Solved

Failover for Window 2000 active directory service ?

Posted on 2002-05-28
9
468 Views
Last Modified: 2010-04-13
Is there any way to build a failover server for Window 2000 server that with active directory service installed ? Once the primary Active Directory Server down, the FailOver server will be running up.



0
Comment
Question by:joehuang
  • 5
  • 2
  • 2
9 Comments
 
LVL 4

Expert Comment

by:Nevaar
ID: 7040276
How about a second W2K domain controller in the same domain?

They should both register their resources in DNS, so any workstations should have access (via DNS) to the names and locations of both domnain controllers/AD servers.
0
 

Author Comment

by:joehuang
ID: 7040486
We do have a second W@K ADS Domain controller here, but the problem is that administrator has to configure RID/PDC/Insfratructure thru Active Directory Users and Computers, and something else that I read from TechNet.
I have done a test that I shutdown the Primary Domain Controller, no user can login to the network even the 2nd DC online. in order for user to logon to network, the RID/PDC/Infrastructure need to be modified on BDC befor PDC shutdown. This is a lot of different than NT4 that BDC still authenticate the net logon, even PDC offline.
It does not make any sense why Microsoft creat a such drawback in Win2k ADS. Please correct me, if my concept is wrong.

This is a reason that I am looking a tool to build a Failover server for OS/Domain Controller failure. I hae found a solution from http://www.marathontechnologies.com , but We do not need such big system.

Does Microsoft Clustering Serveice handle OS Failove for Domain Controler ? or It only handle the application failover ?
0
 
LVL 4

Expert Comment

by:Nevaar
ID: 7040535
The lack of RID, PDC & Infrastructure roles will not keep a user from being able to logon to a domain.

However, the lack of a DHCP and/or DNS server would.  Is you primary server the only DHCP and DNS server that you have set up?
0
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

 
LVL 4

Expert Comment

by:Nevaar
ID: 7040537
Oops, I almost forgot.  A missing Global Catalog server would cause you problems too.
0
 
LVL 6

Expert Comment

by:st_steve
ID: 7040876
If you need to shut down the PDC often, BEFORE you shut it down, "transfer" the PDC Emulator role (from Active Directory Users and Computers) to the second domain controller. Transfer the role back to original PDC when it's up again.

You should only seize the roles if you know for SURE that the old machine will NEVER be online again. Many recommend if you SEIZE a role, you format the hard drive of the machine which held the role originally.

As Nevaar alreasdy mentioned, you also need DNS for AD to function and for clients to locate the nearest PDC.

On another note, if you need to shut down a machine often, that computer shouldn't be running any of the FSMO roles.

You need to be at least Domain Admin to modify these rights. You wouldn't want anyone to modify what server holds what FSMO roles, would you??
0
 
LVL 6

Expert Comment

by:st_steve
ID: 7040878
Under Windows 2000, every DC is the same except:

PDC Emulator:
Controls user authentication
Time synchronisation within the domain (required for Kerberos)

Infrastructure Master:
Manages group membership changes (doesn't function if the machine is also a Global Catalog Server), being a GC, Infrastructure Master can't tell whether group memeberships have changed.

Relative ID Master:
Manages new accounts creations, GUID = DomainID + RelativeID

Schema Master:
Controls Modifications to Schema, the backbone of AD

Domain Naming Master:
Controls adding and removing of Domain names

Schema and Domain Naming are "forest-wide" roles (only one in each forest), the rest are "domain-wide" roles (one in each domain).
0
 
LVL 4

Expert Comment

by:Nevaar
ID: 7041374
What type of clients are you running (W98, NT 2K, XP)?  Are they running NetBios int addition to TCP?
0
 

Author Comment

by:joehuang
ID: 7042494
There is only one DHCP service on Primary DC, DNS service on each of  Primary DC and Second PC. w98/NT/2K/XP are the client running NetBios/TCP. This is a good reminder plus GC, once Primary DC down, DHCP Clients can not lease the iP address from any DC, because there is only one DHCP server.  

So, if the Primary DC dead suddenly, there is no chance to modify the role with PDC on line, how to make second DC become Primary DC ?


 
0
 
LVL 4

Accepted Solution

by:
Nevaar earned 50 total points
ID: 7042767
In terms of Active Directory from the client perspective, there is no such thing as a primary or secondary DC. This is not an old style NT domain.

You should set up a DHCP server (with a smaller scope) on the second DC.  Also make sure that you have both DNS servers listed in the DNS server option on your DHCP server scopes.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
auto copy 8 616
Windows 2003 server: List of EVENT IDs 1 726
Windows 2000, Ghost 2003, disk1 disk 2 mirroring 17 357
Windows  Active Directory  Quesiton 8 129
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Google always has something new and amazing up its sleeve, and the most current thing that they have been working on is another step in the evolution of Google Search, from machine learning to its brilliant successor, deep learning.
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

832 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question