Solved

2003 Server clients authenticating to second DC

Posted on 2007-04-02
4
221 Views
Last Modified: 2010-03-05
We have a second 2003 DC setup as a backup in case the first 2003 DC fails.  Setup on both machines are the same except on the second DC DHCP not installed or setup.  Both are running and authinticating to each other.  Second DC is also setup as backup DNS.  Oh sorry 2003 Standard Edition.  Ok this is what is happening...

When a client logs into the domain it is grabbing the login script from the second DC and not the first.  Checked ipconfig /all to see what it had for dns and everything there looks good.  Checked DNS on first DC and all looks good. We do have a second nic installed on both DC's that connect to our local SAN network.  I did notice that in DNs on the first DC the ip order was the SAN network ip first and the DC's local network IP second.  I selected the first DC and hit resolve and that moved it back into proper order.  I also checked the advanced settings on the NIC's and the DC's Nics where in the correct order....  Strange that in DNS it was different and i had to click the first DC and hit resolve so it would correct the order...

Why would it grab the login script from the second DC and not the first DC???  & Why would in DNS the NICS ip's order change???
0
Comment
Question by:creativeSD
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 30

Accepted Solution

by:
LauraEHunterMVP earned 175 total points
ID: 18838131
Are both domain controllers in the same site?  If so, and all other things being equal, your clients will choose between either DC in a round-robin fashion. However, once a client "chooses" one DC or the other, it will retain that "DC-affinity" for as long as it can continue to contact that DC. This is by design, since Active Directory is designed to be a multi-master directory service - old notions of the PDC and the BDC are no longer in play.

If you still want clients to authenticate to one DC instead of the other, you can modify the default priority and weight of their SRV records in DNS, see the following tutorial for more information: http://www.2000trainers.com/windows-2000/dns-service-records/. For example, if you have 2 DCs with different priorities in DNS, clients will prefer the DNS with the better (lower-numbered) priority.

Hope this helps.

Laura E. Hunter - Microsoft MVP: Windows Server - Networking
0
 

Author Comment

by:creativeSD
ID: 18838479
Thaks!  great info.  I did a reboot on one of the clients and it did then log into the first DC.  Yes both domain controllers are in the same site.  Wonder why it went back to the other DC after reboot....
0
 
LVL 25

Assisted Solution

by:Ron Malmstead
Ron Malmstead earned 75 total points
ID: 18838546
Logon scripts for the domain are replicated in AD after they are modified...so it really shouldn't matter where they pull from.

Are both of the DC's...global catalog servers ?
Global catalog servers process logons....So if one is, and one isn't ....well you get the idea.

LauraEHunter is correct.  You can change the priority of the SRV records in DNS...to go to a "preferred server"....but both should be gc's.
0
 

Author Comment

by:creativeSD
ID: 18840855
Ok the the second DC's global catalog was enabled earlier today.  It appears things are back to norm but going to wait a day or so to see if anything else pops up.  thanks for your help thus far.  
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ADMT 3.2 LAB Computer Migration not successful 2 107
server crashed 2 59
Raising Forest Functional Level 9 57
Delete Disconnected Site from Active Directory 3 59
Many admins will agree: WSUS is is a nice invention but using it on the client side when updating a newly installed computer is still time consuming as you have to do several reboots and furthermore, the procedure of installing updates, rebooting an…
Issue: One Windows 2008 R2 64bit server on the network unable to connect to a buffalo Device (Linkstation) with firmware version 1.56. There are a total of four servers on the network this being one of them. Troubleshooting Steps: Connect via h…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question