Solved

Upgrading from 2000 Functional Domain level to 2003 Functional domain level

Posted on 2014-07-29
6
406 Views
Last Modified: 2014-08-04
The Setup

I have a test setup in a VM environment of all our Production Domain Controllers in order to test the upgrade from Functional Forest/Domain level 2000 to 2003. We need to upgrade the level as we will be putting in a new Exchange 2013 server and this is a requirement

There are 3 VMs. We have (2) Server 2008 R2 SP1 Domain Controllers, and (1) Server 2003 R2 SP2 domain controller. In the virtual environment they all replicate to each other fine, I can open all AD service and everything works.

The Issue

As soon as I go to the First 2008 Server ( Which holds all FSMO roles, and is a Schema Master etc...The big cheese) and raise the Forest Functional level to 2003, the system states the upgrade is complete and will tell the other DC's. I then try to open ANY AD service on the same box I get and error.....

"naming information cannot be located because the target principal name is incorrect"

This is driving me nuts as I cannot figure out why this is happening. This should be very simple to do

Please help
0
Comment
Question by:TechEagle
  • 2
  • 2
  • 2
6 Comments
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40227660
could be a few possibilities
try restarting dns and netlogon services and see if that fixes it
i would also make sure there are no stale kerberos/srv records in dns

could also run dcdiag /test:checksecurityerror and see if that yields anything useful
0
 
LVL 1

Author Comment

by:TechEagle
ID: 40227686
"try restarting dns and netlogon services and see if that fixes it"

I have re-started the VMs. No effect

"i would also make sure there are no stale kerberos/srv records in dns"

What stale records would there be? These VMs were made a few days ago

"dcdiag /test:checksecurityerror"

I ran this and only thing is said was that it could not find a KDC. Everything else passed
0
 
LVL 27

Expert Comment

by:Steve
ID: 40227774
did you confirm AD was OK and replicating on your virtual environment before you raised the level?
raising the domain/forest level rarely causes any issues as long as you have removed all older DCs (which you have)
unless you didn't demote the old servers correctly (check for old servers in AD) you shouldn't really have an issue.

Perform normal DC tests (dcdiag etc) to see whats happening now and check historic event logs for AD & FRS to confirm if there was an issue BEFORE you raised the level or not.
Did you P2V these servers offline or in DS restore mode? If you P2Vd them live you may have corrupted the AD.

note: recent versions of Windows server have got smart to being P2Vd. when you first start them up after P2Ving them they put themselves into a temporary state where they wait to check their AD with another DC before functioning correctly. Great feature but a pain if you P2Ving into a test env as all of the P2Vd DCs could sit waiting to replicate with a normal DC before running properly.
0
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40228248
These VMs were made a few days ago

does this test setup mimic production?
did you take a DS backup from a domain controller and restore in the test area?
if what you have in your test environment (you said it's only a few days old) then there could be something that doesn't match production.  your test environment might fail the upgrade but the variables present may not exist in production
0
 
LVL 1

Author Comment

by:TechEagle
ID: 40228809
Yes the setup Mimics production. The only difference is that I had to change IPs on 2 of the DCs to place them on the same subnet as the First DC ( FSMO role holder ) because I cannot replicate the subnets the other two came from. ( Can only do so much with a single server and VM setups)

Even with changing the IPs, Everything Syncs ( Replicates ) in my test environment before I do the upgrade. DNS entries, Users, etc. If I create entries in either DNS or in AD Users and Computers, the changes replicate to the others. Everything seems to be Status Quo before the upgrade. After the upgrade I get the error as indicated in the original post
0
 
LVL 27

Accepted Solution

by:
Steve earned 500 total points
ID: 40229097
I've only seen issues like this when the P2V was unsuccessful, similar to the post below when trying to restore a server backup.
http://social.technet.microsoft.com/Forums/windowsserver/en-US/58a4c689-931e-42fb-b66f-817be31cf7be/error-naming-informantion-cannot-be-located?forum=winserverDS

I suspect changing the IPs around could have messed with your systems as DCs don't like too many changes but as you are sure your AD was fine we can't really do much on that possibility.

When trying to setup a test environment with multiple sites you are best to make as little changes as possible. Best way is to leave the servers as they are and just setup a spare router to route between your 2 test subnets. this way the servers don't know they have moved and assume they are on the same sites they were before. no IP changes, no messing.
Note: you can use software routers in a VM if spare hardware is a problem (eg Pfsense, clearOS etc)
0

Join & Write a Comment

New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now