• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 229
  • Last Modified:

Adding a 2003 DC into a 2000 Domain

About a month ago I added a 2003 member server to my domain.  The domain already had 2 other 2003 member servers.  One of which is running exchange 2003.   I ran the forestprep and domainprep before installing Exchange 2003.  The member server is DC1.  After a week of no problems with this server in the domain I promoted it to a DC.  It is also running DHCP and DNS.  I transfered all the FSMO roles over to it from one of 2 2000 DC's.  The roles were split between the 2 2000 DC's.  I set it up as the Authoritive time server as well.  The 2000 DC called ADMIN was the DHCP server.  I stopped DHCP on it.  Most of the machines in the network switched over without a problem.  A few reported duplicate IP's on the network but a reboot corrected this.  I also found some "Bad Address" listings in the DHCP table.  I removed these as well.  All three DC's were Global Catalog servers as well.  After 2 weeks without any other problems.  I decided to turn off ADMIN to see if any problems would arise.  I am not sure if this was a good or bad idea, but it seemed a good way to test the 2003 DC.  2 of my 2003 member servers had errors in the event log stating they could not find a DC to authenticate with so no group policy would be loaded.  I rebooted them and they took at least ten minutes to get past the applying group policy window, right before the CTRL+ALT+DEL window pops up.   I turned ADMIN back on because I was unsure if this had any relation to that DC being off.  All the errors in the event logs of the 2 2003 servers went away.  ADMIN was the first DC in this domain.  I am not sure if more needs to be done besides transfering the FSMO roles and the global catalog.  Another strange thing I noticed was when i try to change a logon script in the Netlogon folder of DC1, The change would not replicate to the other 2 DC's.  Today I was investigating this and I noticed that from DC1 I can view the NETLOGON folder on ADMIN and the other DC, BACKUP, but i cannot even edit the scripts.  If I right click on a script and click edit, I get an error stating a permissions error.  There are no errors in the Replication log and other things seem to be replicating perfect.  User account creation, I unchecked ADMIN as a Catalog server and that replicated the change on the other 2 DC's.  I'm not sure whats going on though.  Not sure if I missed a step.  Any suggestions are greatly appreciated and I can elaborate further on anything I've posted here so far.  I apologize in advance for the how scattered this post is as my thoughts were trying to document each thing i've noticed.  Thanks again,
0
RHNOC
Asked:
RHNOC
  • 4
  • 3
  • 2
1 Solution
 
weareitCommented:
What are the current DNS settings on each of the servers?

-saige-
0
 
Netman66Commented:
Changing the role of the server hosting Exchange is unsupported.  You promoted your Exchange server to a DC after Exchange was installed.  This normally causes Exchange to break, however there are other things that may happen.
http://support.microsoft.com/kb/822179
0
 
RHNOCAuthor Commented:
Netman66 - I did not promote my exchange server to a DC.  I added and then promoted a new 2003 member server.  Exchange is running on EXCH.  The 2003 box i promoted to DC is DC1.  

Weareit - Are you refering to the DNS settings in TCP/IP properties, or the settings for DNS itself?
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
weareitCommented:
Both...  The more information the better...

-saige-
0
 
Netman66Commented:
Sorry about that - I thought I read you promoted it after Exchange - my bad.

Let's see what other info you provide.

0
 
RHNOCAuthor Commented:
DNS is configured to Active Directory Integrated and the DNS service is running on all 3 DC's.  Here are the 3 DC's current DNS settings:

1) DC1 - Windows 2003 Server
DNS 1 - DC1
DNS 2 - BACKUP

2)  BACKUP - Windows 2000 Server
DNS 1 - DC1
DNS 2 - BACKUP

3) ADMIN - Windows 2000 Server
DNS 1 - DC1
DNS 2 - BACKUP

Let me know what other DNS info you want and i can get it.
0
 
RHNOCAuthor Commented:
I have ran DCDIAG and NETDIAG on the new DC and there were no problems.
0
 
Netman66Commented:
I've just reread this and something hit me.

On the 2003 server, in DNS console, list out the top-level zones in the Forward Lookup Zone.

My bet is there are some SRV (_msdcs) records missing.

0
 
RHNOCAuthor Commented:
I may not understand what your asking.  In DNS under the 2003 server -> Forward Lookup Zones -> Domain.com -> _msdcs folder.  The record in there match the other two DNS servers (ADMIN and BACKUP).  The files listed are the three DNS servers (Alias) records and 4 folders (PDC, GC, DOMAINS, DC).  DNS is not one of my strong points so if i am not getting you the correct info, i apologize.  If you could be more specific, i can try to retrieve any info you want.  Thanks

0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

  • 4
  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now