Solved

Hyper-V Domain Controller Backup

Posted on 2014-10-16
24
199 Views
Last Modified: 2014-11-12
Hey guys,

I need to take a one time backup of our 03 DC before we get ready to decom it soon. Is there a freeware tool that I can use one time that I will grab the system state too?
0
Comment
Question by:Cobra25
  • 10
  • 7
  • 4
  • +2
24 Comments
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40386072
Well as its on Hyper-V. shut down the DC and then use windows server backup on the HOST to backup the VM. Job done.
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40386085
We have 2 other VM DC's also. IF something goes sour, is that backup sufficient to restore a DC?

Also do you have a link on how perform this?
0
 
LVL 76

Expert Comment

by:arnold
ID: 40386086
Ntbackup within the Vm will backup the systemstate.
When you add the "new DC" and join it, you can transfer the roles.

Maintaing two Dcs provides for redundancy.
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40386091
So the current server (03) the backup fails when using ntbackup through the OS.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40386095
Never rely on a backup of a DC for anything except ABSOLUTE AND UTTER CATASTROPHIC FAILURE type events.  A restore of Domain Controller can make your environment even worse than not restoring it.

ALWAYS have multiple DC's running in your domain, preferably in different locations/floors/rooms so that you are covered for small disasters!

A restore of a DC that has been REMOVED from the domain will be of no use to anybody anyway.
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40386101
It is for preparation before making some changes on the DC in case of absoluter/utter failures. We cannot add new DC's until the issues are resolved! But i'd like to have something to roll back before i make registry changes/patches etc.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40386107
As your on a HYPER-V environment, take SNAPSHOTS!
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40386111
How reliable is a snapshot to rollback with other DC's in the environment?
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40386116
You can not RESTORE or ROLLBACK unless you do it to ALL DC's in the environment. You NEVER restore one DC. You rebuild it
0
 
LVL 76

Expert Comment

by:arnold
ID: 40386126
There is a lot of information missing, do you have one or multiple DC's? What is the issue, out of sync DCs?

Ntbackup is included in win2k3 use it to backup the system state which can the be used if needed.

A snapshot in a multi DC environment is not supported as a snapshot restore will trigger a RId mismatch errors.
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40386127
Here is the issue - one DC is healthy to some extent (users can authenticate to it) other 2 DC's are receiving replication info but they are missing all the contents from sysvol/netlogon folders.
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40386129
the main DC thats healthy has a journal wrap error and i would like to fix it as i believe thats what caused the sysvol/netlogon folders to be empty on the other 2 dcs.
0
Complete Microsoft Windows PC® & Mac Backup

Backup and recovery solutions to protect all your PCs & Mac– on-premises or in remote locations. Acronis backs up entire PC or Mac with patented reliable disk imaging technology and you will be able to restore workstations to a new, dissimilar hardware in minutes.

 
LVL 37

Expert Comment

by:Neil Russell
ID: 40386135
Take a snapshot of all 3 DC's and then take standard steps to remediate the Journal wrap error.  If it fails, revert ALL 3 snapshots at the same time.  This will really need to be done out of hours when NO OTHER AD changes will be made by users or admins.
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40386146
what ad changes what users make? I can take all 3 at once, thats not a bad idea.
0
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 40386162
Have you ever try do a shutdown of DC and copy all virtual machine related files as backup?
Since a DC has a tombstone time, you can not power on after 60 days without connection, but having virtual disk file, you can connect as a new drive and copy files if restoration needed. And best is totally free and no extra software required ;)
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40386163
Miguel do you have steps on it?
0
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 40386170
Pick up an external drive, connect to Hyper-v server.
On virtual machines properties, go to your virtual drives and take note where files are. Copy virtual drive files to your external drive.
If you needs files on virtual drive (recover netlogon per example) simply connect virtual drive file as a new drive on your computer (or server): http://technet.microsoft.com/en-us/magazine/ee872416.aspx
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40386183
Miguel,  that is not going to solve anything.  A snapshot in this case is for a fixed period whilst he addresses a known issue.
the 60 day limit is not an issue here, the OP is asking how to take a backup so he can TRY a fix, if it fails, revert to snapshot.

The snapshot is your option. Its safe, its quick and its free.
0
 
LVL 76

Expert Comment

by:arnold
ID: 40386783
I beleive the journal wrap error is a straight forward resolution included in the event log deals with a registry entry that allows the ad to clear it I.e. Change value from 0 to 1.
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40386836
Nothing is ever safe..I cant lose this environment
0
 
LVL 37

Accepted Solution

by:
Neil Russell earned 500 total points
ID: 40386847
So take three snapshots, set the reg value and test. If it fails revert the snapshots but power off the DC's before reverting so that each never sees the altered state later in time.
0
 
LVL 4

Author Comment

by:Cobra25
ID: 40386908
OK, thats one good option. Anything else as a second option?
0
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 40387206
So snapshots should NOT be done on DCs.  The ONLY time it's safe is in SINGLE DC environments.  Restoring a DC snapshot can cause even more problems.  What I would do is shut down the DCs that are not replicating with the one that is working.  Ensure everything still works with them shut down (or just disconnect the network connection).  Once confirmed, SHUTDOWN the Working DC and EXPORT it.  That will create a usable copy of the VM.  Then TEST IT, but when you test it, MAKE CERTAIN it's on a machine that is not connected to the same network!  Take the exported copy to another Hyper-V server elsewhere and NOT on your network and test it.  Once you confirm it boots and works, you can do whatever else you want to do with the "original" install.
0
 
LVL 76

Expert Comment

by:arnold
ID: 40387535
Imaging of DCs in a multi dc environment is not supported and discouraged by MS.
So long as you maintain the currently functional error free DCs loss of the environment is unlikly. The snapshot/imaging of
If the issue is isolated to the current primary. Transfer of roles is another option. Create a new VM so it is ready to be added as another DC, shutdown
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

David Varnum recently wrote up his impressions of PRTG, based on a presentation by my colleague Christian at Tech Field Day at VMworld in Barcelona. Thanks David, for your detailed and honest evaluation!
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now