Solved

server 2012 -  2nd DC

Posted on 2015-02-11
7
68 Views
Last Modified: 2015-02-12
Hi All,
i have setup a 2nd DC for my environment as below:
I built the 2nd sever - then added the Roles ADDS & DNS - then promoted it to a DC - followed the steps to add it too a existing domain then followed the wizard all seems ok..  after this i have made sure replication works - also on DC1 within DHCP i have added the IP for DC2 in the DNS servers - is there anything else that needs to be done?? also does below look ok?  i dont need to add the DNS IP of DC2 in DC1 do i?
DC1:
IP: 192.168.1.2
Sub:255.255.255.0
gateway: 192.168.1.1
DNS: 192.168.1.2

DC2:
IP: 192.168.1.3
sub & gateway same as DC1
DNS Primary: 192.168.1.2
DNS secondary: 192.168.1.3
0
Comment
Question by:jag b
  • 3
  • 3
7 Comments
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 250 total points
ID: 40603489
You should have a secondary IP from another DNS server in the DNS settings on the domain controller. This will mitigate the island affect if something becomes wrong with the Domain Controller in question. Same goes for DC1, it should have DNS for DC2 as a secondary.

The only other thing i would suggest if you haven't already would be to setup DC2 as a Global Catalog server as well. This is done via Sites and Services.

Check replication and health using the following commands...
repadmin /replsum
repadmin /showprepl
repadmin /bridgeheads

netdom query dc
netdom query fsmo

dcdiag /v

Because you are using DSF-R for sysvol replication I would also recommend adding the DFS role on the domain controller from there you can run health reports against the domain controllers in your environment.

If all of the tests are successful you should be fine.

Will.
0
 

Author Comment

by:jag b
ID: 40603535
will - thanks for above..
I have now added the IP of DC2 to DC1 DNS as secondary DNS..
Global Catalog is ticked on both DC's under site&services NTDS Settings...

DFS role is this only on DC2?? (DFS replication under files and services?  whats the benefit of this and is it needed?
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40603570
This is located under File Server, Distributed File System> check off DFS Replication. This allows you to run health reports, propegation tests and reports as well, from the DFS Management Console. I would recommend doing this as it is easy and useful info that is provided.

You can install this feature on both DC's.

Will.
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 

Author Comment

by:jag b
ID: 40603579
cheers mate - i havent used this before as we only have 1 file server...... nothing else needs to be done on DC2 does it?
if in the long run i wanted to get rid of DC1 can this be done? (im using a old server that has sever 2012)  or is this bad practice?
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40603626
Yeah you dont want to install the DFS namespace feature just the management feature.

if in the long run i wanted to get rid of DC1 can this be done?

You can just demote the 2012 server in the future if needed and re-promote a new 2012R2 server.

Will.
0
 
LVL 22

Assisted Solution

by:Joseph Moody
Joseph Moody earned 250 total points
ID: 40603715
I would also recommend running the AD Best Practices Analyzer on your boxes. You can do this in Server Manager: http://deployhappiness.com/best-practice-analyzer-consulant-box/
0
 

Author Closing Comment

by:jag b
ID: 40605170
excellent advice
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ticket bloat 3 49
Duplicate Computer Name with SID 3 29
How to set a value in extensionAttribute AD attribute by PowerShell? 11 42
AD issue after VM restore 5 12
Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
This article runs through the process of deploying a single EXE application selectively to a group of user.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question