DDR5 Posted May 20, 2024 Posted May 20, 2024 Hi everyone. Just about to embark on my first server build as have taken over from an MSP. Server is around 7 years old and deffo needs replacing. The current setup is: tower server running Server 2016 as a Host with 4 VMs (also 2016). 2 VMs are domain controllers. One DC is the file server so all shares point to this, along with DHCP/DNS etc and the other DC has SIMS/FMS on. I’ll be looking into migrating rather than starting afresh, so guessing easiest way is to join new Host to domain, along with the VMs and transfer roles before demoting existing DCs. How do you guys go about installing SOLUS/SIMS etc - do you get the MIS guys in, or is it easy enough to do? Home folder paths and shares all point to existing DC - easy enough to change to new DC name or would it be easier to rename the new DC as per the old one once shut off? Any advice will be extremely well received
3s-gtech Posted May 20, 2024 Posted May 20, 2024 Do you need to build them all fresh? You can move them in Hyper-V from old host to new then in-place upgrade. It's not new and fresh, but it is a practical solution and takes quite a bit less time! 1
Davit2005 Posted May 20, 2024 Posted May 20, 2024 Not sure about the issues might have if the HyperV host is also joined to the domain and both DCs are on that host and those DCs have a problem. The risk is slightly less I guess if you have 2 DCs but you have all your eggs in one basket. Changing home drives could be as simple as updating the users AD object to point to the new server share i.e. \\filesever\%username% after the share and files have been moved over. If you do it after the files have been moved over it should set the right permissions for that user to their own files from my experience. Have you thought about separating the users shares out to a separate VM rather than have them on a DC? 1
DDR5 Posted May 20, 2024 Author Posted May 20, 2024 Do you need to build them all fresh? You can move them in Hyper-V from old host to new then in-place upgrade. It's not new and fresh, but it is a practical solution and takes quite a bit less time! Isn't there a risk with in place and DC's?
DDR5 Posted May 20, 2024 Author Posted May 20, 2024 Not sure about the issues might have if the HyperV host is also joined to the domain and both DCs are on that host and those DCs have a problem. The risk is slightly less I guess if you have 2 DCs but you have all your eggs in one basket. Changing home drives could be as simple as updating the users AD object to point to the new server share i.e. \\filesever\%username% after the share and files have been moved over. If you do it after the files have been moved over it should set the right permissions for that user to their own files from my experience. Have you thought about separating the users shares out to a separate VM rather than have them on a DC? I would much prefer that solution, yes. Have a dedicated file server VM, so the DC's are just DC's. With it being the first server build, I just want to get it right.
3s-gtech Posted May 20, 2024 Posted May 20, 2024 Isn't there a risk with in place and DC's? No. The DC role upgrades fine. I think that advice goes back to Server 2003-2008 days. If you've tagged loads of additional services onto the DC you may get issues, but I never have.
Aprice Posted May 20, 2024 Posted May 20, 2024 I'd strongly suggest you don't join the Hyper-V host to the domain, if it can be avoided. With clusters we always use a separate domain just for the cluster, last thing you want is a problem with your primary domain causing issues with the Hyper-V host. 1
Jawloms Posted May 20, 2024 Posted May 20, 2024 I'd strongly suggest you don't join the Hyper-V host to the domain, if it can be avoided. ^^^^ This! If a cyber attack gets in to your domain, your undomained hosts have one more level of protection. Obviously not infallible, but everything helps. 1
DDR5 Posted May 20, 2024 Author Posted May 20, 2024 ^^^^ This! If a cyber attack gets in to your domain, your undomained hosts have one more level of protection. Obviously not infallible, but everything helps. Interesting! All the schools I've worked in have had the HOST joined to the domain. I'll certainly look into it.
djm968 Posted May 20, 2024 Posted May 20, 2024 It might be a good opportunity to look into cloud options? You will probably still need a server, but I would be looking at moving data storage and other services to a cloud platform.
jthompson Posted May 20, 2024 Posted May 20, 2024 If you do have the hosts on the same domain and your DCs are all virtual servers, you'll want at least one of those DCs on a host that's either on a different domain or on no domain.
FragglePete Posted May 20, 2024 Posted May 20, 2024 That's interesting thoughts as the following indicates: https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/best-practices-analyzer/domain-membership-is-recommended-for-servers-running-hyper-v So, are you recommending having a separate domain that your hosts are a member of? Where would your DCs for this domain being located - because you need two DCs don't you for redundancy? Physical or Virtual, but where ? Honestly, I'm intrigued. Always (and have) ran our Hosts as Domain joined after a lengthy discussion many years ago with a paid in engineer setting things up. Always thought having them as independent 'workgroup' standalone servers. Pete
TwistedHelixis Posted May 20, 2024 Posted May 20, 2024 We don't join hosts to domain. We only have one DC on a host. No point having more, you might as well just take good backups and restore if needed. In fact restoring a single DC is simpler than restoring one when there are more. If you do want more than one DC, stick it on the old server so its separate from the main DC. SIMS migration is doable, I have done a few over the years, but expect some pain. It never goes to plan.
TwistedHelixis Posted May 20, 2024 Posted May 20, 2024 Also, I always use new names and new IPs on my new servers and migrate stuff over to the new server. As I go I update any shares or map addresses.
DDR5 Posted May 20, 2024 Author Posted May 20, 2024 Thanks all for the replies. With regards to the DC, I think the reason there are two was for replication and redundancy should one go belly up.
TwistedHelixis Posted May 20, 2024 Posted May 20, 2024 With regards to the DC, I think the reason there are two was for replication and redundancy should one go belly up. Yep that might help, but when I worked for the LA, we had over 250 primary schools and they all only had one DC. We had a few of those go belly up and it was very simple to just restore the entire DC VM from backup. Probably took about 30 minutes and they were back up and running. There are no worries about server replication issues after restoring as there are no other servers to replicate with:-) Obviously if you are a larger school then you will need more than one DC, but for me the above works very well.
KK20 Posted May 23, 2024 Posted May 23, 2024 (edited) if you have VMs, spool up a quick server, promote it, demote the other DC, upgrade the other DC, promote other DC, demote new VM and remove new VM. I would say pointless having two VM DCs, there is some worth to a physical and VM DC. Make sure you have very good backups before you start anything. 4xVMs and 1xtower means you can buy a cheap refurb server from the likes of ETB and run community VEEAM on it for 10 workloads. Then if you screw up you can be up and running again quickly. Anyway, if you already have VMs then you can also backup your existing setup, shut it down and leave it as cold store, bare metal restore to new server (this tests your restores nicely!), then look at inplace upgrading. Edited May 23, 2024 by KK20
MrKJLS Posted May 25, 2024 Posted May 25, 2024 When we used to do Traded Services for IT in primary's, we used to get them to replace the server (as the schools we looked after normally had really old kit) with either new or refurb. Then just spin up new servers on the new server and migrate the services over. When it came to AD we used to re-do all the group policy's outside the schools current AD structure them when we came in we would just move all the users and groups into the new structure. Then transfer the roles during the migration period in the holidays. The worst part was migrating SIMS lol
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now