Jump to content

Recommended Posts

Posted

I am having a great morning. I came in and the sun was shining. I walked into the department and one of my main domain controllers is dead as a post and I dont have spare parts to use but at least its under warranty. Stone are coming out tomorrow as its under warranty and log on times are now 35 mins for the fastest machines. Lovely.

 

I have explained to staff that the network is broken and not usable today and I have had 3 teachers come in and ask to book computer rooms today. I have come to the conclusion staff just do not listen.

 

I have wandered round and lots of staff are trying to log on and complaining at me its not logging on even though they have been told.

 

Sometimes it makes me wonder why I bother telling them things they just dont listen.

 

Richard

Posted
I am having a great morning. I came in and the sun was shining. I walked into the department and one of my main domain controllers is dead as a post and I dont have spare parts to use but at least its under warranty. Stone are coming out tomorrow as its under warranty and log on times are now 35 mins for the fastest machines. Lovely.

 

I have explained to staff that the network is broken and not usable today and I have had 3 teachers come in and ask to book computer rooms today. I have come to the conclusion staff just do not listen.

 

I have wandered round and lots of staff are trying to log on and complaining at me its not logging on even though they have been told.

 

Sometimes it makes me wonder why I bother telling them things they just dont listen.

 

Richard

 

:( Poor you.

 

Time to hit the hobnobs, I think. Hope it's sorted quickly tomorrow.

Posted
hobnobs + tea + locking yourself away whilst you fix things + unhooking phone = ideal

 

What he said, and also fix a HUGE notice on your door saying that there are problems, that you HAVE told them and that all will be fixed ASAP. Might stop them knocking! (I did say 'might')

  • Thanks 1
Posted

@ricki:

 

Eh! whats that you say young PFY?

Speak up I can't hear you!!

Did you say anything worth while? Hurry up and spit it out man as I "need" to get the computer rooms booked before anyone else.

 

This is how their thinking works \ / tunnel vision with "me! me! me!" at the end of the tunnel!. Me

  • Thanks 1
Posted

In this situation a few years ago I disabled other key services that I knew would be responding less than satisfactorily, so that at least they got an immediate indication that it was screwed instead of wasting 20 minutes finding out.

 

This is also a good opportunity to have redundant systems budgeted for, now that SMT can see just what an effect a single failure can have. Two domain controllers in disparate locations can work wonders and would only cost them a couple or few hundred to achieve.

Posted

Losing one DC shouldn't have that sort of effect on logon times - what's the remaining DC doing apart from authentication? Can you turn off other services on that DC to make the logon process faster (or is the actual "logon" bit quick but other "stuff" happens afterwards? if so, can that be removed temporarily?)

 

Were the FSMO roles on the DC which has failed? If so, transfer them to your remaining DC (you'll have to force the transfer but that's fine and won't cause problems later)

 

Is the remaining DC a global catalog? If not, make it a GC.

Posted

Hi

 

It does when scriipts and services run on that server. I am in the process of unlinking group policies that run them. I have got log ons down to 20 mins lols.

 

This domain controller does not have the roles but it does have most of the shares that contains software and scripts.

 

Richard

Posted (edited)

Were the FSMO roles on the DC which has failed? If so, transfer them to your remaining DC (you'll have to force the transfer but that's fine and won't cause problems later)

 

some fsmo roles do as when you plug dead server back in (assuming its fixable) you will have 2 pcs thinking they are the master

Edited by sted
Posted
Two domain controllers in disparate locations can work wonders and would only cost them a couple or few hundred to achieve.

 

I agree.

Posted

and in addition to the two domain controllers...set up something that'll email/text you at $time_you_normally_get_up +5 minutes and let you know if everything's ok or if you should nip in earlier to fix stuff before anyone notices. You should assume no email = come in early.

 

If you're not omnipotent, decent monitoring is a good way of faking it. :)

Posted
some fsmo roles do as when you plug dead server back in (assuming its fixable) you will have 2 pcs thinking they are the master

 

OK; so I didn't include the bit saying "don't forget to transfer the roles back" - I kind of assumed that the OP would realise that needed doing!

Posted

 

Sometimes it makes me wonder why I bother telling them things they just dont listen.

 

Richard

 

So it is written in the Teachers handbook...

 

As with cyclists having an inability to see Red lights, all Teachers will be blessed with inability to here the word NO..

 

I actually think that they are informed during the PGCE's that once you become a Qualified Teacher that word no longer holds any meaning for them. It happened to my now Ex girlfriend..

lol

Posted

Only good news is that this is your chance to turn to management and say "this is why I need more budget, this is what happens when things fail, this is why you need to give me the assistance and funding I need to set up virtualisation/DR site/proper backups/etc."

 

They never listen until after it's failed, so make sure when they come to you in a couple of days asking why 'the network broke' you've got some answers and solutions to stop it happening next time. ;)

 

Chris

Posted
Only good news is that this is your chance to turn to management and say "this is why I need more budget, this is what happens when things fail, this is why you need to give me the assistance and funding I need to set up virtualisation/DR site/proper backups/etc."

 

They never listen until after it's failed, so make sure when they come to you in a couple of days asking why 'the network broke' you've got some answers and solutions to stop it happening next time. ;)

 

Chris

 

Very true. Last summer's disk failure on my one and only server was when I finally got the go ahead to plan for a second server (but can't get it until this summer :rolleyes:)

Posted (edited)

Were the FSMO roles on the DC which has failed? If so, transfer them to your remaining DC (you'll have to force the transfer but that's fine and won't cause problems later)

 

Is the remaining DC a global catalog? If not, make it a GC.

 

I know you've already had a but of stick for this ;) but I've been studying for my MS Certs of late and this has come up in the study material -

 

[grabs book to refresh memory]

 

The RID Master, Schema Master and Domain Naming FSMO's CAN NOT be transfered back if you force transfer them to another DC. Very important (as in can screw up AD big time) DO NOT reactivate a server if you have force transfered any of these roles away from it.

 

If you have force transfered these roles then you will have to rebuild the DC from scratch.

 

Also, I'm not 100% if you can make (or should) make another server a GC if the original GC is off line and/or there are no other active GC's on the network. Does it not have to copy the data from them? Can this cause replication problems if a new GC is created and creates a new version of this data?

 

 

EDIT: just to be clear this is an issue with force transfering or siezing FSMO roles. If you cleanly transfer the roles without seizing them then you don't have this problem and AFAIK you can transfer the roles back. Of course the existing server with these roles needs to be up for you to cleanly transfer the roles.

Edited by tmcd35
  • Thanks 1
Posted

He's right! Only transfer those rolls if that DC is totally completeley and utterly dead and will be thrown in the bin. If on theother hand that DC is gonna be repaired and will come back up at some stage in the near future then you will end up in trouble!

 

Butuz

Posted
Do you not run some scripts from you netlogon/sysvol share? That way they replicate between DCs and you can refer to them in group policy as \\domain\netlogon\script.vbs. Which will be flexible for any DC.
Posted

HI

 

Its not get any of the FSO roles they are on the primary domain controller. I have got log on times to about 10 mins on older machines. That's not good but usable. Am waiting for the engineer praying he can come today. I am hoping its just the powerpack.

 

Pray Pray Pray

 

Any more ideas would be gratefully received.

 

Richard

Posted
surely if the server is not functioning correctly then stone should come out right away? Have you looked at your agreement contract?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...