PC Review


Reply
Thread Tools Rate Thread

Configuration 2nd DC

 
 
Paolo
Guest
Posts: n/a
 
      28th Nov 2005
Hi,

I want to configure a second domain controller in our windows 2000
domain. The main reason for this is to have a "backup" of the
users/groups/policies. Replication just has to work from DC # 1 to DC #
2 and not the other way around. What I also want is that the first DC
stays the logonserver and that the second (new) dc does not have the
role for logon. How can I accomplish this?

Thanks in advance.

 
Reply With Quote
 
 
 
 
Paul Williams [MVP]
Guest
Posts: n/a
 
      28th Nov 2005
You can't really stop replication from flowing both ways. However, you can
configure it so that one will always be favoured over the other.

Firstly, you should add a new DC to the existing domain. You should also
make this DC a GC and a DNS server. Clients should point to both DCs for
DNS.

Once this is done, you must change the SRV record priorities, so that one is
always favoured over the other. To better control the frequency of
replication, you should also install this new DC in a separate VLAN, and
configure a subnet and site for that VLAN and ensure the DC's server object
resides in this site.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


 
Reply With Quote
 
Paolo
Guest
Posts: n/a
 
      30th Nov 2005
Thanks for the information. The only problem here is that the DNS
server is in another (remote) location and that I don't have the rights
to adminster it. Is there another way (like a preferred
logonserver/registry settings/hosts file or something like that?).

Paolo


Paul Williams [MVP] schreef:

> You can't really stop replication from flowing both ways. However, you can
> configure it so that one will always be favoured over the other.
>
> Firstly, you should add a new DC to the existing domain. You should also
> make this DC a GC and a DNS server. Clients should point to both DCs for
> DNS.
>
> Once this is done, you must change the SRV record priorities, so that one is
> always favoured over the other. To better control the frequency of
> replication, you should also install this new DC in a separate VLAN, and
> configure a subnet and site for that VLAN and ensure the DC's server object
> resides in this site.
>
> --
> Paul Williams
> Microsoft MVP - Windows Server - Directory Services
> http://www.msresource.net | http://forums.msresource.net


 
Reply With Quote
 
Paul Williams [MVP]
Guest
Posts: n/a
 
      30th Nov 2005
As long as the DNS server supports dynamic updates, you are fine. You must
change this via a registry key - as NETLOGON triggers (well, tries to) an
update every 60 minutes.

See kb306602 for more info.
-- http://support.microsoft.com/?id=306602

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
RE: Enterprise Library exception: The configuration section securityCryptographyConfiguration is not defined in the current configuration for the AppDomain. Steven Cheng[MSFT] Microsoft ASP .NET 0 21st Sep 2006 10:18 AM
Microsoft Configuration Block and Enterprise library configuration tool Mark Microsoft ASP .NET 0 15th Feb 2006 11:27 PM
Configuration Application Block: Multiple configuration sections in one file: probashi Microsoft C# .NET 1 21st Mar 2005 10:50 AM
computer configuration versus user configuration issue =?Utf-8?B?S2lkIEtvb2lqbWFucw==?= Microsoft Windows 2000 Active Directory 1 16th Mar 2005 11:15 AM
lost IP addresses - TCP/IP configuration screen always shows DHCP configuration Michael Brown Microsoft Windows 2000 Networking 2 8th Jul 2003 10:02 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 09:36 AM.