Solved

migrate DNS from Windows 2000 to AD integrated Windows 2003

Posted on 2006-07-07
8
494 Views
Last Modified: 2010-04-18
I have DNS running on two Windows 2000 servers, one primary and one secondary.  Each of these Windows 2000 servers is a AD domain controller; but DNS is not running as AD integreated.

I have added a new Windows 2003 server as a AD domain controller, and would now like to migrate DNS to this new 2003 domain controller and make DNS AD integrated.  Once I have that working I will also be adding a 2nd Windows 2003 DNS AD domain controller and add DNS to that server.

1.  Could someone please provide me with the steps to setup/add the Windows 2003 server into DNS, AD integrate DNS, and then remove DNS from the two Windows 2000 servers?

2.  Also, how will this impact current Windows clients and Exchange mail traffic, etc.?  I need to be able to make this transition without bringing down the corporate LAN for a whole day.

Thanks.
0
Comment
Question by:baze68
  • 4
  • 3
8 Comments
 
LVL 43

Expert Comment

by:Steve Knight
ID: 17059008
I believe you should be able to just change the zone type to "AD inegrated" on the exisitng primary.  

Here you go:

"Enable Active Directory Integrated DNS (Optional - Recommended)
Active Directory Integrated DNS uses the directory for the storage and replication of DNS zone databases. If you decide to use Active Directory Integrated DNS, DNS runs on one or more domain controllers and you do not need to set up a separate DNS replication topology.

In DNS Manager, expand the DNS Server object.

Expand the Forward Lookup Zones folder.

Right-click the zone you created, and then click Properties.

On the General tab, the Zone Type value is set to Primary. Click Change to change the zone type.

In the Change Zone Type dialog box, click DS Integrated Primary, and then click OK.

The DNS server writes the zone database into Active Directory.

Right-click the zone named ".", and then click Properties.

On the General tab, the Zone Type value is set to Primary. Click Change to change the zone type.

In the Change Zone Type dialog box, DS Integrated Primary, and then click OK.
"
http://www.petri.co.il/create_a_new_dns_server_for_ad.htm
0
 
LVL 43

Expert Comment

by:Steve Knight
ID: 17059022
Then I would say remove the secondary from the second server and add another Ad integrated.  For your third server build it pointing at one of the other DNS servers then set it will take the AD integrated zone too.

Keep a copy of the zone files from \winnt\system32\dns just in case...

Steve
0
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 17059228
>>Then I would say remove the secondary from the second server and add another Ad integrated.
i agree, since they are both DCs already, it is really easy.  Just create or modify their exising zone to AD integrated and you are done.

no need to mess with all that primary/secondary BS.

but remember, on the client end, one DC's IP will need to be listed as the 'primary DNS server' and the other will need to be listed as a 'secondary DNS server'.  this is done on the properties of the NIC.
0
 

Author Comment

by:baze68
ID: 17063254
Can I add the new Windows 2003 AD server into DNS as a secondary server, and then once it has all the zones can I switch that 2003 DNS server from secondary to Primary/AD integrated?  How would this impact the current Windows 2000 DNS server that is set as primary?

I would like to leave the Windows 2000 DNS servers alone until I have the 2003 DNS server up and running - basically, if possible, I want to make sure that things are running fine on the 2003 server first.  I guess what I need help with is the steps involved to make this 2003 server AD integrated...and not break the current DNS in the process.

Thanks,
Patrick
0
Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

 

Author Comment

by:baze68
ID: 17063285
One other thing: is there an easier way to create the DNS zones/records on the 'new' Windows 2003 DNS server, other than creating each one manually?  I have 24 forward zones and 8 reverse zones, and I'd like to be able to simply have all of the zones copied/created on the new server - is this possible?
0
 
LVL 43

Expert Comment

by:Steve Knight
ID: 17063907
Just make your existing one ad integrated, then all the zones will come across anyway.
0
 

Author Comment

by:baze68
ID: 17072462
Okay, so you are saying that I should take my Windows 2000 'primary' DNS server and AD integrate it first.  Then what?  Will the secondary Windows 2000 DNS server automatically get AD integrated?  What about setting up/adding the new Windows 2003 DNS server.

Sorry, but could  you be more specific with instructions about which server and what steps to complete on each?  Thanks.
0
 
LVL 43

Accepted Solution

by:
Steve Knight earned 500 total points
ID: 17073112
Sorry, was on poor connection through PDA (as I am again now) ... Yes update the 'PDC' first to AD integrated.  Your other server should still show as a secondary.  Once first server's AD has replicated to the second server (or force AD replication) then I believe you need to turn that to AD integrated too (if you want too) - I'm afraid not sure whether it will automatically change over or not.  When you build the new server install DNS server on it and it *will* automatically have all the AD integrated zone.  Build the extra server pointing it's DNS to the first server that is already AD integrated.

To answer your previous Q yes you could add the new server in using a secondary zone but you'd have to create each one and I would imagine it is only the primary DNS zone that can be migrated to AD integrated initially?

Sorry can't be more specific than that at the moment bdue to poor connection, the link I gave above goes into more info. on how to actually turn a zone AD integrated.

regards

Steve
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Suggested Solutions

by Batuhan Cetin Within the dynamic life of an IT administrator, we hold many information in our minds like user names, passwords, IDs, phone numbers, incomes, service tags, bills and the order from our wives to buy milk when coming back to home.…
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now