?
Solved

windows server r2 2008 Creating new dc on existing forest 2003

Posted on 2011-10-05
17
Medium Priority
?
1,342 Views
Last Modified: 2012-05-12
I am trying to install new ms server 2008 r2 DC into the ms server 2003 enviroment. When running "adprep /forestprep" I am getting the below message.

Adprep was unable to extend the schema.
[Status/Consequence]
The schema master did not complete a replication cycle after the last reboot. Th
e schema master must complete at least one replication cycle before the schema c
an be extended.
[User Action]
Verify that the schema master is connected to the network and can communicate wi
th other Active Directory Domain Controllers.  Use the Sites and Services snap-i
n to replicate between the schema operations master and at least one replication
 partner. After replication has succeeded, run adprep again.


what is wierd...is that there is only one DC in my enviroment. so i just dont understand what is going on.

the windows server 2003 is my DC/DNS/AD/exchange.

PLEASE HELP EXPERTS!!!
0
Comment
Question by:decoded
  • 7
  • 3
  • 3
  • +3
17 Comments
 
LVL 2

Expert Comment

by:Aquatone
ID: 36921910
Are you doing this on the first DC in the domain?

http://technet.microsoft.com/en-us/library/cc771461(WS.10).aspx
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 36921911
Is your 2003 box 32 or 64 bit.  If 32 bit use adprep32

Wer there ever any other DCs on the network?

Thanks

Mike
0
 
LVL 6

Expert Comment

by:-tjs
ID: 36921916
As mkline suggests it's possible that your one and only DC believes there is another one it should have replicated with.  Try running repadmim /showreps from your DC to see.  If an old DC is listed, search the Microsoft KB for metadata cleanup.
0
Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

 

Author Comment

by:decoded
ID: 36921918
I am using adprep32 below is my command line:

C:\Temp\adprep>adprep32 /forestprep

i want to keep both DC. i just want the second server(win server 2008) as some type of redunancy.
0
 

Author Comment

by:decoded
ID: 36921927
Below is: .repadmin /showreps

C:\Program Files\Support Tools>repadmin /showreps
Default-First-Site-Name\EXCHANGE
DC Options: IS_GC
Site Options: (none)
DC object GUID: a5c258fd-73f5-4119-aaac-e5f68d0ef325
DC invocationID: 85f6980b-812d-4a42-ae1e-bf85e7a622ec

==== INBOUND NEIGHBORS ======================================

DC=dawsonjames,DC=local
    Default-First-Site-Name\SERVER via RPC
        DC object GUID: adc142a2-fe7a-4867-9642-f17053611c60
        Last attempt @ 2011-10-05 20:55:07 failed, result 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.
        33752 consecutive failure(s).
        Last success @ 2007-11-30 16:58:14.
    Default-First-Site-Name\FILESERVER via RPC
        DC object GUID: 8941e33e-d29e-40b5-b79c-e457268e8645
        Last attempt @ 2011-10-05 20:55:22 failed, result 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.
        9870 consecutive failure(s).
        Last success @ 2010-08-21 10:48:12.

CN=Configuration,DC=dawsonjames,DC=local
    Default-First-Site-Name\SERVER via RPC
        DC object GUID: adc142a2-fe7a-4867-9642-f17053611c60
        Last attempt @ 2011-10-05 20:55:09 failed, result 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.
        33751 consecutive failure(s).
        Last success @ 2007-11-30 16:21:04.
    Default-First-Site-Name\FILESERVER via RPC
        DC object GUID: 8941e33e-d29e-40b5-b79c-e457268e8645
        Last attempt @ 2011-10-05 20:55:13 failed, result 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.
        9870 consecutive failure(s).
        Last success @ 2010-08-21 10:34:44.

CN=Schema,CN=Configuration,DC=dawsonjames,DC=local
    Default-First-Site-Name\SERVER via RPC
        DC object GUID: adc142a2-fe7a-4867-9642-f17053611c60
        Last attempt @ 2011-10-05 20:55:11 failed, result 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.
        33751 consecutive failure(s).
        Last success @ 2007-11-30 15:59:19.
    Default-First-Site-Name\FILESERVER via RPC
        DC object GUID: 8941e33e-d29e-40b5-b79c-e457268e8645
        Last attempt @ 2011-10-05 20:55:16 failed, result 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.
        9871 consecutive failure(s).
        Last success @ 2010-08-21 08:55:52.

DC=DomainDnsZones,DC=dawsonjames,DC=local
    Default-First-Site-Name\SERVER via RPC
        DC object GUID: adc142a2-fe7a-4867-9642-f17053611c60
        Last attempt @ 2011-10-05 20:55:18 failed, result 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.
        33752 consecutive failure(s).
        Last success @ 2007-11-30 15:59:20.
    Default-First-Site-Name\FILESERVER via RPC
        DC object GUID: 8941e33e-d29e-40b5-b79c-e457268e8645
        Last attempt @ 2011-10-05 20:55:25 failed, result 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.
        9870 consecutive failure(s).
        Last success @ 2010-08-21 10:46:15.

DC=ForestDnsZones,DC=dawsonjames,DC=local
    Default-First-Site-Name\SERVER via RPC
        DC object GUID: adc142a2-fe7a-4867-9642-f17053611c60
        Last attempt @ 2011-10-05 20:55:20 failed, result 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.
        33752 consecutive failure(s).
        Last success @ 2007-11-30 15:59:20.
    Default-First-Site-Name\FILESERVER via RPC
        DC object GUID: 8941e33e-d29e-40b5-b79c-e457268e8645
        Last attempt @ 2011-10-05 20:55:27 failed, result 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.
        9871 consecutive failure(s).
        Last success @ 2010-08-21 08:55:52.

Source: Default-First-Site-Name\FILESERVER
******* 9871 CONSECUTIVE FAILURES since 2010-08-21 10:48:12
Last error: 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.

Source: Default-First-Site-Name\SERVER
******* 33752 CONSECUTIVE FAILURES since 2007-11-30 16:58:14
Last error: 8524 (0x214c):
            The DSA operation is unable to proceed because of a DNS lookup failu
re.

C:\Program Files\Support Tools>


Those server dont exist those server are DIED...Any ideas guys
0
 
LVL 2

Expert Comment

by:Aquatone
ID: 36921933
Even if the server is no longer in use, if it was at one point a DC, it has to be removed from the directory (metadata clenaup)
0
 

Author Comment

by:decoded
ID: 36921941
How do I run metadata cleanup if server doesnt exisit?
0
 
LVL 2

Expert Comment

by:Aquatone
ID: 36921948
Did a second server ever exist at some point in the past?

http://technet.microsoft.com/en-us/library/cc736378(WS.10).aspx

Dust-off ntdsutil
0
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36921966
This error indicates that there are AD replication problems in the environment. In order to continue the replication issue must be resolved.

1. Make sure that user is schema admin or log on as a Schema Admin (the Administrator of the forest root domain has this role by default).
2. As other said, you need to run ADPREP or ADPREP32(If 2k3 DC is 32bit) on existing 2003 domain controller.
3. To check what replication problems you are having install your Windows Support tools and run Repadmin /Showrepl or Repadmin /Showreps on the Schema Master. This should show you which DC’s you are having problems with.

Once you have determined the DC (s) that has the problem, check to see if you can connect to \\server(servername) and \\FQDN(servername)

If both are unsuccessful then you may have a networking problem, a broken secure channel or a 5 minute time difference between the two machines.

If one is unsuccessful you have a networking problem involving DNS or Netbios name resolution.

If both are successful:

On both the DC that is not replicating with the Schema Master as well as the Schema Master: On both DC's TCP Nic properties point DNS to iteslf or local DNS server , On 2003 At a cmd prompt type Netdiag /fix

Also run ipconfig /all, dcdiag /q , netdiag /q and repadmin /replsum on 2003 DC post result.

Regards,
Abhijit Waikar.
0
 

Author Comment

by:decoded
ID: 36921986
Dust-off ntdsutil ? not sure how to run that command
0
 

Author Comment

by:decoded
ID: 36922023
Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\Administrator.domainname>ntdsutil
ntdsutil:
ntdsutil: metadata cleanup
metadata cleanup:
metadata cleanup: remove selected server
Binding to localhost ...
Connected to localhost using credentials of locally logged on user.
Unable to determine the domain hosted by the DC (1). Please use the connection m
enu to specify it.
metadata cleanup: remove selected server server
A global connection already exists. No arguments should be specified.
metadata cleanup: remove selected server fileserver
A global connection already exists. No arguments should be specified.
metadata cleanup: ntd^C
C:\Documents and Settings\Administrator.domainname>ntdsutil
ntdsutil: metadata cleanup
metadata cleanup: remove selected server server
Binding to localhost ...
Connected to localhost using credentials of locally logged on user.
LDAP error 0x22(34 (Invalid DN Syntax).
Ldap extended error message is 0000208F: NameErr: DSID-031001BA, problem 2006 (B
AD_NAME), data 8350, best match of:
        'CN=Ntds Settings,server'

Win32 error returned is 0x208f(The object name has bad syntax.)
)
Unable to determine the domain hosted by the DC (5). Please use the connection m
enu to specify it.
Disconnecting from localhost...
metadata cleanup: remove selected server fileserver
Binding to localhost ...
Connected to localhost using credentials of locally logged on user.
LDAP error 0x22(34 (Invalid DN Syntax).
Ldap extended error message is 0000208F: NameErr: DSID-031001BA, problem 2006 (B
AD_NAME), data 8350, best match of:
        'CN=Ntds Settings,fileserver'

Win32 error returned is 0x208f(The object name has bad syntax.)
)
Unable to determine the domain hosted by the DC (5). Please use the connection m
enu to specify it.
Disconnecting from localhost...
metadata cleanup:
0
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36922072
Check this to perform metadata cleanup: http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Regards,
Abhijit Waikar.
0
 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 36922130
You need to remove the old Dc's which are not in the network by performing metadata cleanup
follow this Microsoft KB http://support.microsoft.com/kb/216498.

Once done you can proceed with installation of 2008 DC below are the steps:


The installation of Windows 2008 into the domain and migration is quite simple.
First you need to Adprep your 2003 Domain by running
adprep /forestprep    and
adprep /domainprep   and
adprep /gpprep

from the 2008 DVD on the Windows 2003 DC  - adprep is in the SOURCES folder on the DVD.

Next install 2008 server on the new machine. You need to assign the 2008 new computer an IP address and subnet mask on the existing network. Make sure that the preferred DNS server on new machine points to the existing DNS Server on the Domain (normally the existing domain controller)

Join the new 2008 machine to the existing domain as a member server

From the command line promote the new machine to a domain controller with the DCPROMO command from the command line Select "Additional Domain Controller in an existing Domain"

Once Active Directory is installed then to make the new machine a global catalog server, go to Administrative Tools, Active Directory Sites and Services, Expand, Sites, Default first site and Servers. Right click on the new server and select properties and tick the"Global Catalog" checkbox. (Global catalog is essential for logon as it needs to be queried to establish Universal Group Membership)

If necessary install DNS on the new server. Assuming that you were using Active Directory Integrated DNS on the first Domain Controller, DNS will automatically replicate to the new domain controller along with Active Directory. Set up forwarders as detailed at http://www.petri.co.il/configure_dns_forwarding.htm

You must transfer the FSMO roles to the 2008 machine then the process is as outlined at http://www.petri.co.il/transferring_fsmo_roles.htm

You then need to install DHCP on the new 2008 server (if used) and set up a scope, activate it and authorize the server.

Change all of the clients (and the new 2008 DC itself), to point to the 2008 DC for their preferred DNS server this may be in DHCP options or the TCP/IP settings.

You can then transfer any data to the new server.

Refernce article:
http://araihan.wordpress.com/2009/08/25/migrate-from-windows-2003-active-directory-to-windows-2008-active-directory-step-by-step/
http://markswinkels.nl/2009/01/08/how-to-migrate-a-domain-controller-from-windows-2003-to-windows-2008/
0
 

Author Comment

by:decoded
ID: 36924591
Sandeshdubey

that is my problem....how can i run metadata cleanup if i cant connect to old dc?

i get the below problem


C:\Documents and Settings\Administrator.domainname>ntdsutil
ntdsutil: metadata cleanup
metadata cleanup: remove selected server server
Binding to localhost ...
Connected to localhost using credentials of locally logged on user.
LDAP error 0x22(34 (Invalid DN Syntax).
Ldap extended error message is 0000208F: NameErr: DSID-031001BA, problem 2006 (B
AD_NAME), data 8350, best match of:
        'CN=Ntds Settings,server'

Win32 error returned is 0x208f(The object name has bad syntax.)
)
Unable to determine the domain hosted by the DC (5). Please use the connection m
enu to specify it.
Disconnecting from localhost...
metadata cleanup: remove selected server fileserver
Binding to localhost ...
Connected to localhost using credentials of locally logged on user.
LDAP error 0x22(34 (Invalid DN Syntax).
Ldap extended error message is 0000208F: NameErr: DSID-031001BA, problem 2006 (B
AD_NAME), data 8350, best match of:
        'CN=Ntds Settings,fileserver'

Win32 error returned is 0x208f(The object name has bad syntax.)
)
Unable to determine the domain hosted by the DC (5). Please use the connection m
enu to specify it.
Disconnecting from localho
0
 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 36928233
To ran metadata cleanup you need to connect to online dc not offline dc.

Refer below article step by step details are given:
http://www.petri.co.il/delete_failed_dcs_from_ad.htm
http://support.microsoft.com/kb/216498
0
 
LVL 10

Accepted Solution

by:
abhijitwaikar earned 2000 total points
ID: 36928468
that is my problem....how can i run metadata cleanup if i cant connect to old dc?
@decoded: I am sure that you did not check the earlier petri link for metadata cleanup, everything is there with GUI,

As per your posted result above, you are not following proper steps and one IMP thing is always connect any functional domain controller in the same domain in at the server connections prompt.

C:\Documents and Settings\Administrator.domainname>ntdsutil
ntdsutil: metadata cleanup
metadata cleanup: remove selected server server - Invalid command

Correct parameter-
metadata cleanup: connections
server connections:
server connections: connect to server server001 (any functional domain controller)
Binding to server100 ...
Connected to server100 using credentials of locally logged on user.
server connections:

Here is again a petri article just go through it and perfrom metadata cleanup:
http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Once you are done with metadatacleanup then go for new server installation

The 2003 and 2008 R2 DCs can happily co-exist.  You just won't be able to raise your domain and forest functional levels to 2008 R2 until every DC is at 2008 R2, Replication will work fine with no issues.  

Quick high level steps.
1.  Prep your forest and domain.  The 2008 R2 prep for has an adprep32 and adprep.  If your 2003 box is x32 then you use adprep32.
2.  Install a 2008 R2 member server (this could have also been step 1)
3.  Use dcpromo to promote the box
4.  By default the 08 dcpromo will make it a global catalog also make it a DNS server
5.  After the reboot make sure replication is working
6.  Once you are ok with that and made sure AD/DNS replication is working (assuming you are using AD integrated DNS) then check sysvol
7.  Transfer FSMO roles to the box
8.  Make sure clients (static and DHCP) are now also pointing to the 2008  box for DNS
9.  Confirm you are ok with the 2008 R2 box and that everything is working
10. Then you are alright.

Optional steps:
--you can run dcpromo and demote the 2003 boxes if you want otherwise leave it.
--Once you know you will never need or introduce another 2003 DC then you can raise your domain and forest functional levels to 2008 R2
--New coll features are available in 2008r2 functional levels, like the AD recycle bin, fine-grained passwords.

Meinolf also has a great blog entry on this topic
http://msmvps.com/blogs/mweber/archive/2010/02/10/upgrading-an-active-directory-domain-from-windows-server-2003-to-windows-server-2008-or-windows-server-2008-r2.aspx

Thanks
Abhijit Waikar.
0
 

Author Closing Comment

by:decoded
ID: 36957024
Perfect
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Suggested Courses

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question