Solved

windows 2003 domain controler Global Catalog fail over

Posted on 2011-03-15
8
401 Views
Last Modified: 2012-06-27
When I reboot my main 2k3 DC my second 2k3 DC will not allow users to log into the domain. Under sites and services I have checked the box on both servers for the Global Catalog. I hear there is a service I have to install on the second DC in order for him to allow users to log in once the main DC is off line. Is there instructions on how to do this?
0
Comment
Question by:Martin_01
  • 3
  • 3
  • 2
8 Comments
 
LVL 13

Expert Comment

by:Felix Leven
Comment Utility
Check FSMO roles:
Click Start, click Run, type cmd in the Open box, and then press ENTER.

Type ntdsutil, and then press ENTER.
Type domain management, and then press ENTER.
Type connections, and then press ENTER.
Type connect to server ServerName, where ServerName is the Name of the Domain Controller you would like to view, and then press ENTER.
Type quit, and then press ENTER.
Type select operation target, and then press ENTER.
Type list roles for connected server, and then press ENTER.
0
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
Can the built=in admin account login when this happened? (don't need the GC for them)

The Administrator in the domain (the Builtin Administrator account) can always log on to the domain, even when a global catalog server is not available.http://technet.microsoft.com/en-us/library/cc730749.aspx

Are both DCs DNS servers...if they are make sure clients have both DNS servers listed in their configuration.

Thanks

Mike
0
 

Author Comment

by:Martin_01
Comment Utility
the FSMO roles are on DC1.

the main Domain admin acct can login only on DC2 when DC1 is down. Yes both DCs have DNS.

Is there a service that can be added to dc2 to fix this?
0
 

Author Comment

by:Martin_01
Comment Utility
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
FSMO roles don't have anythign to do with logons.  Did you try Mr. Graves suggestion?
0
 

Author Comment

by:Martin_01
Comment Utility
I can see the rsmo roles, but is there a service that is needed on second DC for it to allow users to log in when DC1 is down
0
 
LVL 13

Expert Comment

by:Felix Leven
Comment Utility
First, Routput to a text file (/?) -- search the file for FAIL, ERROR,
 WARN and either fix those errors or report them.
 
DNS server(s) are correct configured by dhcp on the client?

 try to restart NetLogon service..
 
0
 
LVL 13

Accepted Solution

by:
Felix Leven earned 500 total points
Comment Utility
sry,
First, run DCDiag on the problematic DC -- and save the output to a text file (/?) -- search the file for FAIL, ERROR, WARN and either fix those errors or report them.
 
DNS server(s) are correct configured by dhcp on the client?

 try to restart NetLogon service..

 
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now