Solved

Adding a second Domain Controller

Posted on 2003-10-29
12
1,080 Views
Last Modified: 2006-11-17
I'm interested in adding a second dc.  I understand the benefits to this, however if DC1 is used for DNS and the future DC2 needs this be promoted.   What could I expect if DC1 needs to come down for serviceing or failure.   What precautions must I take

Your opinions are greatly appreciated
0
Comment
Question by:rschwab
  • 6
  • 3
  • 2
  • +1
12 Comments
 
LVL 18

Expert Comment

by:JConchie
ID: 9643722
Adding a second DC is an essential from a redundancy point of view........with only one, if it goes down, you have lost all your AD data........and will have to recreate a new AD from scratch.
With the second DC, both have copies of all AD info and if one fails or has to go down for maintenance, the other is still available.  If one DC goes down unexpectedly and you cannot recover it...... and it happens to be the DC with your FSMO roles, you will have to seize the FSMOs on the surviving DC......but that is a minor and straight forward procedure.

DC2 does not need DNS running on it to be promoted, it only needs to be able to point to DC1....in other words DNS must be running on the network.  Once you have DC2 up and running, you can set up active directory integrated DNS (DNS on DC1 should be AD-integrated too) on it, again, simply for redundancy.........you can then have your DHCP hand it out to workstations as the secondary DNS.......or assign it manually.

Assuming that you already have functional DNS on your network, there really is no downside here, only benefits.

How big is your network?......will both DCs be in the same site? same subnet?  If the answer here is no, there are a few more details to take care of, but you still don't need any extraordinary precautions.
0
 
LVL 4

Expert Comment

by:Roly_Dee
ID: 9643736
You don't say which OS you're using, but when you mention "promoting" I guess you're talking about NT4?

If NT4, then the extra DC should have DNS installed as well. Set up the zone as Secondary, pulling from the first DC. In the event of failure, this zone could be changed to a Primary if you need to update it, otherwise leave it as a read-only Secondary.

If you have AD, then it's easy. Install the zone as AD-integrated and install DNS server on the new DC. Sorted!
0
 
LVL 18

Expert Comment

by:JConchie
ID: 9643809
Roly_Dee
Careful about assumptions.  In W2K lingo, promoting can mean simply taking a W2K member server and "promoting".........ie, running DCPromo.....it to a DC.

And since we are talking about adding a *second* DC, we are obviously talking about AD.......but thanks for reinforcing my advice.
0
 
LVL 2

Expert Comment

by:tbird008
ID: 9644283
Hi rschwab,

You'll have to have both DC1 and DC2 carries same services such as DNS/WINS/DHCP/GC replcation.
As for DNS once you do "dcpromo" your DC2's DNS will automatically configure and syncrinzed with DC1's DNS.  If you do carry wins make sure you do push/pull settings.
as for you DHCP is you have then on DC1 you will want to create on on DC2 and make sure these two exclude each others scope so you don't have a overlaps.  The last and most important on is do a replcation of Global Categories(GC).

Tbird008
0
 
LVL 2

Expert Comment

by:tbird008
ID: 9644299
many Typos "as for your DHCP if you have them on DC1 you will want to create one on DC2"

Tbird008
0
 
LVL 18

Expert Comment

by:JConchie
ID: 9644517
third008
Lots of extraneous advice here.

Wins is not necesarry on a AD forest.....though it can help if you still have win9x machines on your net....but having it set up on both DCs is a waste of bandwidth, Wins replication is a killer.   If you do need it on DC1, don't install it on DC2 until you need it.....  ie when DC1 goes down.....unless you are putting both DCs in different sites.

If you are in a single subnet, you don't want DHCP running two scopes on two different machines.  By all means, install DHCP on DC2 and duplicate your DC1 scope there.........but don't activate the scope and disable the DHCP service on DC2 until it may be needed.
"Last and  most important"  You only need one GC per site.......and they replicate automatically with the rest of AD.
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 4

Expert Comment

by:Roly_Dee
ID: 9644620
JConchie:

To rewind a bit, I take your first point. The question was not too clear, so I tried to cover both options. Assumtions are dangerous animals...

I would however disagree that "we are obviously talking about AD." In NT4, if your first DC is your PDC, your second DC is your first BDC etc. Primary or Backup, they're all still DCs :-)

PS You may only need one GC per site, but the question revolves around that one machine being unavailable.
0
 
LVL 18

Expert Comment

by:JConchie
ID: 9644690
Roly_Dee,
You said it yourself......in NT4, the first controller is the PDC, all subsequent ones are called BDCs  In W2K, all controllers are simply DCs.

Re: GCs.......if you have 2 DCs in a site and one goes down, the other still carries a full replica of AD...making it the new GC is as simple as checking a box.
0
 
LVL 18

Expert Comment

by:JConchie
ID: 9644706
rschwab.......we are managing to get a bit sidetracked here.......more importantly, does any of this answer your question.......or would you like more specifics on any aspect of it?
0
 
LVL 2

Expert Comment

by:tbird008
ID: 9645406
JConchie

"extraneous" info it all depends on rschwab's network.  1st of all you do not know if he is running under mix or native mode and how he's network is setup.
"GC" is only checking a box right but with it check he will not have to worry about the other went down in the middle of night or whe the admin is not around.  It is all about work smart.

Tbird008
0
 

Author Comment

by:rschwab
ID: 9645428
Wow !!!  just got back and started viewing these inputs

JConchi thanks for your explanation I see my question wasn't very clear.  I do understand that DC2 needs to point to DC1's DNS.  I was curious to what occurs when DC1 goes down for service or failure?

Roly_Dee pointed in the first response where it is I was going. but does this pertain to 2000 as well????

This is a small network 15 users, 22 nodes.  No DHCP,wins

Thank you  for your assistance
0
 
LVL 18

Accepted Solution

by:
JConchie earned 125 total points
ID: 9645553
With no Wins or DHCP, this really is quite straight forward.

If starting from a NT4 server, upgrade to W2k first,  make sure it can connect to DC1 , then run DCPromo.  Set up DNS as active directory-integrated on both boxes.  DC1, as the first DC in the domain is automatically a GC server.  If you lose DC1 and are unable to recover it, you just seize the FSMO roles on DC2 and designate it as the new GC.  Nothing very complex and no real pitfalls to avoid. If you need more detail about seizing FSMOs, see  "Flexible Single Master Operation Transfer and Seizure Process" at:    http://support.microsoft.com/?kbid=223787
0

Featured Post

Network it in WD Red

There's an industry-leading WD Red drive for every compatible NAS system to help fulfill your data storage needs. With drives up to 8TB, WD Red offers a wide array of solutions for customers looking to build the biggest, best-performing NAS storage solution.  

Join & Write a Comment

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Resolve DNS query failed errors for Exchange
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now