Solved

migrate DNS from Windows 2000 to AD integrated Windows 2003

Posted on 2006-07-07
8
498 Views
Last Modified: 2010-04-18
I have DNS running on two Windows 2000 servers, one primary and one secondary.  Each of these Windows 2000 servers is a AD domain controller; but DNS is not running as AD integreated.

I have added a new Windows 2003 server as a AD domain controller, and would now like to migrate DNS to this new 2003 domain controller and make DNS AD integrated.  Once I have that working I will also be adding a 2nd Windows 2003 DNS AD domain controller and add DNS to that server.

1.  Could someone please provide me with the steps to setup/add the Windows 2003 server into DNS, AD integrate DNS, and then remove DNS from the two Windows 2000 servers?

2.  Also, how will this impact current Windows clients and Exchange mail traffic, etc.?  I need to be able to make this transition without bringing down the corporate LAN for a whole day.

Thanks.
0
Comment
Question by:baze68
  • 4
  • 3
8 Comments
 
LVL 43

Expert Comment

by:Steve Knight
ID: 17059008
I believe you should be able to just change the zone type to "AD inegrated" on the exisitng primary.  

Here you go:

"Enable Active Directory Integrated DNS (Optional - Recommended)
Active Directory Integrated DNS uses the directory for the storage and replication of DNS zone databases. If you decide to use Active Directory Integrated DNS, DNS runs on one or more domain controllers and you do not need to set up a separate DNS replication topology.

In DNS Manager, expand the DNS Server object.

Expand the Forward Lookup Zones folder.

Right-click the zone you created, and then click Properties.

On the General tab, the Zone Type value is set to Primary. Click Change to change the zone type.

In the Change Zone Type dialog box, click DS Integrated Primary, and then click OK.

The DNS server writes the zone database into Active Directory.

Right-click the zone named ".", and then click Properties.

On the General tab, the Zone Type value is set to Primary. Click Change to change the zone type.

In the Change Zone Type dialog box, DS Integrated Primary, and then click OK.
"
http://www.petri.co.il/create_a_new_dns_server_for_ad.htm
0
 
LVL 43

Expert Comment

by:Steve Knight
ID: 17059022
Then I would say remove the secondary from the second server and add another Ad integrated.  For your third server build it pointing at one of the other DNS servers then set it will take the AD integrated zone too.

Keep a copy of the zone files from \winnt\system32\dns just in case...

Steve
0
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 17059228
>>Then I would say remove the secondary from the second server and add another Ad integrated.
i agree, since they are both DCs already, it is really easy.  Just create or modify their exising zone to AD integrated and you are done.

no need to mess with all that primary/secondary BS.

but remember, on the client end, one DC's IP will need to be listed as the 'primary DNS server' and the other will need to be listed as a 'secondary DNS server'.  this is done on the properties of the NIC.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:baze68
ID: 17063254
Can I add the new Windows 2003 AD server into DNS as a secondary server, and then once it has all the zones can I switch that 2003 DNS server from secondary to Primary/AD integrated?  How would this impact the current Windows 2000 DNS server that is set as primary?

I would like to leave the Windows 2000 DNS servers alone until I have the 2003 DNS server up and running - basically, if possible, I want to make sure that things are running fine on the 2003 server first.  I guess what I need help with is the steps involved to make this 2003 server AD integrated...and not break the current DNS in the process.

Thanks,
Patrick
0
 

Author Comment

by:baze68
ID: 17063285
One other thing: is there an easier way to create the DNS zones/records on the 'new' Windows 2003 DNS server, other than creating each one manually?  I have 24 forward zones and 8 reverse zones, and I'd like to be able to simply have all of the zones copied/created on the new server - is this possible?
0
 
LVL 43

Expert Comment

by:Steve Knight
ID: 17063907
Just make your existing one ad integrated, then all the zones will come across anyway.
0
 

Author Comment

by:baze68
ID: 17072462
Okay, so you are saying that I should take my Windows 2000 'primary' DNS server and AD integrate it first.  Then what?  Will the secondary Windows 2000 DNS server automatically get AD integrated?  What about setting up/adding the new Windows 2003 DNS server.

Sorry, but could  you be more specific with instructions about which server and what steps to complete on each?  Thanks.
0
 
LVL 43

Accepted Solution

by:
Steve Knight earned 500 total points
ID: 17073112
Sorry, was on poor connection through PDA (as I am again now) ... Yes update the 'PDC' first to AD integrated.  Your other server should still show as a secondary.  Once first server's AD has replicated to the second server (or force AD replication) then I believe you need to turn that to AD integrated too (if you want too) - I'm afraid not sure whether it will automatically change over or not.  When you build the new server install DNS server on it and it *will* automatically have all the AD integrated zone.  Build the extra server pointing it's DNS to the first server that is already AD integrated.

To answer your previous Q yes you could add the new server in using a secondary zone but you'd have to create each one and I would imagine it is only the primary DNS zone that can be migrated to AD integrated initially?

Sorry can't be more specific than that at the moment bdue to poor connection, the link I gave above goes into more info. on how to actually turn a zone AD integrated.

regards

Steve
0

Featured Post

Active Directory Webinar

We all know we need to protect and secure our privileges, but where to start? Join Experts Exchange and ManageEngine on Tuesday, April 11, 2017 10:00 AM PDT to learn how to track and secure privileged users in Active Directory.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question