Jump to content

Recommended Posts

Posted

I have 2016 DC doing my DNS DHCP 

I have an ancient 2012r2 DC DNS which is still going strong but needs to come out for obvious reasons

 

I have spun up a new 2019 VM on hyper v and want to make it into another DC so that I can remove the 2012r2 one

 

IPv6 isn't enabled on any DC but they have both been doing a stellar job for 8+ years with no issues

 

(I inherited this network a few years ago and only now am I able to do anything with it)

 

However will I have any issues if I don't tick the IPV6 box?

 

I kind of don't want to cos it's all been working fine without?

 

It's only when I was researching that I found out that IPv6 should be enabled on DCs other wise it can cause all sorts if issues when you try to add another??

 

Any advice greatly received!

 

 

 

 

 

Posted

Enable it on both, best just to follow that guidance. I don’t use IPv6 on anything else but it’s enabled on my DCs, all on 2022 now.

Posted

Windows server uses ipv6 for a lot internally, don’t disable it just adjust the settings to prefer ipv4

Posted

Thanks for the replies. It's already unchecked on the 2 DC's that are running and it has been since they were setup some 8 years ago? That's what's confusing me. 

 

Everything I read says don't disable ipv6 on DC's but it always has been disabled as far as I'm aware and it hasn't caused any obvious issues.

 

In fact I've noticed both schools I work at have the same setup with 2 virtual 2016 DC's that have ipv6 disabled? 

 

I didn't set any of these up, this is my first time adding an addition DC, and it's only because of the physical age of the existing setup. 

 

 

Posted

It was disabled on our DCs when I took them on, back when we were running 2003. As MS guidance changed, I turned it on. Is it there as a legacy setting, or because the tech who set it up was also on legacy settings (seen that enough times - “oh we don’t run updates on the servers, for reliability”

Posted

I believe that when Server 2008 came along IPv6 was a mandatory component and if you had it unticked/turned off then you were running "an unsupported configuration" as "Doing so can lead to seemingly random service failures, authentication problems, and erratic network behavior" as a lot of background services use it for communication.

  • 2 weeks later...
Posted

So IPv6 has been unticked on our existing DCs since they were installed some 12 and 8 years ago. It is unticked across the network and all computers (running windows 11) are operating fine. Also Smoothwall (which we use) only uses IPv4. I have a 2016 DC and a 2012r2 DC (Yes I know! that's why I'm doing this!)

 

I want add a 2019 DC as it will be covered for updates for a few more years. (2016 updates end Jan 27) and when its up and happy, I want to retire the 2012r2 DC (Obviously! 😬)

 

My point is if everything is ticking along nicely now and i don't have any issues, why would i need to tick the IPv6 box in my "new" 2019 dc? (When i set it up)

 

 

Posted

From memory, stuff works without it but I found DC operations markedly quicker with IPv6 active. You don't need it active on clients, Smoothwall, firewall etc. You're also going to 'recommended' settings rather than 'it works so I leave it' settings.

 

Try it.

Posted

One thing I hadn't thought to consider is that IPv6 is set as higher preference on most devices.  If you have no IPv6 DHCP set a bad actor could potentially spin one up and cause mischief. I've not looked into the ins and outs of this, only heard it as part of a larger webinar yesterday, but it did make me stop and think.

  • 3 weeks later...
Posted

a bit like others, i do now have ipv6 on all my DCs... 3x and it has been enabled since they were at least 2016DCs... my domain started its day in NT4... and been through 2000,2003,2008,2012 etc... and in the beginning ipv6 was either not there or i un-ticked it (turned it off) when i commissioned a new DC then at some point in the past sometime around 2012 -> 2016 i actively turned them all back on because it was recommended and now they are all 2022 with ipV6 on.  nothing ever seemed broken before i turned it on or broke since... i guess because i probably turned it on a while ago I'm not sure what a mix of newer DCs would play like if it was off on some or all...

Posted

I have ipv6 set up on all my servers but no DHCP scope.  I use DHCP snooping so dont really mind what the clients are doing.  We still have an public IPv4 for our external web internet services so I have had no reason to transition, although I do have a plan to enable ipv6 for public facing services should I need to.

Posted (edited)

To be honest I would not go by the fact it has not caused issues before and would follow best practice mostly. It will only take a feature implementation in MS to have a scratching head 🙂

 

@TechMonkey DHCP snooping should block accidental or mulicious issues with DHCP, we've had routers plugged in serving IP addresses that someone thought would be a good idea to use our org DHCP range in that area. Took about 2 weeks of intermittent issues before we found it and was close to filing it in the waste bin via the nearest window. The other thing we had was AV devices that if they did not get an IP from a DHCP server they became a DHCP server but easy to spot as they used a common 192.168 subnet which we do not use internally. DHCP snooping is enabled on all edge switches that support it for the last 3-4 years here.

Edited by Davit2005
Posted

I've just checked our two DC's, both Server2022. It's not only not enabled, but the protocol seems to not be installed on the network adapter?

 

 

image.png.e42ba8670213cdb092cb927e2ff43fef.png

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...