Solved

Demoting a Domain Controller and switching DNS server

Posted on 2015-02-03
16
180 Views
Last Modified: 2015-02-05
We have a new Microsoft Windows Server 2012 R2 Standard server that we have made a Global Catalog/Domain Controller/DNS server to replace our secondary DNS server which is a Windows 2003 Server.

We have already prepared the Forest and replication has been tested but our question is twofold. Can we run DCPROMO on the Windows 2003 and this will also get rid of DNS on the 2003 server and how can we get the end user systems to see the new secondary 2012 DNS server?

The servers and other equipment that have static IPs have been manually changed and the new server listed in the DNS entries as static but how can we quickly/easily get the rest of the equipment to see the new DNS server? IPCONFIG /FLUSHDNS?
0
Comment
Question by:regsamp
  • 7
  • 5
  • 2
  • +1
16 Comments
 
LVL 34

Accepted Solution

by:
Seth Simmons earned 167 total points
ID: 40587375
...and this will also get rid of DNS on the 2003 server

no it will not remove dns server

how can we get the end user systems to see the new secondary 2012 DNS server

change all your systems (either dhcp scope or manually if using static)
0
 
LVL 12

Expert Comment

by:Bryant Schaper
ID: 40587384
Change the DHCP scope and reboot.  The workstations need to change their logon server as well, and this happens during boot.
0
 

Author Comment

by:regsamp
ID: 40587388
Okay, so we have to use Manage Your Server in 2003 to remove DNS but where do we change the DNS secondary option in the "dhcp scope"?
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 

Author Comment

by:regsamp
ID: 40587391
The FSMO and primary DNS server is not changing as well as the logon server so do they need to change that?
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40587398
...and this will also get rid of DNS on the 2003 server
Just to be clear, when you demote a domain controller, the DNS server role does not get removed but, if you are using AD-integrated Zones the 2003 server will be removed from delegation on all of the ADI zones it was hosting.

So yes it still has the role installed but it is removed from Active Directory Integrated Zones. Any other Zones that are not AD Integrated will still remain.

Also stated, configure DHCP scopes for your clients, remove all of the client leases, this will force them to get the new settings published by DHCP.

Unfortunately you will need to manually configure any servers or workstations that are using static IP addresses for DNS.

Will.
0
 
LVL 12

Expert Comment

by:Bryant Schaper
ID: 40587402
The FSMO and primary DNS server is not changing as well as the logon server so do they need to change that?

Is the existing logon server the 2003 box?  You want them to use the new one correct?
0
 

Author Comment

by:regsamp
ID: 40587403
So should I remove the DNS option role first, change the DHCP scope with the steps below and then run the dcpromo on the 2003 server to remove it?

Open the DHCP console.
In the console tree, click the applicable scope.
On the Action menu, click Properties.
View or modify scope properties as needed.
0
 

Author Comment

by:regsamp
ID: 40587406
"Is the existing logon server the 2003 box?  You want them to use the new one correct?"

No the logon server is a totally different server that is not the existing one or the new one. The primary FSMO and DNS server right now is the logon server and we are not touching that one at all.
0
 
LVL 12

Expert Comment

by:Bryant Schaper
ID: 40587409
I would change DHCP first to get the users off DNS server.
0
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40587411
i wouldn't remove dns before doing a dcpromo
the server is probably looking to itself for dns which would be bad if you broke that
change your dhcp scope(s) to point to the new dns server and test that first before taking down anything on the 2003 server
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 167 total points
ID: 40587413
Set the DNS (on your clients and servers) to point to your primary server (before you do anything), change DHCP scope to set the Primary DNS server to the domain controller that is primary.


Open the DHCP console.
In the console tree, click the applicable scope.
On the Action menu, click Properties.
View or modify scope properties as needed.

That is correct.

Once all of your clients are pointing to the DC that will stay online you can start the demotion. Remove DNS role from the 2003 server once it is demoted.

Will.
0
 
LVL 12

Assisted Solution

by:Bryant Schaper
Bryant Schaper earned 166 total points
ID: 40587417
so just change the dhcp scope to reflect the new ones.

I think maybe we got off track, your workstations find the domain controllers by querying DNS, so if they are using the "untouched" server now, and you have that as the primary DNS, you can probably safely run dcpromo to remove the AD roles, and you can remove DNS as well if nothing is currently pointing to it as primary.
0
 

Author Comment

by:regsamp
ID: 40587419
Okay, so add the new 2012 server to the DHCP DNS Server scopes. When ready change the DHCP scope to remove the 2003/Secondary one. When we are ready, run dcpromo and then remove the DNS role from the 2003 server.
0
 
LVL 12

Expert Comment

by:Bryant Schaper
ID: 40587420
yes
0
 

Author Comment

by:regsamp
ID: 40587422
Okay, thank you!
0
 

Author Comment

by:regsamp
ID: 40587429
Okay, I will take this slow and then post anything. Thank you Will, Seth and Bryant.
0

Featured Post

Space-Age Communications Transitions to DevOps

ViaSat, a global provider of satellite and wireless communications, securely connects businesses, governments, and organizations to the Internet. Learn how ViaSat’s Network Solutions Engineer, drove the transition from a traditional network support to a DevOps-centric model.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ISP Change 14 63
Simultaneous work of Wi-Fi and LAN on Win10 laptop 4 58
PC trouble to connect to file server 6 39
DNS zone 3 28
I've written instructions for one router type, but this principle may be useful for others of the same brand and even other brands of router. Problem: I had an issue especially with mobile devices that refused to use DNS information supplied via…
Resolve DNS query failed errors for Exchange
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question