Solved

AD Test Environment

Posted on 2013-12-09
4
247 Views
Last Modified: 2013-12-13
Experts,

My company was sold and we are migrating off their network to a new one.

I have created a new AD Forest (Win2008R2) in the same subnet and our servers and desktops have migrated successfully. This exists happily in the old subnet along with the old company's live AD domain we moved away from. With a little tweaking we have accounts and shares working pretty well. We now have to switch subnets away from them to a NAT one, 192.168.100.xxx. I'd like to test this move in advance.


I'd like to test in advance by moving a "disposable" DC that will be wiped after the test to a different physical network and use the NAT network. I'd bring over a couple "disposable" workstations and a "disposable" server. This will be using a different WAN connection and would be connected to the internet separately from the old network.

I took my "disposable" DC over to the NAT network but DNS and DHCP will not start. I assume because it doesn't see the GC, have the FSMO roles, or other needed pieces.

Is there an outline of steps I would want to perform to do this test, without taking down the two live DCs on the old subnet before I'm ready?


Thoughts?
0
Comment
Question by:bschatzman
4 Comments
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 39707334
When you move a DC's (PDC or BDC) to a total isolated network/environment, you need to Seize the roles to this machine in question...

Seizing domain roles...
http://support.microsoft.com/kb/255504

Once you have done this you also need to do a metadata cleanup
http://www.msserverpro.com/metadata-cleanup-using-ntdsutil-in-windows-server-2008-r2/

Make sure that your SRV records do not associate with your other domain controllers from your production network. You can simply go do the following...
- open DNS manager
- expand domain.com
- expand _msdcs
- expand the folders and delete any entries for old DC's that are not in your "test" environment. You do this for all SRV locations Kerberos, LDAP, GC etc

Will.
0
 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 39708171
Ensure that correct dns setting is configured once the DC is moved to new network.
Best practices for DNS client settings on DC and domain members.
http://abhijitw.wordpress.com/2012/03/03/best-practices-for-dns-client-settings-on-domain-controller/

Once the IP address is changed reboot the server for registration to take place corretly.You need to seize the fsmo role once done.Check the AD sites and services are set correctly as per n/w subnet.Verify the health of DC by dcdiag /q .You also need to remove the instances of other live DC which are not move else replication failure will occur.
0
 
LVL 14

Expert Comment

by:Ram Balachandran
ID: 39708894
i am trying to understand your question, but i think you might need to configure sites and services and for DHCP you might need to configure DHCP relay agent
0
 

Author Closing Comment

by:bschatzman
ID: 39717626
This was exactly what I needed to do, and it was a success. The links were great. I'll be shutting down the test network and doing the real migration tonight. Thanks!

Bob
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
In-place Upgrading Dirsync to Azure AD Connect
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question