?
Solved

dns scenario

Posted on 2004-09-30
3
Medium Priority
?
410 Views
Last Modified: 2012-06-21
I am looking for the proper config of active directory and dns in my local w2k domain. I currently have 2 DC'c in a domain and the primary running dns alone. I am worried about it failing and trying to implement redundancy amongst them. I want to add a second dns to act as a secondary/ backup and assume it should be setup on my second DC. My questions are as follows. But confused on the diffensce between a secondary dns and a backup or are they the same.

Q1 If the primary DC goes down I want a secondary dns to kick in. how do I do this?
 
Q2 In DHCP, should I give it both IP addresses of the above 2 DNS server so if the primary fails, the secondary kicks in. Right now when i shutdown my Priimary DC, I instantly get a notice in my workstation event viewer " can not locate dns".Does the secondary dns mean it will  point to my backup dns in case of faulure? or is this done automatically without adding that second dns address on my workstations IP config

Q3 In my second DC , dns was turned off and upon turning it on, I see the zones from my primary DNS. does this mean it set itself up to backup. Since I am not sure how the zones got there, I want to delete them to start over, do you see any danger in deleting the zones of my second DC and recreating the zones all over again as secondarys.
0
Comment
Question by:vstav
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 5

Assisted Solution

by:zerofield
zerofield earned 400 total points
ID: 12190829
You have the right idea, just relax :)  Setup the DNS to run on the second DC as well (in fact, i generally run DNS on all DC's given the AD is so heavily dependent upon it.

Yes again, setup your DHCP to assign both of the DC's ip's as DNS servers.

There is a 2 second timeout by default, so should the first DNS server die or become unusable, the clients will timeout to it and query the second DNS server.

And, yes, again, you were right about it auto-configuring itself.  When you have DNS servers on the DC's in an AD, when they replicate, they will automatically update one another on any host changes.

If your clients do not have the second DNS server listed, and the primary dies, there is no automatic failing over.  DNS resolve will be broken at that point.

So, go ahead and let the second DC/DNS server auto-populate itself.  Change the DHCP to assign the second DNS server.  Life will be good.

If you want to take it a step further, I use a cache'in linux server running bind which all internal AD boxes forward external requests to.  This way the linux machine sits on the frontlines while the AD hides behind the firewall.

Let us know!
0
 

Author Comment

by:vstav
ID: 12193580
is this  same scenario applicaple for the DC also meaning if the primary DC fails all toghether(crashes), will the second DC take over and keep all object in the AD active?  I not refering only to DNS, I mean everything in AD and the domain. Or do I have to, after it crashes, hand over rights? I similuted shuting down the primary DC and noticed when loged in from my other DC that when I tried to go browse computers in (entire directory), it came up with a meassge saying the master was not available.


0
 
LVL 12

Accepted Solution

by:
Mazaraat earned 200 total points
ID: 12195694
IF the main DC fails, depending on how long it will be down, you may have to transfer some of the schema roles to the secondary server.

How to sieze roles:
http://support.microsoft.com/default.aspx?scid=kb;en-us;255504
How to sieze the RID master role:
http://www.microsoft.com/windows2000/techinfo/reskit/en-us/default.asp?url=/windows2000/techinfo/reskit/en-us/distrib/dsbl_fsm_cfyf.asp

Roles will need to be seized for all 5 roles if they were on the failed server:
Schema owner
Domain role owner
PDC role
RID pool manager
Infrastructure owner

If the primary server will be up in a reletively short time you may decide to not seize the roles.
0

Featured Post

Get MongoDB database support online, now!

At Percona’s web store you can order your MongoDB database support needs in minutes. No hassles, no fuss, just pick and click. Pay online with a credit card. Handle your MongoDB database support now!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Suggested Courses

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question