GCIT_Manager
asked on
AD DNS SOA with 2 DCs
I added a new domain controller. I can't remember the exact errors anymore but I'm certain everything didn't go as it should have.
Are there specific steps I should take to verify that adding the second DC worked correctly? One thing I'm not certain of is if DNS was set up correctly. I go the the DNS domain properties in each DC and both say that the Primary server is themselves. Is this as it should be?
I've set the NIC properties to point to their own IPs. Things like this I'm trying to see if everything is working.
thanks! (the better your list of checkmarks, the better the points!)
Are there specific steps I should take to verify that adding the second DC worked correctly? One thing I'm not certain of is if DNS was set up correctly. I go the the DNS domain properties in each DC and both say that the Primary server is themselves. Is this as it should be?
I've set the NIC properties to point to their own IPs. Things like this I'm trying to see if everything is working.
thanks! (the better your list of checkmarks, the better the points!)
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
I have a major deadline for this and thus I have reverted (using our SAN) to pre-AD for all our servers. This issue is one of many I've been having. I'm praying this doesn't happen on the second try. If so I will definitely do your suggestions.
Anyway, if any other ideas please post because there's a chance the issues will come back once I install AD again.
One other question: Do you think I should configure all the roles and features before I add servers to the domain or add them to AD and then add the features and roles? things like IIS, Application Role, etc.
Thanks!Accept and Award Points Accept as Solution
Anyway, if any other ideas please post because there's a chance the issues will come back once I install AD again.
One other question: Do you think I should configure all the roles and features before I add servers to the domain or add them to AD and then add the features and roles? things like IIS, Application Role, etc.
Thanks!Accept and Award Points Accept as Solution
ASKER
I have a major deadline for this and thus I have reverted (using our SAN) to pre-AD for all our servers. This issue is one of many I've been having. I'm praying this doesn't happen on the second try. If so I will definitely do your suggestions.
Anyway, if any other ideas please post because there's a chance the issues will come back once I install AD again.
One other question: Do you think I should configure all the roles and features before I add servers to the domain or add them to AD and then add the features and roles? things like IIS, Application Role, etc.
Thanks!Accept and Award Points Accept as Solution
Anyway, if any other ideas please post because there's a chance the issues will come back once I install AD again.
One other question: Do you think I should configure all the roles and features before I add servers to the domain or add them to AD and then add the features and roles? things like IIS, Application Role, etc.
Thanks!Accept and Award Points Accept as Solution
If you can try to keep other applications of your DC but if you have to have them on there I'd add them after the server is part of the domain but either way will work.
Good luck on try two.
So right now there is no active directory? Just trying to figure out your setup.
Thanks
Mike
Good luck on try two.
So right now there is no active directory? Just trying to figure out your setup.
Thanks
Mike
Just a tiny note...
> I go the the DNS domain properties in each DC and both say that the Primary server is themselves.
> Is this as it should be?
Referring to the SOA record for AD Integrated zones: Yes, that is exactly as it should be.
In the traditional DNS model (standard zones) the SOA is the only system to hold a writeable copy of the zone. In the multi-master model used with AD Integration this means that each server hosting the zone must also consider itself to be the Start of Authority (SOA) for the zone if it is to accept dynamic updates.
Chris
ASKER
Chhris-Dent:
Thanks for the reply. So in my past experience I saw the AD admin incrememnt the SOA priority number each time he changed DNS. Should I be doing this? And thus make sure whichever DNS server I make the change on I increment to be higher than the other one and it should replicate those changes automatically?
Mkline71:
Yeah, one of our other domain controllers is also going to be backup SQL server. Can't afford lots of separate servers.
Thanks for the reply. So in my past experience I saw the AD admin incrememnt the SOA priority number each time he changed DNS. Should I be doing this? And thus make sure whichever DNS server I make the change on I increment to be higher than the other one and it should replicate those changes automatically?
Mkline71:
Yeah, one of our other domain controllers is also going to be backup SQL server. Can't afford lots of separate servers.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thanks. So in DNS, should I allow zone transfers (as picture shows) in an AD only environment? I've selected only those in the Name Servers tab as the setting. Then there's the "automatically notify secondary servers" popup too (on top in picture).
Thanks!
Zone-Transfers.JPG
Thanks!
Zone-Transfers.JPG
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
What type of zone do you have now? If you have a primary you can convert that to AD Integrated
http://support.microsoft.c om/kb/8161 01
How To Convert DNS Primary Server to Active Directory Integrated
Thanks
Mike
http://support.microsoft.c
How To Convert DNS Primary Server to Active Directory Integrated
Thanks
Mike
ASKER
Thanks. We're already AD integrated. I'll uncheck both those screens now...
it will check the DNS,AD health state.
http://support.microsoft.com/kb/321045