Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


DNS server deleted during DC demotion.  No running DNS server on Domain.  How do I rebuild?

Posted on 2006-07-18
Medium Priority
Last Modified: 2010-04-18
I have 3  Win2003 servers.  I demoted my PDC so I could set it up with Exchange 2003.  It was also my DNS server.  The demotion went fine (well, maybe not) but the DNS deleted as well.  There are no longer any zones configured.  Active directory on my new PDC looks complete.  How do I rebuild my DNS?

Question by:srsdtech
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
LVL 85

Expert Comment

ID: 17130777
What exactly do you mean with "demoted my PDC" and "AD on my new PDC looks complete"? What was your setup (DNS, AD) before you demoted the machine, what is your current state now? What is the "final state" you want to have?
As to what happened: your zones were AD integrated, so they're only available if the DNS server is running AD as well.

Author Comment

ID: 17130852
I only had two real servers on the network.  The rest were in different states of rebuild and phase-out and have limited network functionality.  Fileserver and Netserver were both DCs with AD and global catalog (win2003).  Netserver had the 5 FSMO roles, timeserver role, and DNS.  I transferred the first 6 roles to fileserver and then removed active directory from netserver without intentionally changing DNS in any way.  After the demotion, I looked at my event logs to see how things went.  I had a bunch of 4015, 4000, and 4001 errors in DNS, so looked at my DNS to see what was happening.  There were no zones configured.  That brings you up to about 15 minutes ago.

Author Comment

ID: 17130896
Re "AD looks complete"

The AD now resides on fileserver, the only DC currently on the network.

There seemed to be fewer columns displayed for the objects than I remember, but all the entries were there and a spot check of records revealed that all the information appeared to be there as well.
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

LVL 26

Expert Comment

ID: 17130992
The original PDC you demoted probably had an Active Directory integrated DNS zone.  When you removed AD from the box, so went DNS as this is stored in AD.
If you want DNS to remain on this box, you will need to make it a secondary DNS server pointing to your new PDC.


Author Comment

ID: 17131075
Pber--that rings a bell.


The problem is that was the only server running DNS.  Is it a big deal rebuilding my DNS from scratch on an existing domain?  I am researching that as I do this (this forum is part of my research) but have not settled on a course of action yet.
LVL 85

Accepted Solution

oBdA earned 2000 total points
ID: 17131163
So no DNS on the new DC? That's bad. For the quickest resolution (assuming NewDC and all the other machines in your network are currently pointing to OldDC for DNS, and assuming you want DNS on NewDC from now on), create a new forward lookup zone for your AD domain on OldDC, enable dynamic updates for the zone. Allow zone transfers to NewDC.
On NewDC, open a command prompt and enter "ipconfig /registerdns", and restart the netlogon service. Run ipconfig /registerdns on any other vital server that needs to be resolved by your clients.
That should get you going again; the next steps don't need to happen immediately.
Install DNS on NewDC; create a secondary zone with OldDC as master. Let the zone replicate.
Change your clients to use NewDC as DNS server.
Change NewDC to use itself as DNS server, and finally change the zone type of the secondary zone on NewDC to primary and AD integrated.
Check if everything works OK, and delete the zones from OldDC.

Author Comment

ID: 17131519
Thanks, oBdA.  I'll start on that now and re-post as soon as I complete the steps.  

Author Comment

ID: 17131897
Wow.  Well, I started messing around and discovered DNS was up and running on the new PDC.  Apparently, it was installed as part of the demotion process of the old PDC. (?)

I feel a little foolish, but never thought to look there because I knew I had not intentionally installed DNS on the new PDC myself.

Before I close this, I will ask one more question.  The DNS is set up on the new DC as AD-integrated.  Will the old DC (which no longer runs AD) work okay as a backup DNS server, or should I remove the DNS role from the old DC and use my third server (which will have AD installed on it) as the backup DNS?

What I am actually asking is:  Is it best to run DNS on a server that runs AD?
LVL 85

Expert Comment

ID: 17131981
Then you had the DNS service already installed on NewDC; that's the benefit of AD integrated zones.
Anyway, if you have another DC, then yes, it's best to run DNS on it as well. Keeping OldDC as DNS server would require to create a secondary zone on OldDC and replicate this the old-fashioned way. AD integrated zones have the big advantage (apart from secure updates) that each DNS server is SOA ad can write to the zone.

Author Comment

ID: 17132033
Thanks.  I'll remove DNS and set it up on the third server then.  Appreciate your prompt attention to this.

Featured Post

Ask an Anonymous Question!

Don't feel intimidated by what you don't know. Ask your question anonymously. It's easy! Learn more and upgrade.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Video by: ITPro.TV
In this episode Don builds upon the troubleshooting techniques by demonstrating how to properly monitor a vSphere deployment to detect problems before they occur. He begins the show using tools found within the vSphere suite as ends the show demonst…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question