Solved

Adding 2nd DC to Server R2 Existing Domain

Posted on 2010-11-23
25
890 Views
Last Modified: 2012-06-27
I have 1 08 server r2 as the DC. I am trying to add the second 08 server r2 into the same domain. During the dcpromo i get to the part where it asks if it is a dns server/global catalog and then when i hit next it comes back and says:

A delegation for this dns server cannot be created because the authoritive parent zone cannot be found or it does not run windows dns server.

Then it goes on to say i would need to manually add the delegation myself bla bla bla.

So why am i getting this. Like i said my other 08 server is the only dc and as far as i can tell dns is working fine. Any tests i should run or what can i do to fix this message. It says i can ignore this and continue but i am waiting so i do not get a screwed up dc off the bat.

Thanks.
0
Comment
Question by:valmatic
  • 13
  • 5
  • 4
  • +1
25 Comments
 
LVL 39

Expert Comment

by:Krzysztof Pytko
Comment Utility
That's nothing worrying if you install your first DNS server (DC + DNS). This is because server points to itself as DNS server. When you set up additional DNS server, first you have to be sure that you properly configured NIC settings of that new box. Check if you set up IP address in DNS section of your existing server. Then during promotion process you shouldn't see that message.

Regards,
Krzysztof
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
well on my new DC i am trying to add the DC role to it is not anything yet. No dns no nothing. So i have a static ip set and it of course is pointing for DNS to my #1 DC that also runs dns.

So you are saying this is why i am getting the message?

Should i cancel this wizard and set up DNS by itself then come back and run dcpromo?
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
Comment Utility
No no, definitively you should point in DNS section to your existing DNS server. Then run dcpromo and follow with wizard. Make you new DC as DNS and Global Catalog server and don't worry, everything will be fine! :)

Regards,
Krzysztof
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
when the install is done do i set my new DC to look at itself for DNS then and list the other as its second choice?
0
 
LVL 31

Expert Comment

by:DrUltima
Comment Utility
Yes, just make sure that by "others", you don't mean external sources.
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
Yes, i meant by others as in my internal dns server which was the first DC on my domain till this one.
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
Comment Utility
Set up NIC's properties in DNS section

Primary DNS IP address: current DC
Alternative DNS IP address: second DC

Do not configure external forwarders on new DC, only set up forwarders to old DC which contains external (probably ISP) DNS server. Then all unresolved queries from new DC's DNS will be redirected to old DC and it will send them to ISP's DNS server for the Internet access (I hope I wrote it clear ;) )

Additionally, modify option no. 006 in your DHCP server's scope. Add there second DNS IP address of your new DC

Regards,
Krzysztof
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
So, you are getting this error for a reason.

Check your DNS Console do you have a msdcs.domain.com zone? Do you have a domain.com zone with the msdcs folder grayed out?
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
Darius, yes i have all thse things you listed.
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
actually let me clarify darius. I have 2 of my own zones listed in dns. I do not see msdcs.domain.com in the root that holds all my zones.

However under my one zone i have a folder called msdsc and it is no greyed out.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
Ok good so you have a domain.com or domain.local zone with the msdcs folder listed under this zone that is not grayed out, right?

You need to make sure that all DNS servers have this zone with this folder not being grayed out. Check your other DNS servers.
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
Yes, both servers have that folder not greyed out under my main domain name.
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
Good. Run dcdiag /fix

Do you have records in these folders?
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
Records of what? What am i looking for. Here is my dcdiag /fix.

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = VALDC2
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\VALDC2
      Starting test: Connectivity
         ......................... VALDC2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\VALDC2
      Starting test: Advertising
         ......................... VALDC2 passed test Advertising
      Starting test: FrsEvent
         ......................... VALDC2 passed test FrsEvent
      Starting test: DFSREvent
         ......................... VALDC2 passed test DFSREvent
      Starting test: SysVolCheck
         ......................... VALDC2 passed test SysVolCheck
      Starting test: KccEvent
         ......................... VALDC2 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... VALDC2 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... VALDC2 passed test MachineAccount
      Starting test: NCSecDesc
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=ForestDnsZones,DC=valmatic,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=DomainDnsZones,DC=valmatic,DC=com
         ......................... VALDC2 failed test NCSecDesc
      Starting test: NetLogons
         ......................... VALDC2 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... VALDC2 passed test ObjectsReplicated
      Starting test: Replications
         ......................... VALDC2 passed test Replications
      Starting test: RidManager
         ......................... VALDC2 passed test RidManager
      Starting test: Services
         ......................... VALDC2 passed test Services
      Starting test: SystemLog
         ......................... VALDC2 passed test SystemLog
      Starting test: VerifyReferences
         ......................... VALDC2 passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : valmatic
      Starting test: CheckSDRefDom
         ......................... valmatic passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... valmatic passed test CrossRefValidation

   Running enterprise tests on : valmatic.com
      Starting test: LocatorCheck
         ......................... valmatic.com passed test LocatorCheck
      Starting test: Intersite
         ......................... valmatic.com passed test Intersite


0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
well there are subfolders in those folders and a couple of cname entries.
0
 
LVL 31

Expert Comment

by:DrUltima
Comment Utility
You can safely discard the error on NCSecDesc, as that only has to do with using RODCs.  If you don't plan on using them, this is irrelevant.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
Good that is what we are looking for now start the promotion process if you get the error stating it could not create the delegation record that is fine proceed
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
yeah no RODCs here. Thanks. Hopefully everyting is good. I guess i just have to turn off my main server when i have a chance and see if the second one can log people in and do dns to get to the web.
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
i did promote this one to a DC is there anyway to check that it is functioning as my backup.?
0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 250 total points
Comment Utility
First thing make sure your DC is pointing to itself for DNS. Second make sure clients have this DNS server in their TCP\IP properties. Make sure this DC is a Global Catalog server.

For full test you really need to move over the fsmo roles to make sure everything is running properly.
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
so if the first main dc i have that has every roles goes down, will this one not work unless i manually switch the roles?
0
 
LVL 31

Expert Comment

by:DrUltima
Comment Utility
If the server which contains the FSMO roles fails, you will have to seize the roles on another server.  It will continue to work in a diminished state before that is done, but not well.
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
so basically logons and dns requests will take a few minutes. Well that kind of stinks, i would think it is more streamed line since having multiples dcs is the usual? Should i balance the roles or do you see no benefit?
0
 
LVL 31

Assisted Solution

by:DrUltima
DrUltima earned 250 total points
Comment Utility
There are good arguments for and against having your FSMO roles separated or all on the same machine.  Another Expert (well, several of us, really), addressed the issue of splitting FSMO roles on this Question:

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Q_25204029.html

I would suggest not splitting it unless you are in a very large environment.  There are some Roles which MUST be on the same server:

http://support.microsoft.com/kb/223346

Justin
0
 
LVL 7

Author Comment

by:valmatic
Comment Utility
Thanks for the input Justin. I will take a look at those articles.
0

Featured Post

Why do Marketing keep bothering you?

Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

Join & Write a Comment

There have been a lot of times when we have seen the need to enter a large number of DNS entries in a forward lookup zone. The standard procedure would be to launch the DNS Manager console, create the Zone and start adding new hosts using the New…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now