?
Solved

Disaster recovery scenario with a Seize Role

Posted on 2014-12-03
6
Medium Priority
?
162 Views
Last Modified: 2014-12-17
Hi Experts,

We are having a disaster recovery exercise soon. Scenario as follows:

1 forest domain with 2 active sites and a DR site.
Currently Site A (2 DCs with one DC holding all 5 roles) is in active replication/sync with Site B (2 DC). However in a disaster recovery scenario of site B to be down, a disaster site named site C with 1 DC will be up with a backed up data of Site B.

The DC with the5 FSMO roles will then be shut down (to create a scenario of FSMO role holder crashed). DC in site C will seize all roles.

Question is, after DC in site C seize roles, will it still be able to recognise other the other DC in Site A which is still alive? Or a restore is also needed for the DC in Site A? Basically what I'm trying to find out is that, if a DC seized all the FSMO roles, will it still be able to recognise other DCs in other sites and what needs to be done if it can recognize and if it can't does it mean we have to restore all other DCs?

Thanks in advance
0
Comment
Question by:Ali_Junior
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
6 Comments
 
LVL 7

Expert Comment

by:Network Zero
ID: 40480079
I'm going to quote Microsoft on this "  domain controller whose FSMO roles have been seized should not be permitted to communicate with existing domain controllers in the forest. In this scenario, you should either format the hard disk and reinstall the operating system on such domain controllers or forcibly demote such domain controllers on a private network and then remove their metadata on a surviving domain controller in the forest by using the ntdsutil /metadata cleanup command. The risk of introducing a former FSMO role holder whose role has been seized into the forest is that the original role holder may continue to operate as before until it inbound-replicates knowledge of the role seizure. Known risks of two domain controllers owning the same FSMO roles include creating security principals that have overlapping RID pools, and other problems."

Reference KDB: http://support.microsoft.com/KB/255504
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40480181
Firstly you say that you are using a " with 1 DC will be up with a backed up data of Site B. "
If that means you will try and restore a backup of a DC from B to C then you will fail.

Also as stated, a DC that has had all its roles Seized while offline should NEVER be switched back on. It will cause all kind of issues on your network.
0
 

Author Comment

by:Ali_Junior
ID: 40482096
Thanks for the input, but I think I might have confused you guys :-P

1. The DC which has it's roles seized will not be introduced back to the forest. It will be formatted and re-introduced.
2. The site C is basically a physical site which when brought up into the scenario as the disaster site will be the exact copy of DCs from site B (since site B will be deemed down).

All I needed to confirm is that the remaining Dcs that are alive, can it communicate to the DC that has seized the role.

Thanks.
0
The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

 

Author Comment

by:Ali_Junior
ID: 40482098
To add on to Point 1. the formatted DC will only be introduced after the disaster recovery exercise is done and situation has been normalized. It will not be brought up during the exercise.
0
 
LVL 37

Accepted Solution

by:
Neil Russell earned 750 total points
ID: 40482111
Any DC can communicate with any other DC so long as there are network links. You will have to ensure that all of the roles are siezed and away you go :)
0
 
LVL 7

Assisted Solution

by:Network Zero
Network Zero earned 750 total points
ID: 40482131
This is where I think we are confused:

The DC which has it's roles seized will not be introduced back to the forest. It will be formatted and re-introduced.

if the DC in the domain being seized and then is going to be formatted there's going to be no communcation.

Say that site B blew up..

You have 3 DC's   1\ your seizing and formatting number 2 is gone and C is the backup

So there are no DC's left since you will be formatting DC1 and then it will be able to communicate with DC3 once it has been restored normally.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
Suggested Courses
Course of the Month9 days, 3 hours left to enroll

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question