burbankmarc wrote: » Hey all, I frequent the Cisco and Linux forums here but I have an MS question. I am not an MS guy so you might have to talk slowly to me. Anyways, I want to upgrade my domain controllers from 2000/2003 to 2008 R2. I first want to test this upgrade process. I installed server 2000 on a PC added it to the domain and made a domain controller. I then had a complete copy of the AD forrest so that was cool. I then moved it to a private network and stuff stopped working. I wasn't able to do anything for AD because it couldn't contact the other domain controllers, so I seized control of all the roles I could hoping that would be it. Well it wasn't and now it seems to work even less. So my question is how do you pull a working Domain Controller and move it to a private LAN for testing?
burbankmarc wrote: » Ok, so maybe I can't just pull it from a live environment and throw it onto a test environment, but is there a way I can export the AD on the live servers and import it onto my test machine?
Mojo_666 wrote: » Well if you allowed it to replicate it should have a copy already, that's how it works, or am I not understanding what you have done?
Mojo_666 wrote: » BTW I would also advise a transitional migration not an upgrade, unless you have a reason for doing so.
burbankmarc wrote: » Ha, well I tried the metadata cleanup, but the servers weren't listed so I didn't have anything to clean. Now, however I cannot even connect to AD. I guess I'll have to wipe the system and start again, no biggie. Well that's what I was banking on, the replication, which worked perfectly. However, I didn't know that if you pulled it off the network it would break everything. I guess I was curious if I could just export AD from one network then import it to my test machine. Well I don't know what that means, but sure. I just want to get off these old OS's. So whichever way works best is fine by me.
ajs1976 wrote: » What DNS server is your test box pointing to? Itself or one of the other DCs?
Mojo_666 wrote: » Well you can get it going, all these things are fixable it's just how much time and effort do you want to spend doing so? I have a few hours to help but you might be better of starting from scratch as its a lab setup...your call. Transitional means just that you transition over to 2008, so you would basically build a 2008 DC on to your domain MOVE roles to it, get it all working then decom an old server, rebuild it to 2008 make it a DC and so on until all your DC's are 2008 rather than what is effectivly an OS upgrade.....make sense?
burbankmarc wrote: » Word up, it was the DNS. I can connect to AD and make changes. I removed all the "failed" DCs. So now my test machine is the only one. Now, as a test I tried adding my test 2008 server to the domain, but it failed out. It says it can't find the domain. It's DNS server is pointed to the server 2000 test machine.
Mojo_666 wrote: » Happy days, first thing make sure the 2000 box is working ok, no events etc, dcdiag looking ok and so on, make sure you have no firewall running then try again, but again check the ip config of the 2008 box, it needs to be on the same subnet or have a route and it needs to be looking at the dns servers of the domain you are wanting to join etc.
Mojo_666 wrote: » But make sure the 2000 box is ok as above, maybe even give it a reboot for good luck.
Domain Controller Diagnosis Performing initial setup: Done gathering initial info. Doing initial required tests Testing server: MAPCOM\MAPCOM-HQ-06 Starting test: Connectivity MAPCOM-HQ-06's server GUID DNS name could not be resolved to an IP address. Check the DNS server, DHCP, server name, etc Although the Guid DNS name (0d46c4b3-096f-4a20-af69-410cc72cdcbe._msdcs.mapcom.local) couldn't be resolved, the server name (mapcom-hq-06.mapcom.local) resolved to the IP address (172.18.1.1) and was pingable. Check that the IP address is registered correctly with the DNS server. ......................... MAPCOM-HQ-06 failed test Connectivity Doing primary tests Testing server: MAPCOM\MAPCOM-HQ-06 Skipping all tests, because server MAPCOM-HQ-06 is not responding to directory service requests Running enterprise tests on : mapcom.local Starting test: Intersite ......................... mapcom.local passed test Intersite Starting test: FsmoCheck Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355 A Global Catalog Server could not be located - All GC's are down.
Domain Controller Diagnosis Performing initial setup: Done gathering initial info. Doing initial required tests Testing server: MAPCOM\MAPCOM-HQ-06 Starting test: Connectivity ......................... MAPCOM-HQ-06 passed test Connectivity Doing primary tests Testing server: MAPCOM\MAPCOM-HQ-06 Starting test: Replications ......................... MAPCOM-HQ-06 passed test Replications Starting test: NCSecDesc ......................... MAPCOM-HQ-06 passed test NCSecDesc Starting test: NetLogons ......................... MAPCOM-HQ-06 passed test NetLogons Starting test: Advertising Fatal Error:DsGetDcName (MAPCOM-HQ-06) call failed, error 1355 The Locator could not find the server. ......................... MAPCOM-HQ-06 failed test Advertising Starting test: KnowsOfRoleHolders ......................... MAPCOM-HQ-06 passed test KnowsOfRoleHolders Starting test: RidManager ......................... MAPCOM-HQ-06 passed test RidManager Starting test: MachineAccount ......................... MAPCOM-HQ-06 passed test MachineAccount Starting test: Services ......................... MAPCOM-HQ-06 passed test Services Starting test: ObjectsReplicated ......................... MAPCOM-HQ-06 passed test ObjectsReplicated Starting test: frssysvol Error: No record of File Replication System, SYSVOL started. The Active Directory may be prevented from starting. There are errors after the SYSVOL has been shared. The SYSVOL can prevent the AD from starting. ......................... MAPCOM-HQ-06 passed test frssysvol Starting test: kccevent ......................... MAPCOM-HQ-06 passed test kccevent Starting test: systemlog An Error Event occured. EventID: 0x8000003E Time Generated: 08/18/2010 14:16:03 Event String: This Machine is a PDC of the domain at the root ......................... MAPCOM-HQ-06 failed test systemlog Running enterprise tests on : mapcom.local Starting test: Intersite ......................... mapcom.local passed test Intersite Starting test: FsmoCheck Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355 A Global Catalog Server could not be located - All GC's are down. Warning: DcGetDcName(TIME_SERVER) call failed, error 1355 A Time Server could not be located. The server holding the PDC role is down. Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 1355 A Good Time Server could not be located. Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1355 A KDC could not be located - All the KDCs are down. ......................... mapcom.local failed test FsmoCheck ................ mapcom.local passed test Intersite Starting test: FsmoCheck Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355 A Global Catalog Server could not be located - All GC's are down. Warning: DcGetDcName(TIME_SERVER) call failed, error 1355 A Time Server could not be located. The server holding the PDC role is down. Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 13 A Good Time Server could not be located. Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1355 A KDC could not be located - All the KDCs are down. ......................... mapcom.local failed test FsmoCheck are down. ......................... mapcom.local failed test FsmoCheck
burbankmarc wrote: » Ok well I noticed that I didn't even have DNS services installed. So I installed them and ran dcdiag again, now almost all the tests are passing. I'm still getting an FSMO 1355 error though....lemme grab the output and post it.
burbankmarc wrote: » Cool thanks for all the help. This has been pretty informative. Still cannot connect though. I tried the full domain too of mapcom.local. If I ping mapcom.local from my 2008 server it returns the address of the 2000 DC.
burbankmarc wrote: » It says "AD DC for domain mapcom.local could not be contacted" -paraphrased. dcdiag /test:dns - tells me that isn't a valid test. The FSMO test is still failing, though.
Starting test: FsmoCheck Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error A Global Catalog Server could not be located - All GC's are down.
burbankmarc wrote: » [code] It tells me to "remove any stale conflicting account"