ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Secondary Domain Controller Setup

    IT Discussion
    windows active directory domain controller
    10
    38
    8.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • dafyreD
      dafyre
      last edited by

      Generally, no. But if anything goes sideways, it's always better safe than sorry, lol.

      1 Reply Last reply Reply Quote 0
      • DashrenderD
        Dashrender
        last edited by

        Do you need backups? sounds like it's not critical, but hopefully you are backing up at least one of your DCs.

        DNS isn't required, or mandated by the promotion (unless that was changed in 2012 R2) but I'd highly recommend it (might even be considered best practices) and should be offered to be installed during promotion if you don't already have it installed.

        The rest of the guys are right, it really is that simple... you don't need to do anything to setup replication. The system takes care of that during AD promotion.

        bbiAngieB scottalanmillerS J 3 Replies Last reply Reply Quote 1
        • scottalanmillerS
          scottalanmiller @bbiAngie
          last edited by

          @bbiAngie said:

          Question I think the answer is yes but want to verify: Should I have DNS installed on the secondary DC as well?

          Yes, if you are using your DCs as your DNS servers (which is by far the most common option) then you will want redundant DNS just like you want redundant AD. Without the redundant DNS, the secondary DC will not be useful as DNS will be down when it is needed.

          1 Reply Last reply Reply Quote 1
          • bbiAngieB
            bbiAngie @Dashrender
            last edited by

            @Dashrender Both my current DC's are getting backed up nightly. Only reason I question is because if there is any chance this will bring down the "primary" DC, I need to wait to do it.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @Dashrender
              last edited by

              @Dashrender said:

              Do you need backups?

              You already have these, I hope! Is your DC currently not part of a daily backup process?

              DashrenderD 1 Reply Last reply Reply Quote 0
              • bbiAngieB
                bbiAngie
                last edited by bbiAngie

                Based on what you all say, all I really need to do is promote it to a DC, then point it back to my current "primary," let it do its thing then I should be done. (besides re-pointing DNS)

                coliverC DashrenderD 2 Replies Last reply Reply Quote 0
                • J
                  Jason Banned @dafyre
                  last edited by Jason

                  @dafyre said:

                  I would definitely check and make sure that DNS was installed on your second DC. Have you actually gone through the process to promote it from being a member server yet?

                  That will install with AD DS

                  1 Reply Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @scottalanmiller
                    last edited by

                    @scottalanmiller said:

                    @Dashrender said:

                    Do you need backups?

                    You already have these, I hope! Is your DC currently not part of a daily backup process?

                    lol that was really rhetorical 😉

                    1 Reply Last reply Reply Quote 0
                    • coliverC
                      coliver @bbiAngie
                      last edited by

                      @bbiAngie said:

                      Based on what you all say, all I really need to do is promote it to a DC, then point it back to my current "primary," let it do its thing then I should be done. (besides re-pointing DNS)

                      You don't even need to do that. Promoting it will do all of this for you.

                      1 Reply Last reply Reply Quote 0
                      • J
                        Jason Banned @Dashrender
                        last edited by Jason

                        @Dashrender said:

                        DNS isn't required, or mandated by the promotion (unless that was changed in 2012 R2) but I'd highly recommend it (might even be considered best practices) and should be offered to be installed during promotion if you don't already have it installed.

                        DHCP isn't required. DNS very much is a required part of a DC (but doesn't have to be on the same server)

                        1 Reply Last reply Reply Quote 0
                        • bbiAngieB
                          bbiAngie
                          last edited by

                          Cool, like I said, it just seemed way to easy to be correct. Glad made sure before!

                          1 Reply Last reply Reply Quote 0
                          • bbiAngieB
                            bbiAngie
                            last edited by

                            A delegation for the DNS server cannot be created because the authoritative parent zone cannot be found or it does not run in Windows NS server. If you are integrating with an existing DNS infrastructure, you should manually create a delegation to this DNS server in the parent zone to ensure reliable name resolution from outside the domain "domain.name.". Otherwise, no action is required.

                            Translation?

                            J 1 Reply Last reply Reply Quote 1
                            • DashrenderD
                              Dashrender @bbiAngie
                              last edited by

                              @bbiAngie said:

                              Based on what you all say, all I really need to do is promote it to a DC, then point it back to my current "primary," let it do its thing then I should be done. (besides re-pointing DNS)

                              Pretty much - I've never seen a failure when promoting a DC. Before you promote the DC, make sure the primarily DNS points to one of the other DCs (which it probably already does). You don't need to change this until just before you demote the old one.

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @Dashrender
                                last edited by

                                @Dashrender said:

                                Pretty much - I've never seen a failure when promoting a DC.

                                I see it most times, normally a DNS error.

                                1 Reply Last reply Reply Quote 1
                                • J
                                  Jason Banned @bbiAngie
                                  last edited by

                                  @bbiAngie said:

                                  A delegation for the DNS server cannot be created because the authoritative parent zone cannot be found or it does not run in Windows NS server. If you are integrating with an existing DNS infrastructure, you should manually create a delegation to this DNS server in the parent zone to ensure reliable name resolution from outside the domain "domain.name.". Otherwise, no action is required.

                                  Translation?

                                  It means it couldn't created one at the root, this is expected in many cases as the .com or root dns is not yours.

                                  bbiAngieB 1 Reply Last reply Reply Quote 0
                                  • bbiAngieB
                                    bbiAngie @Jason
                                    last edited by bbiAngie

                                    @Jason Is that most likely since one already exists? Should I just click through the error and do all the dns stuff after?

                                    1 Reply Last reply Reply Quote 0
                                    • DashrenderD
                                      Dashrender
                                      last edited by

                                      Do you get that when you try to install DNS before you promote your server to AD DS?

                                      1 Reply Last reply Reply Quote 0
                                      • bbiAngieB
                                        bbiAngie
                                        last edited by

                                        I am getting it during the DNS options while doing the Promo

                                        J 1 Reply Last reply Reply Quote 0
                                        • H
                                          hubtechagain
                                          last edited by

                                          click through, I always get that one 🙂

                                          1 Reply Last reply Reply Quote 0
                                          • J
                                            Jason Banned @bbiAngie
                                            last edited by

                                            @bbiAngie said:

                                            I am getting it during the DNS options while doing the Promo

                                            Click through it it's normal in most setups as the parent zone is not something that's yours.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post