fine until I logged back in and was unable to communicate with my secondary dc. I can connect via a unc path from my failed dc to my secondary but nothing from my secondary to my failed dc. No replication and was giving me an error about the server name is invalid and active directory did not sync.

 

Do I need to perform anthing else after a non authoritative restore?

 

 

I think I am going to seize the roles if I cant get anything to work soon and try and work out how to move the dhcp server from split to my secondary if anyone knows how to do that?

 

Thanks in advance

  • 2 months later...
Posted

Sorry for starting this thread again.

I am in similar situation as you were itgeeg, except I have 3 DCs (one physical) and Dc2 keeps blue screening. At the moment everything seems to be working fine. I have a backup a few days old and the server started to play up early afternoon today. Did you manage to solve your issue using restore from backup in the end?

 

Thanks in advance.

Posted
I will reiterate unless you have something else running on that DC that you can absolutely not do without, then you are best off just killing it and standing up a new one.
  • Thanks 1
Posted
...and if you do have something you cannot live without on the broken DC, you still abandon the broken DC and build new.... because you can use the VEEAM virtual lab feature to bring up an backup of the broken dc in a private sandboxed environment, back up the service/data you need from there, kill the virtual lab, build your new dc and restore the service/data you just backed up.
  • Thanks 2
Posted
This is one reason I keep roles separate. An AD server is purely for AD, DNS, and DHCP. We once had one DC compromised, other 2 were fine so could just kill it, clear up the metadata and rebuild from the remaining servers.
  • Thanks 1
Posted

Restoring it from a backup is effectively doing the snapshot thing again.

 

Cull the problem DC. Seize the roles. Monitor and take any cleanup action and create a new DC.

 

I believe modern versions of Windows won’t have this issue with snapshots. Might be worth upgrading both DC.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...