Solved

domain controller migration

Posted on 2014-07-31
16
165 Views
Last Modified: 2014-09-13
I have one domain controller.  I plan to add another soon, however, I need to migrate this one to a different ESXi host.  I plan to power off my Exchange server before doing so...  But..  Do I need to power off my file server, SQL server,  and web server before doing so?   Will those at least function or will the users not be able to access the file share?  The only few users connected will already be authenticated.
0
Comment
Question by:gopher_49
  • 7
  • 5
  • 3
  • +1
16 Comments
 
LVL 62

Accepted Solution

by:
gheist earned 500 total points
ID: 40231765
Best is to add other domain controller and move one by one.
0
 
LVL 119
ID: 40231836
You have a single DC, and you are going to turn it off ?

If you turn it off, prepare for a world, of authentication issues, whilst it's off, if any services require AD.

You would be better OFF, having a complete power down, to avoid issues.

Or do it, and live through the issues! (if any occur!)
0
 
LVL 62

Expert Comment

by:gheist
ID: 40231850
Each file server will revalidate kerberos ticket of user once in a while, maybe try at least off-hours...
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:gopher_49
ID: 40231857
I figured it might cause issues.. Even if it's only for a few mins..  I'm spinning up another DC and adding it's IP as a secondary DNS server to the NICs of all servers.  I guess that will be the easiest solution.  That way I can migrate the old DC.  Right?  Do I need to change any roles prior to this?
0
 
LVL 62

Expert Comment

by:gheist
ID: 40231879
Just popped in my mind - make a new virtual server a second domain controller, transfer roles, though what leaves me confused - better call microsoft support and ask how to quickly transfer the activation/licences.
0
 
LVL 119
ID: 40231880
That should be fine.
0
 

Author Comment

by:gopher_49
ID: 40235693
We lease our licenses so that's not a problem.   What roles do I really need to transfer?  I know technically it should fail over even without transferring roles..  But.  I'd prefer to do it properly.  Do I need to transfer all roles?  I guess this is the safest.
0
 
LVL 62

Expert Comment

by:gheist
ID: 40235805
just schema master...
0
 
LVL 119
ID: 40236093
Adding another DC is fine, but the issue you will always have, is a client/user has authenticated against DC1, and DC1 is not available because it's off, it will always go back to the DC, it first authenticated against, even if you have a DC2.

I would just shutdown everything, and tell users, scheduled maintenance.

Also, what issues IP Addresses ?
0
 
LVL 62

Expert Comment

by:gheist
ID: 40236099
Adding DC lets sstrech the whole migration in couple of days without significant impact. Want it or not users log out every night, so one day add new server, next day move schema master, other day power off old DC, another clean it from domain.
0
 
LVL 2

Expert Comment

by:great_gentle_man
ID: 40238280
hi,

if you can provide answer to below questions we might be able to help

Are you a 24x7 operation? if not what are your off hours.
How many users are you supporting?
How much time do you have? i.e dead line for migrating your dc from one host to another.
Are your vm-ware hosts located in house or on the cloud?
0
 

Author Comment

by:gopher_49
ID: 40321226
We are mainly a 8x5 operation except for my Exchange users.  I'll spin up a new DC and add the new DC to all servers NIC cards and then migrate.
0
 
LVL 62

Expert Comment

by:gheist
ID: 40321233
Day 1: add 2nd DC
Day 2: migrate network devices to use 2nd DC
Day 3: switch roles
Day 4: power off old DC and remove from AD....
0
 

Author Comment

by:gopher_49
ID: 40321345
I'll move everything to use the 2nd DC as the primary DNS server.  I'll then start the role transfer.  Verify it's complete via event logs and then power down the old DC and migrate.
0
 

Author Comment

by:gopher_49
ID: 40321409
I got the attached error when running DCPROMO.
DNS-delegation-error.png
0
 
LVL 62

Expert Comment

by:gheist
ID: 40321438
.local is not a legal domain name, so you need to do what message says...
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
vmdk greater than 2TB 2 57
Clone VM with existing snapshot via Putty 2 53
What is the best method for LongTermArchival of a VM 13 67
VMWare & 2008 R2 Domain Controllers 3 53
Will try to explain how to use the VMware feature TAGs in the VMs and create Veeam Backup Jobs using TAGs. Since this article is too long, I will create second article for the Veeam tasks.
In this article, I will show you HOW TO: Create your first Windows Virtual Machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, the Windows OS we will install is Windows Server 2016.
Teach the user how to use configure the vCenter Server storage filters Open vSphere Web Client:  Navigate to vCenter Server Advanced Settings: Add the four vCenter Server storage filters: Review the advanced settings: Modify the values of the four v…
Teach the user how to install and configure the vCenter Orchestrator virtual appliance Open vSphere Web Client: Deploy vCenter Orchestrator virtual appliance OVA file: Verify vCenter Orchestrator virtual appliance boots successfully: Connect to the …

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question