How to install a Windows 2000 Backup Domain Controller in a 2003 network?

How do I install/setup a Windows 2000 Server as a Backup Domain Controller in a 2003 network?
LVL 1
askstevehowAsked:
Who is Participating?
 
tigermattConnect With a Mentor Commented:

Install Server 2000 to the server and make it a member of the existing domain. Then, at a Start > Run prompt, enter the dcpromo command. Follow through the wizard to promote the server, choosing the option 'Additional Domain Controller in an existing domain' when prompted.

This will be possible, provided the Domain/Forest Functional Levels have not been upgraded to Server 2003. If they have, you cannot (and will never be able to) run a pre-Windows 2003 machine as a DC.

-Matt
0
 
askstevehowAuthor Commented:
How can I find that out before doing the promo and what other things should I be aware of?
0
 
tigermattCommented:

Here's how to check the Domain and Forest Functional Levels. You do NOT want to actually hit the 'Raise' option. Instead, when the procedure tells you to press 'Raise Domain Functional Level', press Properties in the menu instead. You can then see the appropriate information in the dialog box.

The only other thing you should be aware of is that the new DC needs to initially point to the IP of the other DC as its DNS Server during the promotion. You can then make it a GC and DNS Server, and point it back to itself for DNS.

Make it a GC: http://www.petri.co.il/configure_a_new_global_catalog.htm
Install DNS Server: http://www.petri.co.il/install_and_configure_w2k_dns_server.htm (just the initial 'Installing' part, not the 'Configuring' section).

-Matt
0
Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

 
askstevehowAuthor Commented:
Where is the raise option exactly?  Do I come to it during the promo or?
0
 
tigermattCommented:

Sorry, I should have explained. Active Directory has a concept of Domain and Forest Functional Levels. These essentially define the Operating System base which can be installed as DCs on the network. Raising the functional level is an irreversible reaction, since doing so unlocks features specific to the current functional level and higher.

For example, if I raise the Domain Functional Level to 2003, I guarantee there can be no 2000 DCs on the network (and never will be). Several Server 2003-specific Active Directory-related features are therefore unlocked.

You NEED the functional levels to be, at the highest, Server 2000 Native. If they have already been Raised any higher, the 2000 DC cannot be promoted.

I hope that answers your question.

-Matt
0
 
askstevehowAuthor Commented:
Where can I see if the Domain Functional level is at 2000 or 2003?
0
 
askstevehowAuthor Commented:
I found where to see what level it is at in the Active Directory Domain and Trust in MMC.  Looks like the domain is set to Windows 2000 mixed.  Will that be ok?
0
 
askstevehowAuthor Commented:
Looks like the domain is set to Windows 2000 mixed.  Will that be ok?
How do I point the new DC to the IP of the other DC as its DNS Server during the promotion?
0
 
tigermattCommented:

Yes, Windows Server 2000 Mixed will be fine.

Simply edit the properties of the DC's Network Card, TCP/IP Properties, and set the static IP there. In the preferred DNS server, enter the IP of your current DC.

-Matt
0
 
askstevehowAuthor Commented:
OK.  Do that before I start the promo?
Then make it a GC and finally install the DNS server and then change the properties of the NIC for the preferred DNS to point to itself?
0
 
tigermattCommented:

That all sounds right to me, yes.
0
 
askstevehowAuthor Commented:
Is there any chance this could mess up my curent DC?  Should I have a backup of that first?
0
 
tigermattCommented:

The chances are slim. It's a good idea to take a System State backup using NTBackup - JUST in case - but I have promoted many DCs over my time and never, ever had one mess up Active Directory.

If it does, it's only a few keyboard transactions to clean up the failed attempt and try again.

-Matt
0
 
tigermattCommented:
http:#a24101189 answered the original question, so I suggest Accept that comment.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.