Changing the IP address of my AD Server

G

Guest

I need to change the IP address design of my compnay LAN from a 192.9.195.x
illegal subnet to a legal 172.16.101.x subnet. Part of these changes involve
changing the AD Servers, DNS and Exchange 2000. Do I need to follow any
procedure when I change the IP address of my AD Servers?

All my clients will have a new IP address from my new DHCP scope.

Many thanks.

Kevin
 
T

Tomasz Onyszko

Kevin said:
I need to change the IP address design of my compnay LAN from a 192.9.195.x
illegal subnet to a legal 172.16.101.x subnet. Part of these changes involve
changing the AD Servers, DNS and Exchange 2000. Do I need to follow any
procedure when I change the IP address of my AD Servers?

All my clients will have a new IP address from my new DHCP scope.

Not really - procedure should look like this:
- change IP
- stop netlogon
- start netlogon
- check DC registration in DNS
- clean old\incorrect entries if any

What You have to care about is that during this operation this server
should point to the DNS server which is known by other DCs as well tl
let them know about this change.

Don't change all DCs IP addresses at one time - do it in the stages
 
H

Herb Martin

Tomasz Onyszko said:
Not really - procedure should look like this:
- change IP
- stop netlogon
- start netlogon
- check DC registration in DNS
- clean old\incorrect entries if any

What You have to care about is that during this operation this server
should point to the DNS server which is known by other DCs as well tl let
them know about this change.

Emphasize this: Make sure when you are changing IP for DCs
that if these are also DNS you are also updating the NIC properties
for the DC (and other DCs) so that they will continue to find the
DNS, register, and thus find each other.

Same for clients when you get through with the DCs and DNS,
make sure the clients all have their NICs pointing to the new
DNS IP addressess.
Don't change all DCs IP addresses at one time - do it in the stages

But have them all able to reach the DNS whatever address the DNS
servers are using.

You may also have a problem if all are AD Integrated DNS -- if so,
point ALL DCs to a "favored" DNS-DC and restart the NetLogon
services again until they are all registered in a single DNS. AD
should then replicate and you can point them back to themselves or
the closest DNS after AD replication is complete.

Remember: DCDiag is your friend. It will show if replication is
failing OR if DNS entries are incorrect or failing to replicate.
 
T

Tomasz Onyszko

Herb Martin wrote:
(...)

Thank You Herb fir restating this - those all things were behind my post
but left in my mind :(
 
C

chriss3 [MVP]

nltest /dsregdns is also friendly tool to make sure the DC specific records
really are there.
 
H

Herb Martin

Tomasz Onyszko said:
Herb Martin wrote:
(...)

Thank You Herb fir restating this - those all things were behind my post
but left in my mind :(

Yours was an excellent post. I just offered him some help
in case it goes bad or he doesn't know these things.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top