?
Solved

Second AD Domain Controller

Posted on 2011-02-25
9
Medium Priority
?
631 Views
Last Modified: 2012-08-13
I have a server which runs 4 virtual machines on Hyper-V, and is also a DC, DNS, DHCP. I want to obvously have a backup of this. I have two older machines which I premarily use as SQL batch operation machines.

Should I install promote a virtual machine, or one of the old physical machines? what happens when the old physical machine dies? Does that leave rouge crap in AD forever that is always causing errors? I have had this problem before on another network where one of the DCs died, and I could never get rid of some phantom issues where it was looking for the other machine first.

the only reason I could think to use a virtual machine as the secondary DC would be because I can redeploy that from backup image, and bam I have my AD back. the physical old machine I think would be the best route, but if it dies, I dont want to replace right away likely. So what happens when a secondary DC just drops off the face of the earth I guess is the real question?
0
Comment
Question by:markterry
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
9 Comments
 
LVL 2

Accepted Solution

by:
Mattrw earned 2000 total points
ID: 34984429
Virtual DC's can be a bit of a problem.  If the virtual DC has a problem with it's network connectivity it will opt to receive it's time source from the the clock on the hardware it's hosted.  This in turn can cause problems because it may fall out of sync with other DC's while it thinks it has the correct time.  MS recommend you stick with physical DC's where ever possible.  If your physical DC is lost foreever then seize the roles this broken DC held, rebuild  a new  server promote it and name it accordingly it will start to replicate all of the information from the other domain controllers.
0
 
LVL 2

Assisted Solution

by:Mattrw
Mattrw earned 2000 total points
ID: 34984469
Further Clarification:  Your DC's should have an NTP time source set such as an atomic clock which can be updated over the internet.  If your virtual dc loses this NTP time source it will opt for the hardware time source in the BIOS.
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34984485
In an only-two DC environment (which is what minimally what you should have). Opt for one physical.

VM based DCs have been far too prevalent and they are supported by MS.

Regarding the tim sync issue mentioned above, see my blog post http://www.shariqsheikh.com/blog/index.php/200912/time-synchronization-for-virtualized-dcs/
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 6

Author Closing Comment

by:markterry
ID: 34984487
Thank you! that is very informative and exactly what I was hoping/expecting to hear.
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34984510
Only the PDCe (the FSMO role) should be setup as NTP (with an external source), the other DC(s) should be setup with NT5DS i.e setup to sync its time with the PDCe (by default).

http://support.microsoft.com/kb/816042
0
 
LVL 6

Author Comment

by:markterry
ID: 34984567
I guess I accepted the answer to the question a bit too early. Now I am a bit torn. So should I go virtual then?

I still think I will go for physical over virtual as if the host goes down, so do the virtuals, and I have to wait to be able to restore for AD to be online.

I will take heed the time issues, that is very informative, Thank you!
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34984600
0
 
LVL 6

Author Comment

by:markterry
ID: 34985096
Restore from a backup image (windows backup image) just as bad as well?
0
 
LVL 11

Expert Comment

by:RickSheikh
ID: 34985445
True as it is an image, take a look at the links regarding the USN issue with doing so.
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Here's a look at newsworthy articles and community happenings during the last month.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses
Course of the Month12 days, 20 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question