Jump to content

DC wipe - how to backup the users / AD etc?


Have you ever wiped and reinstalled your DC?  

26 members have voted

  1. 1. Have you ever wiped and reinstalled your DC?

    • No way! I dont want to get sacked
    • No, but I am thinking that I may need to!
    • I am planning to do so at the moment!
    • Yes - i promoted a BC and did it this way!
    • Yes - I effectively deleted the domain and recreated it [explain pls]
    • Yes - I used a 3rd party tool [explain]
      0
    • Yes - Using a temporary DC on a virtual machine


Recommended Posts

Posted

Hi all

 

I'm sure i asked this before but I'll try again ;)

 

My DC is like death at the moment and has been ever since the IP range change. Having gone through everything with 8 fine-tooth combs, I think it would be best to wipe it and start fresh....

 

So.... The question is, what would the best way be? I dont want to go any install all the clients yet again, but at the same time, I dont want any of the current problems to reappear either :S

 

Is there a way I can backup the AD? I can keep export the current shares list from the registry so thats covered i.e. for home dir's etc.

 

Also, backing up the GP would be useful - after spending so long on it, I'd hate to lose it all :S

 

What adverse effect will it have on the Exchange server? Will it die after DC goes, even when the DC is recreated and the same domain [name] is used? I definately dont want to lose all the emails or I'd be strung up hehe The exchange server is on a physically seperate 2003 server btw ;)

 

If this is all easy enough, could I get 2003 R2 and are the client CALs for 2003 usable for 2003 R2 or would i have to buy new ones? [if the latter, then no thanks hehe]

 

Any other thoughts?

 

Nath.

Posted

If you wipe your DC then you will end up killing exchange as well. You will have to rejoin all the clients etc etc.

What you should try and do is make a temporary DC on a spare machine or even a virtual machine and get active directory replicated accross to that and all the FSMO roles as well. Once you have tested backups of the original DC I would then see if everything went ok with the new temp DC then I would wipe the original and reverse the process.

If you end up starting from scratch it's going to be a lot of work.

 

Using the same domain name etc will not work as everything works of SIDs and they will be different.

Posted
Using the same domain name etc will not work as everything works of SIDs and they will be different

 

Hmmm.... thats what I thought Chris *sighs*

 

Could I promote the Exchange box as the DC, wipe & reinstall the DC, attach to domain and promote back again?

 

Would the promotion copy the shares, and the GP, as well as the AD stuff?

 

I dont plan to remove the other partitions on the DC which contain the homedir folders, resources, teacher share, network applications, etc. so that should help recreate the links - as I can change the drive letters back to what they were after the new install I'd wager.

 

My thoughts are regarding the permissions on the folders - when the C partition is wiped, will the other partitions lose their security info? or should that info still be there when i get 2003 up and running?

 

Nath

Posted
Its easy enough to test that as well. Run something like newsid on a workstation then try and join it to the domain. You will get an error even though an account exists for it. You would have to reset the account to get tit to work.
Posted
You share information isnt in AD its stored in the registry. I think when I did this last time the files and folders kept their NTFS permissions on the other partition and just the share information had to be restored. Ofc dont quote me on that :p
Posted

I know it aint but had to ask hehe

 

Im sure your right because when i migrated from the old NT 4 Server to the new 2003 server [two different machines], I physically moved the HDD from one to the other and exported the share list from the registry and I had things like unknown acount and stuff on there security tab of the files ;)

 

Just imported the share [after giving the partition the same name] and it worked nicely

 

Now what about R2? worth it? can i use my old 2003 CALs with it or not?

 

Nath

Posted
Now what about R2? worth it? can i use my old 2003 CALs with it or not?

 

Nath

 

A bit of an interim answer for you until someone can confirm, but I'm pretty sure I read that 2003 CALs would be valid for R2

 

:)

 

Andy

Posted

I've wiped my DC's before, but as we don't run exchange it wasn't a factor.

 

The Domain rebuild was forced upon me when our two DC's decided that they were no longer DC's and didn't want to talk to each other anymore (It's a loooong story).

 

The way that we managed to recreate users was through the fact that we run Ranger.

 

We rebuilt one of the DC's from scratch and reinstalled Ranger onto it, creating a new domain. Then using Ranger Account Manager we got it to recreate all of the user accounts from the unaffected old users shares on a seperate file server.

 

1 X New Domain built with 1000 users in less than a day.

 

Only problem was that we now had to reatach the 300 workstations, this is what took the time.

Posted

I don't think there is any easy solution for this.

 

I've heard what ChrisH proposed referred to as a 'swing' installation (presumably 'cos the AD swings onto a temporary box then back to the real box). Thing is, if the problem is in AD, then this obviously won't get rid of it.

 

You could export everything with LDIFIDE (or whatever it's called), but if you've never done it before, it could still be a major job. Even assuming you exported the entire AD then imported it into a fresh domain, there's no guarantee the clients would still work (I'm guessing the secure channel would be broken). GP can be backed up with GPMC and then re-imported. There are so many possiblities it doesn't bear thinking about.

 

I guess what I'm suggesting is fix the existing DC. What's the problem with it anyway?

Posted

I kind of agree with both ChrisH and ajbritton here. If the problem lies in AD then rebuilding the DC won't fix it since you would be re-importing your problems from the backup.

 

If the problem lies with the DC configuration then use the virtual machine method. Dos_Box and I did this when we discovered a previous employee had pulled a 2000 DC from the domain without using dcpromo!

Posted
If the problem lies with the DC configuration then use the virtual machine method. Dos_Box and I did this when we discovered a previous employee had pulled a 2000 DC from the domain without using dcpromo!

 

Is that what brought about that avatar :)

Posted
I don't think there is any easy solution for this.

 

I've heard what ChrisH proposed referred to as a 'swing' installation (presumably 'cos the AD swings onto a temporary box then back to the real box). Thing is, if the problem is in AD, then this obviously won't get rid of it.

 

I know....

 

and, I know lol

 

I guess what I'm suggesting is fix the existing DC. What's the problem with it anyway?

 

yep, thats what i was after, but after a year of no luck and limited amount of holiday time left, i'm worried about giving myself more to do [i've got a room to cable PC's into cupboard's & re-setup the music room when its completed] which is why I'd love to find out if i can fix the DC without a long-winded DC wiping process thingy lol

 

Not sure where the thread is now, but last summer it was, and the basic story is after implementing the firewall/vpn system, I changed the IP ranges of the two seperate domains. The firewall still logs old IP addresses coming from the DC's, even though I've completely [AFAIK] removed the DNS server's on both ranges and started again.

 

That isn't the problem tho - its the fact that both servers have turned into slugs and have started to affect things now, in that sometimes, no one can connect to the server [which then needs to be restarted].

 

I havent seen anything legible in the Event Viewer that gives me any clue, so thus the reason for the idea of wiping the DC. The thought about not wanting to keep the domain settings, and starting again [with the GP, AD Users / Objects & Share Reg export] with a fresh version of the domain was my idea - but having to go and manually start over with all the machines again [like i did last summer at some point after the IP change] I dont relish doing the same again. Its taken most of this year to get everyone happy with the custom programs and stuff on the department pc's.

 

*sighs* what to do..... I dunno :(

 

[but if i can just manage to get a job, i will finally wont have to worry about it hehe Any jobs that dont require me moving house available? ;)]

 

Regards

Nath.

Posted

@tarquel: It sounds increasingly like AD is stuffed and the 'quickest' thing is probably to nuke it and start afresh. As has been mentioned, re-joining you client machines will be a royal PITA.

 

I cannot remember if you use Ghost or RIS but if you do, this would be a relatively quick way to rejoin your machines and they would get a spring clean the same time.

 

I can help you out with a script to reconnect your users to their homedrives, assigning permissions and ownership. You would still need to re-create your GPOs (although the GP Management Console will export these to files for you so that they can be re-imported or you can create HTML outputs that you can manually re-enter).

 

All in all it's probably going to be about a week's worth of work undisturbed!

Posted

I've wiped the domain entirely

Kept the same Domain name, but given the servers new names and wanted to start a fresh

various odd problems with old system which i hope to eliminate now

Posted

Here's a thought...

 

1 - Set up a temporary domain on another PC (physical or virtual)

2 - Use ADMT to migrate everything over to it (User Accounts, Computer Accounts, Passwords etc.)

3 - Wipe and reinstall the existing DC, create a new AD

4 - Use ADMT to migrate everything back to the original domain

 

This method should retain all user & computer accounts, passwords, permissions etc. You get a freshly installed server and a new AD. If ADMT won't handle Exchange, I've a vague feeling that Exchange has it's own migration tool. Worst case is to dump Exchange database to PST files then reimport.

 

Only hassle is that to migrate computer accounts, computers must all be switched on and have some kind of agent running. I've only use ADMT myself once, so I'm hardly even a novice. Maybe someone else could comment on how practical this solution might be.

Posted

My only problem is going to be RIS/Ghost with these damn SiS900 NICs

I'd rather start using RIS - but the Sis900 arent PXE enabled, and the rbfg disk hasnt got support for them.

 

Might try WinPE see if i can initiate RIS or Ghost from there..

Posted

@Gatt: You could always buy a load of decent NICs - 3COM perhaps. It would be quite easy to put forward a business case for extra funding given the amount of time that it would save you.

 

You could argue that it takes you one hour of faffing per machine and you probably rebuild the boxes 3 times a year giving a total of 3 man hours. Surely you are paid more than a third of a NIC for 1 hour's work!

Posted

There are two tools which are free from Bill and Co. Exmerge will do a bulk export Import on mailboxes- essentialy it moves the mail boxes as .pst files. Outlook profiles will need to be re-created but not a problem if you use OWA.

Exchange Migration Wizard - single step process from 5.5 to 2003 this tool preserves directory information (You may not want this if you are building from the ground up)

 

Don't forget there is also the Active Directory Migration Tool for moving users, groups, computers etc. Create a second trusted domain and move across rebuild and put onto the domain where everything will live. Don't forget to remove the trust or you end up with two or three logon domains 1st, temp, final, local etc.

  • 2 months later...
Posted
You said it started after a shuffle of IP address have you purged all of the caches?

 

Well... I change the IP range from one range - that was sort of governed by the LEA, to a private LAN range [10.0...].

 

The DC took the changes and i had to erase and reinstall each computer in the end hehe but it worked lol

 

The only problem is that the DC seems really sluggish ever since. I deleted and reinstalled the AD / DNS more times than I care to imagine but no success with the laggy feel to the servers - and the Hardware Firewall logs show the IP addresses still trying to do stuff... its all very confusing hehe

 

 

but moving on......

Posted

Ok... See what you think of this.

 

From what everyone has said in the previous posts, the easiest option would be to use the "swing" method and would seem to be the quickest method of seeing whether it helps things or not.

 

So this is the stage I've got to so far:

 

I have cleaned up the DC as much as possible and its pretty happy [so far].

 

I've updated the schema [for R2 when i get the product key from the lea or MS hehe] and thats all happy.

 

The server with Exchange 2003 SP2 is all happy and all MS updates have been placed on both servers.

 

The new server [that will be going to the Music room and is mentioned in a different thread - ill link it later] is currently installing 2003 SP1.

 

Could I use this new server by attaching it to the domain and setting it as the DC? If so, and once that has been done, is it just a matter of:

 

- exporting the shares [from within the registry]

- exporting the Group Policies using the GPMC tool

- removing the old DC from the domain

- erasing the C drive

- installing 2003 SP1 again

- attaching to the domain

- premoting it again

- importing the shares reg file

- importing the group policies using the GPMC

 

Have I missed anything there?

Can I do the above in a day? [as i've only got tomorrow left and I've got to configure the new server - as mentioned in the other thread]

 

Cheers

Nath

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...