DC down, DC up again.

2 DCs. Master fails. I seized the FSMO roles to the second DC. Worked great. Cleaned up Metadata. I rebuilt DNS from scratch on new Master and DHCP.

After tinkering with the failed DC I got it to boot. I turned off DNS and DHCP on the "bad" server. I want this sever up a few more days so I can pull other service configs and some file shares off before I format and reinstall as a DC again.

It is interfearing with the GC. when I try to add a computer to the domain, it shows up under the ADUC of the bad DC and not the Good one. i tryied to rebuild the connections to allow replication. When I force replication it says "replication completed" but the new WS does not show up in the "Good" dc, only the "bad" one.

I checked the Metadata and the PDC roles on both servers and they both point to the "Good" server.

When i ping the domain.local from the Workstations it returns the IP of the Bad DC. flushdns did not fix it.

I want to put the bad DC into a member server role so that it will stop interfearing with the GC long enough to xcopy some files off of it and then format the raid. Keep in mind DCPROMO does not work, and ntdsutil does not see the bad DC.
stephenwylesAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Henrik JohanssonSystems engineerCommented:
If seizing FSMO-roles, the old DC holding FSMOs shall not be online as DC again until it has been demoted and cleaned up.
Use dcpromo/forceremoval on the bad DC and cleanup metadata before getting it back as DC again.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
stephenwylesAuthor Commented:
This appears to be working, it got further than the normal "dcpromo" attempt. I will keep you posted.
0
stephenwylesAuthor Commented:
It appears to have worked... one problem. When it finished, it said it successfully removed AD from the computer... Restart Now or Restart Later?

That's a problem. I do not want to restart this server in the fear of it not coming back up. I feel as though it is on "life support" and if I shut it down it may never start back up. I need windows to restart so that I can continue to get the service config settings off of it.

Anyway to manually restart the individual services in order to clear the AD info from the server without actually restarting it?
0
10 Tips to Protect Your Business from Ransomware

Did you know that ransomware is the most widespread, destructive malware in the world today? It accounts for 39% of all security breaches, with ransomware gangsters projected to make $11.5B in profits from online extortion by 2019.

SteveCommented:
in a situation where a bad DC is interfering you're best option is to disconnect it from the network.
In this way, you can have the bad DC running and copy files or access it as required without it affeecting the existing domain. BY design, while the server is connected and thinks it is a DC, it will try to perform DC tasks and cause problems.

0
Krzysztof PytkoSenior Active Directory EngineerCommented:
After FSMO seizing old DC shouldn't be connected to the network. You have to reinstall OS first and then promote it to the domain controller again. If you do not proceed that way you can have problems with PDC.
0
Henrik JohanssonSystems engineerCommented:
The reboot is necessary to finish the removing of the DC role.
With the metadata cleanup on the good DC, it is not longer recognized as DC in the domain, but still beleaved it's a DC until used dcpromo/forceremoval to force it into member server role.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.