Jump to content

Recommended Posts

Posted

Hi,

 

I've been migrating our DC's to Server 2012 R2 DC's from Server 2003 ones. I've migrated DNS, DHCP and all of the FSMO roles to the new DC's. However, we've had a long-running problem that if one of the old 2003 DC's is not switched on, only about half of the machines apply group policy and get wallpaper, security settings, proxy settings etc. The others log on as normal. This is still the case now that I've migrated all roles to the new DC's. I've also found that DNS doesn't work if the same old DC is switched off, even though it is present and should be working fine on all of the DC's. I've been trying to troubleshoot this for months now and I'm still no further forward.

 

Any help would be appreciated.

Posted

Sure you have but just trying out the obvious stuff. Your clients are using the new DNS servers address?

 

Do you have software restrictions in? I had a issue where things would occasionally not be right, figured it was because I was only allowing things from the first DC and not the second DC.

  • Thanks 1
Posted

As above - are all your clients pointing to the new DNS Servers? Do you use DHCP for all your clients? It's not possible that some of them have fixed IPs or fixed DNS?

 

Have you demoted the old DCs? or just switched them off?

  • Thanks 1
Posted
Sure you have but just trying out the obvious stuff. Your clients are using the new DNS servers address?

 

Do you have software restrictions in? I had a issue where things would occasionally not be right, figured it was because I was only allowing things from the first DC and not the second DC.

 

The clients certainly have them showing in ipconfig /all, and they are appearing as the first two in the list.

 

We do have a software restriction policy, but the only ones referencing any servers don't reference domain controllers.

 

It's been like looking for a piece of hay in a massive stack full of needles.

Posted (edited)
As above - are all your clients pointing to the new DNS Servers? Do you use DHCP for all your clients? It's not possible that some of them have fixed IPs or fixed DNS?

 

Have you demoted the old DCs? or just switched them off?

 

All of the clients that I'm testing with are just classroom PC's; they are all on DHCP and aren't using fixed addresses for their IP or for DNS.

 

I didn't want to demote the old DC's until I had DNS working on the new ones. I'd authorised the new DNS servers, unauthorised the old ones and disconnected their network connection.

 

*edit* Deauthorising was what I did when I was looking at migrating DHCP. So yes, I'd simply turned the servers off by disconnecting their network connection.

Edited by theeggmaster
Posted

Sounds like DNS. Look for duplicate records with the same IP address and different host names.

 

A forceful way to make the clients to look at the new DNS would be to delete all your local A records and wait for them to re-populate.

 

A good idea also is to set up scavenging to auto delete old/unused records.

 

Check your DHCP server config for the correct DNS server addresses.

 

As @pantscat says - Have you demoted your old DC's ?

  • Thanks 1
Posted
It's definitely DNS. I'll eat my hat if it's not.

 

I agree with you, but I have all of the DNS servers in the DHCP Scope options, the clients show that they can see them as registered DNS servers. This is the first time I've had to do a DC migration, so I'm loathe to demote a DC when I know if I do, half of the clients will stop processing group policy. They used to do this before I even started looking at Server 2012 R2 when that server was off.

Posted

Well, if a DC is switched off it won't be able to process requests, BUT, it'll still be listed in DNS as an "available" DC.

 

When clients come to do group policy processing they may try to contact the switched off DC, since it's in DNS, and fail to process anything as they can't contact it because it's switched off.

This is entirely normal behaviour if you just switch a DC off. They're not meant to be turned off.

Posted
have you transferred the fismo roles off the 03 box(s) onto one/more of the servers you intend to keep. Also make sure the first dns servers clients see is the new server(s). I have found that 2012 r2 dosent seem to like having any other server as a dc it seems to eventually over time do odd things
  • Thanks 1
Posted (edited)

You don't have to demote the old DC, you can keep it running if you want.

 

You do however have to transfer the FMSO roles and demote the current DC as the schema operations master & Global catalogue server, tell it its the primary domain controller etc according to FSMO.

You cant have two masters on the same domain. That means you have to remove some of the FSMO roles on the 2003 server. You can always keep it as a secondary server.

 

Its very simple. Find a Youtube guide. That's what I did, followed step by step and it worked perfectly.

 

Do the FSMO role changes swiftly though or something will break.

 

EDIT...

 

Follow this. It looks pretty bang on.

 

http://blogs.technet.com/b/canitpro/archive/2014/04/02/step-by-step-active-directory-migration-from-windows-server-2003-to-windows-server-2012.aspx

Edited by mikkydoos
Posted
have you transferred the fismo roles off the 03 box(s) onto one/more of the servers you intend to keep. Also make sure the first dns servers clients see is the new server(s). I have found that 2012 r2 dosent seem to like having any other server as a dc it seems to eventually over time do odd things

 

Yes, all of the FSMO roles were transferred, and both of the new servers are the first two DNS servers.

Posted
You don't have to demote the old DC, you can keep it running if you want.

 

You do however have to transfer the FMSO roles and demote the current DC as the schema operations master & Global catalogue server, tell it its the primary domain controller etc according to FSMO.

You cant have two masters on the same domain. That means you have to remove some of the FSMO roles on the 2003 server. You can always keep it as a secondary server.

 

Its very simple. Find a Youtube guide. That's what I did, followed step by step and it worked perfectly.

 

Do the FSMO role changes swiftly though or something will break.

 

EDIT...

 

Follow this. It looks pretty bang on.

 

Step-By-Step: Active Directory Migration from Windows Server 2003 to Windows Server 2012 R2 - Canadian IT Professionals - Site Home - TechNet Blogs

 

netdom query fsmo gives me

 

Schema master DC02.mardenclc.org

Domain naming master DC02.mardenclc.org

PDC DC02.mardenclc.org

RID pool manager DC02.mardenclc.org

Infrastructure master DC02.mardenclc.org

 

DC02 is one of our new DC's. DC01 is the other one, and it's running DHCP.

 

I thought I'd done it correctly as I followed this slightly older guide from the same website you posted, written by the same guy

Step-By-Step: Adding a Windows Server 2012 Domain Controller to an Existing Windows Server 2003 network - Canadian IT Professionals - Site Home - TechNet Blogs

 

I'll verify the steps on the one you posted to see if it matches up.

Posted (edited)
Yes, all of the FSMO roles were transferred, and both of the new servers are the first two DNS servers.

 

But have you demoted the current DC as the operations master & Global catalogue etc? It will still be broadcasting as the main DC.

 

EDIT - Ignore that - Didnt see your netdom query above :bowl:

 

 

Hang on. I'm confused....

 

So you've got 2 new DC's ?

 

Why not have DC01 as a primary DC, DNS1, DHCP1, AD etc etc

 

Then DC02 as a secondary DC, DNS2, DHCP failover etc etc.

 

I think splitting those roles is a bad idea. I'm pretty sure your PDC has to be the primary DHCP and DNS.

Edited by mikkydoos
Posted
But have you demoted the current DC as the operations master & Global catalogue etc? It will still be broadcasting as the main DC.

 

EDIT - Ignore that - Didnt see your netdom query above :bowl:

 

 

Hang on. I'm confused....

 

So you've got 2 new DC's ?

 

Why not have DC01 as a primary DC, DNS1, DHCP1, AD etc etc

 

Then DC02 as a secondary DC, DNS2, DHCP failover etc etc.

 

I think splitting those roles is a bad idea. I'm pretty sure your PDC has to be the primary DHCP and DNS.

 

I was originally going to have all of the roles on the same server to start with, but the DHCP migration to DC02 failed as it wasn't handing out IP addresses, so I rolled it back and tried it on DC01 instead, which worked. I could try moving the roles all onto DC01.

Posted
Oooh. I'm thinking start again with the new DC's :nerd:

 

Whether I do or not, it doesn't solve the underlying problem of one of the 2003 DC's causing group policy processing issues when it's switched off, which is where the group policy central store idea came in on the last page. However, I can't find any policies that are stored just on that server. This issue existed before new DC's were introduced.

 

Don't you love inheriting networks...

Posted
Whether I do or not, it doesn't solve the underlying problem of one of the 2003 DC's causing group policy processing issues when it's switched off, which is where the group policy central store idea came in on the last page. However, I can't find any policies that are stored just on that server. This issue existed before new DC's were introduced.

 

Don't you love inheriting networks...

 

 

Yeah but when you did your dcpromo all that should have pulled through from the 2003 box. If it hasn't it mustn't have done a clean copy to the new box.

That's why I would look at starting DC01 again. When your satisfied its functional - no DCDiag errors - you could promo DC02 and set up 2nd DNS & DHCP etc.

Posted
Is the \\Domain.local\Sysvol and \\Domain.local\Netlogon present the none 2003 DC?

 

Yes, all present and with the same amount of objects inside the folders. If I copy a file to \\domain.local\Sysvol or \\domain.local\netlogon it gets copied to the sysvol and netlogon folders on each server

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...