Advertisement

04.07.2008 at 09:29AM PDT, ID: 23301891
[x]
Attachment Details

Second domain in forest, domain controller not recognized by forest root

Asked by shawn703 in Active Directory, Windows 2003 Server

Tags: Microsoft, Windows, 2003, Active Directory replication

We have two domains in the same forest.  The forest root was installed with Windows 2000 R2, and the second domain was created as a second domain tree in the same forest, and was upgraded from a Windows NT domain.  After upgrading the NT domain controller to Windows 2003, I installed an additional domain controller in this domain and made it a Global Catalog.  I then transferred the 3 domain FSMO roles from the former NT domain controller to the new domain controller.  Finally, I ran dcpromo again on the former NT domain controller to remove Active Directory from it.  

I attempted to authorize a DHCP server in this domain, but it never recognized that it was authorized.  I verified in adsiedit on a forest root domain controller that the DHCP server was authorized.  While in adsiedit on the forest root, I unauthorized the DHCP server and saw the entry disappear - and then reappear when I authorized the server again.  I suspected a replication problem.  In Active Directory Sites and Service on the secondary domain, the domain controllers for the forest root domain show up as replication partners.  In Sites and Services on the forest root domain, only the forest root domain controllers and the old domain controller that I demoted showed up.  I removed the old server, but I'm left trying to figure out how to tell the forest root what server it should replicate with.  The domain controller for the secondary domain also does not show up in the ForestDnsZones application partition in DNS.  Running NTDSUtil from the forest root domain controller and looking at the objects in the secondary domain, tells me that the forest root domain controller does not know of any domain controllers existing in the secondary domain, although it does show the secondary domain as existing.  

I would suspect I would use NTDSUtil to create objects for the domain controller for the secondary domain on the forest root domain controller, but I'm not sure how to do that.  Please help if you can.


Start Free Trial
[+][-]04.07.2008 at 09:53AM PDT, ID: 21298616

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.07.2008 at 09:55AM PDT, ID: 21298633

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.07.2008 at 11:07AM PDT, ID: 21299183

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.07.2008 at 11:23AM PDT, ID: 21299362

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.07.2008 at 11:39AM PDT, ID: 21299500

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.07.2008 at 11:46AM PDT, ID: 21299547

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.07.2008 at 12:39PM PDT, ID: 21299896

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.10.2008 at 08:57AM PDT, ID: 21326219

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Active Directory, Windows 2003 Server
Tags: Microsoft, Windows, 2003, Active Directory replication
Sign Up Now!
Solution Provided By: shawn703
Participating Experts: 1
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628