?
Solved

Adding second Domain Controller to Windows 2000 domain for replication, redundancy - PART 2

Posted on 2005-03-08
12
Medium Priority
?
138 Views
Last Modified: 2010-03-18
This is in reference to the original question here (please read this first!):
http://www.experts-exchange.com/Networking/Microsoft_Network/Q_21338371.html

OK, seems to be a bit of a problem that has come up:

Since we do not have the new branch open yet, we have simulated a default gateway for the new 192.168.2.X network using our firewall to redirect traffic. I have put the new DC on the .2.X network with the simulated gateway address and such on it. With all that, it seems I am able to communicate with the old DC, but cannot browse to any other computer on our 192.168.1.X network (also, from my workstation on the 192.168.1.X network I am able to successfully browse to the new DC on the 192.168.2.X network and see it's shares, but the new DC cannot browse to my machine and see my shares). Furthermore, it seems that replication between DC's is one-way at this point - the new DC has successfully replicated info from the old DC, but the old DC seems to not be picking up any changes to AD (for example, Sites and Services) from the new DC. So the new DC seems to be able to pick up the changes from the old DC, but not the other way around.

A big example of this, as mentioned above, is in AD Sites and Services. On the new DC, I had created the new site, the new subnet, and moved the new DC server object to the new site. There is a site link between the sites, and everything seems to be setup correctly there. However, I just noticed today that the old DC reflects none of those changes in AD Sites and Services. Hence, it seems to not be pull-replicating correctly with the new DC.

Am I missing something here? Let me know if I can provide any other information.

Thanks!
0
Comment
Question by:electech98
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 3
  • +1
12 Comments
 
LVL 16

Accepted Solution

by:
samccarthy earned 2000 total points
ID: 13490778
Use the KISS method.  If the other site is not up yet, don't configure it in sites and services and don't give yourself a headache with simulated Gateways.  Backup and put the DC on the existing subnet, and leave both of them in the existing site of the first DC.  IMHO, you are overcomplicating yourself.

With both DC's on the Same subnet, pointing to the same Gateway and both pointing to DC #1 for DNS.  Life should be good all around.  Replication should work.  If you use WINs, point them appropriately.

Now, when you are ready to move it to that remote site.  Just do it!  Put the new IP address on it there and then have DNS point to itself and WINS should do that too.  All the Clients at that site should be pointing to that new DC as their DNS and WINS.  Go into Sites and Services then and put the new DC in the second site and associate the appropriate Subnet with it.

I assume you will have hardware VPN tunnels to allow the DC's to talk.

This works extremely well and is the way I rolled out the whole city.  Once you have the DC in the remote location, everything will update itself.
0
 

Author Comment

by:electech98
ID: 13491337
I should have thought to include this information when I first posted:

Even when the new DC was on the 192.168.1.X network, and the new DC server object was in the same site as the old DC, AD Sites and Services did not seem to replicate from the new DC to the old DC. I created the new site and new subnet in ADS&S on the new DC while the new DC was still on the 192.168.1.X network, but the old DC did not have that information when I opened up ADS&S on it.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 13491509
Did you give it time to replicate to the other DC when it was in the original subnet?
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:electech98
ID: 13491574
yes...more than two day's time should be more than enough time for them to replicate.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 13491887
Although much of this article will not apply to you in your scenario, it may provide something useful since you are running through a firewall..

http://www.microsoft.com/serviceproviders/columns/config_ipsec_P63623.asp
0
 

Author Comment

by:electech98
ID: 13492196
Thanks for the suggestion, though we are not actually running anything *through* the firewall...we just have 192.168.2.2 set up as another interface on the firewall in order to act as a gateway for the network for the time being. It is sort of "redirecting" traffic rather than actually having traffic pass through it.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 13492279
What kind of device are you using for your routing?  (Cisco, etc?)  So, as I understand it right now, routing is only a one way street?  Are you running any routing protocols on this device such as RIP?  or are your routes static?  Can you even ping from the new DC to your .1 subnet?
0
 
LVL 16

Expert Comment

by:samccarthy
ID: 13495151
OK, here is my suggestion..........  Take a step backwards and lets simplifiy your setup.  Both DC's in the same site and under the same subnet.  Go into DNS and remove any entries for the DC that point it anywhere but on the same subnet.  Point DNS on the new DC to the old DC.  Now, both on the same subnet, DNS is the same, DNS has no rogue entires, now look at replication and force if need be.  If it is working now, then wait until you go to the other building to change anything as I suggested above.

If it is not working, then fix it here.  Overcomplicating your setup will only overcomplicate your troubleshooting.  If your replication does not work, run DCDiag and NetDiag and find and fix the problem in this simplified environment.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 13495486
Completely agree with Sam here!  Need to take any subnetting and routing issues out of the equation!
0
 
LVL 18

Expert Comment

by:crissand
ID: 13497652
Verify the fsmo roles. The replication must work thru simulated network (I don't call it is "simulated", it's a real configuration).
0
 

Author Comment

by:electech98
ID: 13500511
OK, configured the new DC to be on the same subnet as the old DC, and deleted any DNS entries that pointed the new DC to the 192.168.2.X subnet, and it seems that everything is replicating fine now. Has to be something in how the virtual gateway on the firewall is configured. I guess I'll have to wait until we actually put the branch in to see if things replicate fine with two different subnets.

Well, thanks for your help guys.
0
 
LVL 16

Expert Comment

by:samccarthy
ID: 13502218
Glad to be of assistance
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

FIPS stands for the Federal Information Processing Standardisation and FIPS 140-2 is a collection of standards that are generically associated with hardware and software cryptography. In most cases, people can refer to this as the method of encrypti…
Are you one of those front-line IT Service Desk staff fielding calls, replying to emails, all-the-while working to resolve end-user technological nightmares? I am! That's why I have put together this brief overview of tools and techniques I use in o…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question