Looking for Closure in a Relationship with two DCs

Posted on 2013-01-01
Medium Priority
Last Modified: 2013-01-06
I’m having difficulty retiring a failing GC / DC / Exchange Server (server1).
It’s running Windows Server 2003 with Exchange 2007 SP3.  The hardware is failing and the server needs to be replaced.  It’s a small business with 5 clients machines and a single server.

The replacement server (server2) is running Windows Server 2008 R2 with Exchange Server 2010 SP2.

I installed the replacement server; promoted it using DCPromo, set it up as a GC, transferred all FSMO roles, and enabled it as a DHCP and DNS server (and a WINS server for good measure since the clients are on XP).  Ran adprep /forestprep from the Windows Server 2008 R2 CD on server1.  There were no problems.  The login scripts automatically were synced on both servers.  I moved all the file shares and updated the login scripts to point to server2.  Users logged into and their drive mappings all point to server2 now.

Then installed Exchange 2010 SP2 on server2.  Moved the send and receive connectors from server1 to server2.  Changed the router to send 80, 25 and 443 to server2.  Moved all mailboxes.  So far so good.  Enabled Exchange to use server2 as the GC.  Tested OWA and ActiveSync.  Good to go at this point.

When I attempted to shut down server1, Exchange would not allow connections.  Users could not log into the network unless they had a hard coded IP.  Right away that pointed me towards DHCP as an issue, but the scope of server2 does not overlap with server1’s DHCP scope.  DNS is also working fine.  NSLOOKUP resolves to server2.

I have not actually done a DCPROMO on server1 to demote it to a member server in fear losing the domain, nor have I uninstalled Exchange 2007 on server1 to officially retire it.  I have done this in the past and yet somehow I feel I missed something.  Right now server1 is on life support.  Server2 cannot function unless server1 is on.

Can someone help me figure out what I  missed?


Question by:tedwill
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Expert Comment

ID: 38735503
You have to actually uninstall Exchange from the server you're taking out of the network so that the domain & Exchange forest is properly updated.  If there are any left over items or hidden gremlins hanging out in your original Exchange box you'll find out during the uninstall... hopefully you won't have any remaining items to clean up and the uninstall will flow easily... if not, don't worry... just action each item that comes up so that Exchange will uninstall properly and you'll be good... you'll be able to decommission the domain controller at that point and have a clean exit.
LVL 13

Expert Comment

ID: 38735561
sieze the FSMO's
LVL 33

Expert Comment

ID: 38735571
Are you facing an issue with Exchange or Network logins?

If its network login - troubleshooting goes to a different path, if its Exchange - again to a different path.


Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.


Expert Comment

ID: 38735582
@Exchange_Geek... I think he was pretty clear... his new DC is online and holds the FSMO roles... he brought up an Exchange 2010 SP2 install in co-existence with his original 2007 server.  Once he got everything "working" he just shut down the 2007 machine which isn't going to work... the 2007 server has to be uninstalled from the domain properly so that the 2010 server isn't still referencing it...

...it's all pretty clearly written...

Author Comment

ID: 38738477
I know that uninstalling the Exchange server will resolve the issues with Exchange, but will demoting the original resolve the issues?  I did an NTDSUTIL and saw that all five FSMO roles were on the new server.  Is there a delegation step I might have missed with DNS?

Accepted Solution

jpgobert earned 2000 total points
ID: 38738503
From what you've written it sounds like you've properly brought the new domain controller up, moved the FSMO roles, verified the FSMO roles are indeed on the new server, and you have the Exchange 2010 box working.  You've also setup the support services (DNS, WINS, DHCP) on the new controller and you've verified that those are working, correct?  Have you reviewed the event logs on the new server for any warnings or errors?  

What's the network configuration setup like?  Any special considerations in play?  Any VLANS or other advanced config details?

Have you reviewed AD Sites and Services to make sure that everything looks correct and that the new server is showing up in the site within the correct subnet?

I don't know how much you're able or willing to share but maybe posting portions of the event logs or something could give us something to review and help you track down the issue... I'd offer to join you in a Webex or Goto Assist session if you wanted to so we could check through everything... a second pair of eyes is usually the trick on things like this...

One question... have you verified for certain that DHCP & DNS are properly configured and working on the new server?  Can you create a static DHCP lease on the new server and verify that the lease works and the server responds to the client DHCP request with the right configuration?

Author Closing Comment

ID: 38749361
Thanks for the tip.  It got me started looking at DHCP.  Turns out there were issues on the old server's registry.   The new server was never properly authorized.  A "ghost" server which was decommissioned years ago was showing up as an authorized server.  I had to go into the registry to get rid of it.  Now DNS and DHCP are disabled on the old server.  The new server is serving up addresses just fine. <br /><br />Now for the nightmare of moving public folders off the old server.  Thanks for your help!

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In-place Upgrading Dirsync to Azure AD Connect
Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses
Course of the Month13 days, 21 hours left to enroll

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question