Adding a second Domain Controller

I'm interested in adding a second dc.  I understand the benefits to this, however if DC1 is used for DNS and the future DC2 needs this be promoted.   What could I expect if DC1 needs to come down for serviceing or failure.   What precautions must I take

Your opinions are greatly appreciated
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Adding a second DC is an essential from a redundancy point of view........with only one, if it goes down, you have lost all your AD data........and will have to recreate a new AD from scratch.
With the second DC, both have copies of all AD info and if one fails or has to go down for maintenance, the other is still available.  If one DC goes down unexpectedly and you cannot recover it...... and it happens to be the DC with your FSMO roles, you will have to seize the FSMOs on the surviving DC......but that is a minor and straight forward procedure.

DC2 does not need DNS running on it to be promoted, it only needs to be able to point to other words DNS must be running on the network.  Once you have DC2 up and running, you can set up active directory integrated DNS (DNS on DC1 should be AD-integrated too) on it, again, simply for can then have your DHCP hand it out to workstations as the secondary DNS.......or assign it manually.

Assuming that you already have functional DNS on your network, there really is no downside here, only benefits.

How big is your network?......will both DCs be in the same site? same subnet?  If the answer here is no, there are a few more details to take care of, but you still don't need any extraordinary precautions.
You don't say which OS you're using, but when you mention "promoting" I guess you're talking about NT4?

If NT4, then the extra DC should have DNS installed as well. Set up the zone as Secondary, pulling from the first DC. In the event of failure, this zone could be changed to a Primary if you need to update it, otherwise leave it as a read-only Secondary.

If you have AD, then it's easy. Install the zone as AD-integrated and install DNS server on the new DC. Sorted!
Careful about assumptions.  In W2K lingo, promoting can mean simply taking a W2K member server and "promoting", running to a DC.

And since we are talking about adding a *second* DC, we are obviously talking about AD.......but thanks for reinforcing my advice.
OWASP: Threats Fundamentals

Learn the top ten threats that are present in modern web-application development and how to protect your business from them.

Hi rschwab,

You'll have to have both DC1 and DC2 carries same services such as DNS/WINS/DHCP/GC replcation.
As for DNS once you do "dcpromo" your DC2's DNS will automatically configure and syncrinzed with DC1's DNS.  If you do carry wins make sure you do push/pull settings.
as for you DHCP is you have then on DC1 you will want to create on on DC2 and make sure these two exclude each others scope so you don't have a overlaps.  The last and most important on is do a replcation of Global Categories(GC).

many Typos "as for your DHCP if you have them on DC1 you will want to create one on DC2"

Lots of extraneous advice here.

Wins is not necesarry on a AD forest.....though it can help if you still have win9x machines on your net....but having it set up on both DCs is a waste of bandwidth, Wins replication is a killer.   If you do need it on DC1, don't install it on DC2 until you need it.....  ie when DC1 goes down.....unless you are putting both DCs in different sites.

If you are in a single subnet, you don't want DHCP running two scopes on two different machines.  By all means, install DHCP on DC2 and duplicate your DC1 scope there.........but don't activate the scope and disable the DHCP service on DC2 until it may be needed.
"Last and  most important"  You only need one GC per site.......and they replicate automatically with the rest of AD.

To rewind a bit, I take your first point. The question was not too clear, so I tried to cover both options. Assumtions are dangerous animals...

I would however disagree that "we are obviously talking about AD." In NT4, if your first DC is your PDC, your second DC is your first BDC etc. Primary or Backup, they're all still DCs :-)

PS You may only need one GC per site, but the question revolves around that one machine being unavailable.
You said it NT4, the first controller is the PDC, all subsequent ones are called BDCs  In W2K, all controllers are simply DCs.

Re: GCs.......if you have 2 DCs in a site and one goes down, the other still carries a full replica of AD...making it the new GC is as simple as checking a box.
rschwab.......we are managing to get a bit sidetracked here.......more importantly, does any of this answer your question.......or would you like more specifics on any aspect of it?

"extraneous" info it all depends on rschwab's network.  1st of all you do not know if he is running under mix or native mode and how he's network is setup.
"GC" is only checking a box right but with it check he will not have to worry about the other went down in the middle of night or whe the admin is not around.  It is all about work smart.

rschwabAuthor Commented:
Wow !!!  just got back and started viewing these inputs

JConchi thanks for your explanation I see my question wasn't very clear.  I do understand that DC2 needs to point to DC1's DNS.  I was curious to what occurs when DC1 goes down for service or failure?

Roly_Dee pointed in the first response where it is I was going. but does this pertain to 2000 as well????

This is a small network 15 users, 22 nodes.  No DHCP,wins

Thank you  for your assistance
With no Wins or DHCP, this really is quite straight forward.

If starting from a NT4 server, upgrade to W2k first,  make sure it can connect to DC1 , then run DCPromo.  Set up DNS as active directory-integrated on both boxes.  DC1, as the first DC in the domain is automatically a GC server.  If you lose DC1 and are unable to recover it, you just seize the FSMO roles on DC2 and designate it as the new GC.  Nothing very complex and no real pitfalls to avoid. If you need more detail about seizing FSMOs, see  "Flexible Single Master Operation Transfer and Seizure Process" at:

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Networking

From novice to tech pro — start learning today.