[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Replace Server 2003 Domain Controller with Server 2008

Posted on 2011-10-10
15
Medium Priority
?
653 Views
Last Modified: 2012-06-22
Greetings,

Current Local Network Setup = Server 2003 Standard 32 bit File Server (our one and only Server on the Network) acting as the sole Domain Controller and managing Active Directory, DHCP, DNS. No Exchange.
15 user/Computer Network.

I need to replace the 2003 Standard File Server (remove from the Network) with a new Server 2008 Standard 64bit and have this new Server 2008 Server act as the Sole Domain Controller managing Active directory, DHCP, and DNS.

There appears to be specfic steps that need to be taken to "demote" and "promote" Domain Controllers within a Network.

My questions are:
1. Since there is a minimal amount of user data and configurations to "re-enter" into the new Server 2008 Server is it possible to simply use the same Server Name and IP address as the Server 2003 Server when setting it up the new Server 2008 Server as a Domain Controller and avoid having to perform the steps to demote / promote?

2. IF I do need to follow and impliment the demote / promote steps (Restructering?) I'd like to know the simplest steps to take to accomplish this Server Replacement.

3. Is it possible to use the same Server name and IP address on the new Server 2008 Server that is currently on the Server 2003 Server?

4. Since the AD info is outdated, are there "minimal" steps I can take to demote / promote without transferring the necessary information?  (the current Server 2003 DHCP & DNS config info is still valid)

Thank you in advance.
0
Comment
Question by:COM1
  • 4
  • 4
  • 4
  • +2
15 Comments
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 400 total points
ID: 36945888
Normally you can reuse the name/IP   and Ace has a great writeup   http://msmvps.com/blogs/acefekay/archive/2010/10/09/remove-an-old-dc-and-introduce-a-new-dc-with-the-same-name-and-ip-address.aspx

You would have to rename and reIP the current box before you could resue the names.  You can't have two machines with the same name on the network.

I went over steps here   http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_27195917.html

You should try to have 2 DCs though.  If you only have one and that goes down hard you are in a bind.

Thanks

Mike
0
 
LVL 6

Assisted Solution

by:kiwistag
kiwistag earned 400 total points
ID: 36945929
Does the new server have to be the same name as the old? I.P address is simple as it can be changed at any time (as long as you replicate the changes in the DHCP server).
Depending on your MS licensing structure upgrade from Server 2003 to Server 2008 first.

If not then your best bet is to install the Active Directory data for Server 2008 on the Server 2003 AD.
( http://www.petri.co.il/windows-server-2008-adprep.htm ). This will need to be done regardless of what step you take.
0
 

Author Comment

by:COM1
ID: 36946046
Thanks kiwistag,

No, the new Server 2008 does not have to have the same Server name...I thought it might simplify other network set ups.

 " install the Active Directory data for Server 2008 on the Server 2003 AD "
I'm confused about what you mean about installing AD data from Server 2008 on the Server 2003 Server?....do you mean running adprep then raise the functional level?

It sounds like I'll need to run adprep.exe/forestprep & adprep.exe/domainprep on the Server 2003 Server while the Server 2003 is connected to the network then raise Domain functional level on the Server 2003 to Server 2008 level (?).....then what?
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 6

Expert Comment

by:kiwistag
ID: 36946060
You do need to run adprep to "prepare" the domain structure for Server 2008's new improvements.

With Server 2008 R2 from memory is that there is tools to migrate all settings from another server (2003/2008). This includes DNS & DHCP. You'd have to read up about it though.
http://technet.microsoft.com/en-us/library/dd365353%28WS.10%29.aspx

I thought that if you wanted to upgrade the server from Server 2003 to Server 2008 (just a basic install-upgrade) it could ease the process. Your best bet may be the migration tools however.
0
 
LVL 3

Assisted Solution

by:mwiener1
mwiener1 earned 400 total points
ID: 36946113
Migration is always a safer bet.

run adprep32 /forestprep  and adprep32 /domainprep from the server 2008 disk on the old server to prepare it for the migration.

on the new server install the active directory role through server manager.

Set the new servers IP addresses statically and make sure that you point dns to the old server.

after that has been installed, you need to run dcpromo.

basically click next through the whole thing - make sure that you pick new DC in existing forest, and make sure its a Global Catalog, and that you choose to install DNS. ( i believe those are all defaults anyway)

once dcpromo is finished and the machine restarts, you'll have to transfer the FSMO roles from the other server. I find the fastest way to do this is with NTDSUtil.

From a cmd prompt, type ntdsutil

type the following all one line at a time followewd by enter key:

roles

connections

connect to server oldservername

quit

transfer infrastructure master

transfer PDC

transfer RID master

transfer schema master

quit

quit


Once that completes give it a little while to replicate all of the necessary data, since you only have a small amount of users it shouldn't take very long.  Maybe give it an hour to be safe.

after you're satisfied that you have waited long enough, run dcpromo on the old server and follow the prompts to demote it.

Install DHCP role on the new server if the old one was doing DHCP for you, and you'll be all set and can safe;y remove the old server from the network.





quit


0
 
LVL 3

Expert Comment

by:mwiener1
ID: 36946130
I forgot to mention, after the new server is promoted and before you pull down the other server, make sure you set the new servers DNS to 127.0.0.1 so it looks to itself for dns.
0
 
LVL 6

Expert Comment

by:kiwistag
ID: 36946278
with adprep also you'll have to run the 32bit version from the Server 2008 DVD. If you only have the 64bit then you'll have to source a 32bit version (I can't remember if both are on the DVD or not).
0
 
LVL 3

Expert Comment

by:mwiener1
ID: 36946333
They're both there. I gave the command for it - aprep32 /forestprep.

I just fought with that the other day for like 15 minutes until i realized there was a different file. Felt like a complete n00b.
0
 
LVL 6

Expert Comment

by:kiwistag
ID: 36946431
Ah, tired eyes. Yeah - had total hell with it in the past when we had to push the settings in for Exchange in the past, got caught there too.
COM1: what do you use for e-mail on that network?
0
 

Author Comment

by:COM1
ID: 36946591
Thanks Kiwistag & mwiener1....I appreciate your time!

kiwistag: We are using Google Apps (Paid)  for Business for our email.

mwiener1: I am confused...in your first post  you mention running dcpromo on the S2k3 Server twice at separate points...once after running adprep32 and then again after running NTDSUtil (?).

Also, which Server do I run the NTDSUtil from?...it sounds like I would run it from the 2003 Server side....if this is the case does it at some point ask for static IP of new DC?....."make sure that you pick new DC in existing forest" = the time you designate IP address of new DC?



0
 
LVL 24

Accepted Solution

by:
Sandeshdubey earned 800 total points
ID: 36946921
Here is the complete guide how to migart 2008 DC.

There are a couple of very important considerations, that you should have in mind, before you proceed with your migration scenario.

--Check, and raise, if necessary, the Domain and Forest functional levels. You cannot upgrade directly from Windows 2000 mixed, or Windows Server 2003 interim domain functional levels.

--The first Windows Server 2008 Domain Controller in the forest must be a Global Catalog Server, and it cannot be a Read Only Domain Controller, RODC.

--Check the FSMO roles assignments. When you prepare the existing AD, you should run adprep /forestprep on the Schema operations master, and adprep /domainprep /gpprep on the infrastructure master.In your case as there is a single Dc you need to run on the same server.

The installation of Windows 2008 into the domain and migration is quite simple.
First you need to Adprep your 2003 Domain by running
adprep /forestprep    and
adprep /domainprep   and
adprep /gpprep
from the 2008 DVD on the Windows 2000 DC  - adprep is in the SOURCES folder on the DVD.

Next install 2008 server on the new machine. You need to assign the 2008 new computer an IP address and subnet mask on the existing network. Make sure that the preferred DNS server on new machine points to the existing DNS Server on the Domain (normally the existing domain controller)

Join the new 2008 machine to the existing domain as a member server

From the command line promote the new machine to a domain controller with the DCPROMO command from the command line Select "Additional Domain Controller in an existing Domain"

Once Active Directory is installed then to make the new machine a global catalog server, go to Administrative Tools, Active Directory Sites and Services, Expand, Sites, Default first site and Servers. Right click on the new server and select properties and tick the"Global Catalog" checkbox. (Global catalog is essential for logon as it needs to be queried to establish Universal Group Membership)

Install DNS on the new server. Assuming that you were using Active Directory Integrated DNS on the first Domain Controller, DNS will automatically replicate to the new domain controller along with Active Directory. Set up forwarders as detailed at http://www.petri.co.il/configure_dns_forwarding.htm

You must transfer the FSMO roles to the 2008 machine then the process is as outlined at http://www.petri.co.il/transferring_fsmo_roles.htm

Change all of the clients (and the new 2008 DC itself), to point to the 2008 DC for their preferred DNS server this may be in DHCP options or the TCP/IP settings.

You can then transfer any data to the new server.

Before removing the old DC from the domain, run DCPROMO on it to remove Active Directory.


0
 
LVL 3

Expert Comment

by:mwiener1
ID: 36948050
You run adprep on old server, dcpromo on new server to promote, and then dcpromo on old server to demote.
0
 

Author Comment

by:COM1
ID: 36950440
Thank you kiwistag,mwiener1 & Sandeshdubey.

mwiener1: thanks for clarification of dcpromo...got it

Sandeshdubey: VERY thourough info, thank you.

It all comes together when combing info from all 3 contributing  experts!

It appears relinqiushing control is tricky business....whether your a Domain Controller or Dictator of a county!

Thank you all for contributing. I will execute the DC change over & impliment all provided info this weekend
0
 

Author Closing Comment

by:COM1
ID: 36950471
Forgot to thank the 4th expert, mkline71 for  his input and links.
Thank you all again for your contributions.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 36950506
no problem, just glad you were helped

Thanks

Mike
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question