Solved

Setting up domain controller on Windows 2003 Server Platform

Posted on 2011-03-25
11
301 Views
Last Modified: 2012-05-11
Need to setup a new domain controller on Windows 2003 server platform as our old one is running on fumes.  I have never setup a domain controller using Acitve Directory before.  This controller needs to have dns, etc so computers can login into the internet successfully.  Also, the computers, user accounts, etc that are currently on domain controller do they have to be re-created or can they be copied over to the new domain controller.  Any help would be greatly appreciated.
0
Comment
Question by:qec-cmolloy
  • 4
  • 3
  • 2
  • +2
11 Comments
 
LVL 7

Accepted Solution

by:
mmicha earned 500 total points
Comment Utility
Below is a link to a guide to walk you through the process.

http://www.windowsreference.com/dns/step-by-step-guide-for-windows-server-2003-domain-controller-and-dns-server-setup/

If you currently have a domain controller, you will want to pick the add to existing domain option during the dcpromo process.  This will replicate the other domain controller and leave everything in tact.
0
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
Is your current DC a DNS server...I'm assuming yes.

In that case what you will want to do is point your DNS to the current server.  Then after dcpromo is done you can install the DNS service on the box and at that point just wait for replication to happen.

Make the new DC a global catalog too.

As previously stated no objects have to be recreated.  It all will replicate to the new DC (users, computers, group policy, sysvol, etc)

Thanks

Mike
0
 

Author Comment

by:qec-cmolloy
Comment Utility
Thanks mmicha it looks pretty good.   Just a couple of quick questions.  As we are not creating a new domain choose the option additional domain controller for an existing domain.  The next step in the process is where I am curious do I choose domain tree in an existing forest or domain in a new forset.

Basically our domain covers four locations and I am currently on-site to the location where the faulty domain controller needs to be replaced.  So, it is not a new domain we are creating just bascially a new domain controller in our already created domain.  Thanks for the help.
0
 

Author Comment

by:qec-cmolloy
Comment Utility
Thanks Mike, yes our current dc for this location is also a dns server as well.
0
 
LVL 11

Expert Comment

by:sighar
Comment Utility
Since the old one is about to give up, I'd also either downgrade it by using dcpomo after making sure they replicate ok or manually move the FSMO roles from the old one to the new one. Check out this url for info about FSMO roles and moving them: http://support.microsoft.com/kb/324801
0
Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

 
LVL 7

Expert Comment

by:mmicha
Comment Utility
You should select domain tree in existing forest.
0
 

Author Comment

by:qec-cmolloy
Comment Utility
Thanks MMicha.  I guess the only other think I want to be sure of is I will have to give the new domain controller a different static ip address as the one currently in use, and leave it powered on while the settings replicate??  Do you know how long replication normally takes it?? Reason being is that we want to power off the old doamin controller once completed and provide the new one with the static ip of the current dc in use.
0
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
I would not downgrade/demote the old one until you have at least two others left.  Always try and have two DCs if you can.

Thanks

Mike
0
 
LVL 7

Expert Comment

by:mmicha
Comment Utility
If the site has a domain controller at it, I'd imagine replication will not take very long.  Sighar posted material about FSMO roles that you may want to check before you decom the old DC.  You don't want to kill the DC handling roles until you move them.

Under AD Site & Services you can force replication as well.  Then just run DCPROMO on the old DC, and demote it cleanly.
0
 
LVL 7

Expert Comment

by:mmicha
Comment Utility
Guide for changing IP Address of Domain Controller:
http://technet.microsoft.com/en-us/library/cc758579(WS.10).aspx
0
 
LVL 1

Expert Comment

by:vagedis23
Comment Utility
Use ideal migration from pointdev.com.

This tool allowes you to easily export all objects you want to have on the new domain controller and import them as well. You can copy user passwords, user group memberships ( very Important if you want to keep your NTFS security to work after moving to à new server.

Make sure your new server is NOT connected to your existing network.
Install 2003 server and perform the dcpromo.exe command from start --> run

Fill in your domain name and keep everything else default.

Make sure you select install the first domain controller for à new domain. The servername and ip address must be the Same as your old server, to ensure drive mappings on client pc's Will still work after the migration..

Create Export with ideal migration on old server to USB disk.
Make sure SID history and user groupmembership and computers are exported together with all objects you want to copy to the new server.

Run ideal migration on the new server and import the data from your USB disk.
Shutdown your old domain controller, connect your new server to THE network.

check if the cliënts can login with the new DC with the same username and password as before.

If they can, the object migration was succesfull. If they cannot login, disconnect new server from the network en start up the old server again. everything Will then be back to the original situation before the migration.

-------------------------
you could also Add a new dc to your existing domain and Add the dns role after dcpromo and replication has completed.

to make sure all DC functions are moved to the new server. Perform the dcpromo command on the old server to remove active directory and all FSMO roles from that server. when process has completed your new server Will have all AD objects and roles of the old server.

NEVER remove the old DC, without running dcpromo.exe on it. Change the dns server ip address in your DHCP scope to reflect the ip of the new server after you added the DHCP server role.

The downside of this second approach is that you cannot change back to the original situation by just switching the old server on and disconnect the new server.  though you could perform a full disk restore on the old server from a diskimage created with e.g. Symantec ghost before you added the new DC.




0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now