| View previous topic :: View next topic
|
| Author |
Message |
Jake Guest
|
Posted: Mon Oct 05, 2009 9:45 am Post subject: Adding 2008 dc to 2003 domain - help.. |
|
|
|
Hi,
We have just installed a win2008std server onto new hardware and we are
trying to promote it as a domain controller in a w2003 domain.
We have run 2008's adprep /forestprep on the 2003 primary domain
controller and it finished without errors.
However when trying to promote the 2008 server as dc it still requires
us to run adprep.
Despite that we have run adprep on the w2003 dc its AD Domains and
Trusts properties still display Forest functional level: 'Windows 2000'
We have rebooted both boxes. Rerunning adprep just displays that the
changes have already been applied.
What do we do to come past this..?
regards jake
|
|
| Back to top |
|
 |
Jake Guest
|
Posted: Mon Oct 05, 2009 10:18 am Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Meinolf Weber [MVP-DS] skrev:
| Quote: | Hello Jake,
You have to run adprep /forestprep in the forest and adprep /domainprep
in each domain contained in the forest. If the Domain was 2000 also run
adprep /domainprep /gpprep and if you think about adding RODCs in the
future run directly adprep /rodcprep.
Also see:
http://technet.microsoft.com/en-us/library/cc731728(WS.10).aspx
Best regards
Meinolf Weber
|
Thanks Meinolf,
BTDT... There is only one domain in the forest and one domain
controller running w2003. Domain was at 2003 functional level and
forest at 2000 functional level.
We used the w2008 dvd's adprep at w2003 and run adprep /forestprep which
took several minutes and completed without any error message.
However w2008 still claimed not being able to promote and still wanted
adprep /forestprep to be run.
We rebooted both the w2003 and w2008 boxes. Same problem.
w2003's Domains and Trusts properties still claims that forest
functional level is Windows 2000
adprep /forestprep and adprep /domainprep halt with message 'Changes
already applied, quitting'.
I have also tried to run w2003CD's adprep /forestprep to rise it from
2000 to 2003, but the same message pops up.
What do we do now...?
regards
jake
|
|
| Back to top |
|
 |
Ace Fekay [MCT] Guest
|
Posted: Mon Oct 05, 2009 10:47 am Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
"Jake" <jake44@gmail.com> wrote in message
news:uIeqEYbRKHA.4048@TK2MSFTNGP05.phx.gbl...
| Quote: | Meinolf Weber [MVP-DS] skrev:
Hello Jake,
You have to run adprep /forestprep in the forest and adprep /domainprep
in each domain contained in the forest. If the Domain was 2000 also run
adprep /domainprep /gpprep and if you think about adding RODCs in the
future run directly adprep /rodcprep.
Also see:
http://technet.microsoft.com/en-us/library/cc731728(WS.10).aspx
Best regards
Meinolf Weber
Thanks Meinolf,
BTDT... There is only one domain in the forest and one domain controller
running w2003. Domain was at 2003 functional level and forest at 2000
functional level.
We used the w2008 dvd's adprep at w2003 and run adprep /forestprep which
took several minutes and completed without any error message.
However w2008 still claimed not being able to promote and still wanted
adprep /forestprep to be run.
We rebooted both the w2003 and w2008 boxes. Same problem.
w2003's Domains and Trusts properties still claims that forest functional
level is Windows 2000
adprep /forestprep and adprep /domainprep halt with message 'Changes
already applied, quitting'.
I have also tried to run w2003CD's adprep /forestprep to rise it from 2000
to 2003, but the same message pops up.
What do we do now...?
regards
jake
|
In addition to the adprep logs Meinolf requested, please post an ipconfig
/all of your two current DCs, and of the 2008 machine. Also post any Event
log errors (EventID # and Source name).
There may be something else going on, which could be based on configuration.
The event log errors, along with the ipconfigs will help in evaluation.
--
Ace
This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.
Please reply back to the newsgroup or forum for collaboration benefit among
responding engineers, and to help others benefit from your resolution.
Ace Fekay, MCT, MCTS 2008, MCTS Exchange, MCSE, MCSA 2003 & 2000, MCSA
Messaging
Microsoft Certified Trainer
For urgent issues, please contact Microsoft PSS directly. Please check
http://support.microsoft.com for regional support phone numbers.
|
|
| Back to top |
|
 |
Guest Guest
Posts Location
|
Posted: Mon Oct 05, 2009 10:47 am Post subject: Google Ads |
|
|
|
|
|
| Back to top |
|
 |
Jake Guest
|
Posted: Mon Oct 05, 2009 10:54 am Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Meinolf Weber [MVP-DS] skrev:
| Quote: | Hello Jake,
Please run adprep /domainprep from the 2008 installation disk and after
that post the complete adprep logfile.
Best regards
Meinolf Weber
|
Meinolf,
Thanks for your help. As you saw I had already rerun adprep /domainprep
from the w2008 dvd, but I redid it as you requested. Here is the log
file for the latest run:
Adprep created the log file ADPrep.log under
C:\WINDOWS\debug\adprep\logs\20091005144444 directory.
Adprep copied file C:\adprep\schema.ini from installation point to local
machine under directory C:\WINDOWS.
Adprep copied file C:\adprep\schupgrade.cat from installation point to
local machine under directory C:\WINDOWS\system32.
Adprep copied file C:\adprep\PAS.ldf from installation point to local
machine under directory C:\WINDOWS\system32.
Adprep successfully made the LDAP connection to the local Active
Directory Domain Controller PETER.
Adprep was about to call the following LDAP API. ldap_search_s(). The
base entry to start the search is (null).
LDAP API ldap_search_s() finished, return code is 0x0
Adprep successfully retrieved information from the local Active
Directory Domain Services.
Adprep successfully initialized global variables.
[Status/Consequence]
Adprep is continuing.
Domain-wide information has already been updated.
[Status/Consequence]
Adprep did not attempt to rerun this operation.
Adprep was about to call the following LDAP API. ldap_search_s(). The
base entry to start the search is
cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN.
LDAP API ldap_search_s() finished, return code is 0x0
Adprep checked to verify whether operation
cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN
has completed.
[Status/Consequence]
The operation GUID already exists so Adprep did not attempt to rerun
this operation but is continuing.
Adprep was about to call the following LDAP API. ldap_search_s(). The
base entry to start the search is
cn=446f24ea-cfd5-4c52-8346-96e170bcb912,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN.
LDAP API ldap_search_s() finished, return code is 0x0
Adprep checked to verify whether operation
cn=446f24ea-cfd5-4c52-8346-96e170bcb912,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN
has completed.
[Status/Consequence]
The operation GUID already exists so Adprep did not attempt to rerun
this operation but is continuing.
Adprep was about to call the following LDAP API. ldap_search_s(). The
base entry to start the search is
cn=51cba88b-99cf-4e16-bef2-c427b38d0767,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN.
LDAP API ldap_search_s() finished, return code is 0x0
Adprep checked to verify whether operation
cn=51cba88b-99cf-4e16-bef2-c427b38d0767,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN
has completed.
[Status/Consequence]
The operation GUID already exists so Adprep did not attempt to rerun
this operation but is continuing.
|
|
| Back to top |
|
 |
Jake Guest
|
Posted: Mon Oct 05, 2009 11:27 am Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Ace Fekay [MCT] skrev:
| Quote: | In addition to the adprep logs Meinolf requested, please post an ipconfig
/all of your two current DCs, and of the 2008 machine. Also post any Event
log errors (EventID # and Source name).
There may be something else going on, which could be based on configuration.
The event log errors, along with the ipconfigs will help in evaluation.
|
Ace,
There certainly is more going on. First is w2003 dc dns log events,
then same server's ipconfig and last is w2008 ipconfig. Will be offline
a couple of hours but rush back after that. Thanks a lot for any help.
jake
From w2003 dc's dns events:
After reboot - DNS server started and then...:
4015 The DNS server has encountered a critical error from the Active
Directory. Check that the Active Directory is functioning properly. The
extended error debug information (which may be empty) is "". The event
data contains the error.
4004 The DNS server was unable to complete directory service enumeration
of zone .. This DNS server is configured to use information obtained
from Active Directory for this zone and is unable to load the zone
without it. Check that the Active Directory is functioning properly and
repeat enumeration of the zone. The extended error debug information
(which may be empty) is "". The event data contains the error.
4004 The DNS server was unable to complete directory service enumeration
of zone _msdcs.mylocaldomain.LAN. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable
to load the zone without it. Check that the Active Directory is
functioning properly and repeat enumeration of the zone. The extended
error debug information (which may be empty) is "". The event data
contains the error.
4004 The DNS server was unable to complete directory service enumeration
of zone 100.25.172.in-addr.arpa. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable
to load the zone without it. Check that the Active Directory is
functioning properly and repeat enumeration of the zone. The extended
error debug information (which may be empty) is "". The event data
contains the error.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
4004 The DNS server was unable to complete directory service enumeration
of zone mylocaldomain.LAN. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable
to load the zone without it. Check that the Active Directory is
functioning properly and repeat enumeration of the zone. The extended
error debug information (which may be empty) is "". The event data
contains the error.
4004 The DNS server was unable to complete directory service enumeration
of zone LAN. This DNS server is configured to use information obtained
from Active Directory for this zone and is unable to load the zone
without it. Check that the Active Directory is functioning properly and
repeat enumeration of the zone. The extended error debug information
(which may be empty) is "". The event data contains the error.
w2003 dc ipconfig
C:\adprep>ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : peter
Primary Dns Suffix . . . . . . . : mylocaldomain.LAN
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : mylocaldomain.LAN
Ethernet adapter NIC OnBoard Top - Classrooms:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection #
2
Physical Address. . . . . . . . . : 00-13-72-F9-45-2A
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 172.25.100.13
Subnet Mask . . . . . . . . . . . : 255.255.254.0
Default Gateway . . . . . . . . . : 172.25.100.1
DNS Servers . . . . . . . . . . . : 172.25.100.13
Primary WINS Server . . . . . . . : 172.25.100.10
C:\adprep>
win2008:
Microsoft Windows [Version 6.0.6002]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.
C:\Users\Administrator>ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : Peter-2
Primary Dns Suffix . . . . . . . : mylocaldomain.LAN
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : mylocaldomain.LAN
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection
Physical Address. . . . . . . . . : 00-0C-29-19-D2-90
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 172.25.100.10(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.254.0
Default Gateway . . . . . . . . . : 172.25.100.1
DNS Servers . . . . . . . . . . . : 172.25.100.13
172.25.100.11
NetBIOS over Tcpip. . . . . . . . : Enabled
Tunnel adapter Local Area Connection* 8:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . :
isatap.{0ACD987E-9352-4079-B47A-38C0C44B
13D}
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Local Area Connection* 9:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 02-00-54-55-4E-01
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
C:\Users\Administrator>
|
|
| Back to top |
|
 |
Ace Fekay [MCT] Guest
|
Posted: Mon Oct 05, 2009 11:38 am Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
"Jake" <jake44@gmail.com> wrote in message
news:eLoTI%23bRKHA.4476@TK2MSFTNGP02.phx.gbl...
| Quote: | Ace,
There certainly is more going on. First is w2003 dc dns log events, then
same server's ipconfig and last is w2008 ipconfig. Will be offline a
couple of hours but rush back after that. Thanks a lot for any help.
jake
From w2003 dc's dns events:
After reboot - DNS server started and then...:
4015 The DNS server has encountered a critical error from the Active
Directory. Check that the Active Directory is functioning properly. The
extended error debug information (which may be empty) is "". The event
data contains the error.
4004 The DNS server was unable to complete directory service enumeration
of zone .. This DNS server is configured to use information obtained from
Active Directory for this zone and is unable to load the zone without it.
Check that the Active Directory is functioning properly and repeat
enumeration of the zone. The extended error debug information (which may
be empty) is "". The event data contains the error.
4004 The DNS server was unable to complete directory service enumeration
of zone _msdcs.mylocaldomain.LAN. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable to
load the zone without it. Check that the Active Directory is functioning
properly and repeat enumeration of the zone. The extended error debug
information (which may be empty) is "". The event data contains the error.
4004 The DNS server was unable to complete directory service enumeration
of zone 100.25.172.in-addr.arpa. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable to
load the zone without it. Check that the Active Directory is functioning
properly and repeat enumeration of the zone. The extended error debug
information (which may be empty) is "". The event data contains the error.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
4004 The DNS server was unable to complete directory service enumeration
of zone mylocaldomain.LAN. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable to
load the zone without it. Check that the Active Directory is functioning
properly and repeat enumeration of the zone. The extended error debug
information (which may be empty) is "". The event data contains the error.
4004 The DNS server was unable to complete directory service enumeration
of zone LAN. This DNS server is configured to use information obtained
from Active Directory for this zone and is unable to load the zone without
it. Check that the Active Directory is functioning properly and repeat
enumeration of the zone. The extended error debug information (which may
be empty) is "". The event data contains the error.
w2003 dc ipconfig
C:\adprep>ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : peter
Primary Dns Suffix . . . . . . . : mylocaldomain.LAN
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : mylocaldomain.LAN
Ethernet adapter NIC OnBoard Top - Classrooms:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection #
2
Physical Address. . . . . . . . . : 00-13-72-F9-45-2A
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 172.25.100.13
Subnet Mask . . . . . . . . . . . : 255.255.254.0
Default Gateway . . . . . . . . . : 172.25.100.1
DNS Servers . . . . . . . . . . . : 172.25.100.13
Primary WINS Server . . . . . . . : 172.25.100.10
C:\adprep
win2008:
Microsoft Windows [Version 6.0.6002]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.
C:\Users\Administrator>ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : Peter-2
Primary Dns Suffix . . . . . . . : mylocaldomain.LAN
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : mylocaldomain.LAN
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection
Physical Address. . . . . . . . . : 00-0C-29-19-D2-90
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 172.25.100.10(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.254.0
Default Gateway . . . . . . . . . : 172.25.100.1
DNS Servers . . . . . . . . . . . : 172.25.100.13
172.25.100.11
NetBIOS over Tcpip. . . . . . . . : Enabled
Tunnel adapter Local Area Connection* 8:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . :
isatap.{0ACD987E-9352-4079-B47A-38C0C44B
13D}
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Local Area Connection* 9:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 02-00-54-55-4E-01
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
C:\Users\Administrator
|
Thanks for posting this info.
I would suggest on the 2003 machine to leave DNS pointing to itself, but add
the 2008 machine as the second DNS entry.
On the 2008 machine, if DNS is installed, make it point to itself first, and
2003 machine as the second entry.
Windows 2008 has a missing WINS entry. Not that it matters with this issue,
but you'll want to add that to be consitent.
Are 172.25.100.11 and 172.25.100.10 other DCs?
When you went through the domain rename process, were there any errors
encountered?
Does the zone mylocaldomain.LAN exist in DNS, and are updates allowed?
Ace
|
|
| Back to top |
|
 |
Meinolf Weber [MVP-DS] Guest
|
Posted: Mon Oct 05, 2009 11:53 am Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Hello Jake,
You have to run adprep /forestprep in the forest and adprep /domainprep in
each domain contained in the forest. If the Domain was 2000 also run adprep
/domainprep /gpprep and if you think about adding RODCs in the future run
directly adprep /rodcprep.
Also see:
http://technet.microsoft.com/en-us/library/cc731728(WS.10).aspx
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
| Quote: | Hi,
We have just installed a win2008std server onto new hardware and we
are trying to promote it as a domain controller in a w2003 domain.
We have run 2008's adprep /forestprep on the 2003 primary domain
controller and it finished without errors.
However when trying to promote the 2008 server as dc it still requires
us to run adprep.
Despite that we have run adprep on the w2003 dc its AD Domains and
Trusts properties still display Forest functional level: 'Windows
2000'
We have rebooted both boxes. Rerunning adprep just displays that the
changes have already been applied.
What do we do to come past this..?
regards jake
|
|
|
| Back to top |
|
 |
Meinolf Weber [MVP-DS] Guest
|
Posted: Mon Oct 05, 2009 12:27 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Hello Jake,
Please run adprep /domainprep from the 2008 installation disk and after that
post the complete adprep logfile.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
| Quote: | Meinolf Weber [MVP-DS] skrev:
Hello Jake,
You have to run adprep /forestprep in the forest and adprep
/domainprep in each domain contained in the forest. If the Domain was
2000 also run adprep /domainprep /gpprep and if you think about
adding RODCs in the future run directly adprep /rodcprep.
Also see:
http://technet.microsoft.com/en-us/library/cc731728(WS.10).aspx
Best regards
Meinolf Weber
Thanks Meinolf,
BTDT... There is only one domain in the forest and one domain
controller running w2003. Domain was at 2003 functional level and
forest at 2000 functional level.
We used the w2008 dvd's adprep at w2003 and run adprep /forestprep
which took several minutes and completed without any error message.
However w2008 still claimed not being able to promote and still wanted
adprep /forestprep to be run.
We rebooted both the w2003 and w2008 boxes. Same problem.
w2003's Domains and Trusts properties still claims that forest
functional level is Windows 2000
adprep /forestprep and adprep /domainprep halt with message 'Changes
already applied, quitting'.
I have also tried to run w2003CD's adprep /forestprep to rise it from
2000 to 2003, but the same message pops up.
What do we do now...?
regards
jake
|
|
|
| Back to top |
|
 |
Hugo Guest
|
Posted: Mon Oct 05, 2009 12:51 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Hi Jake !
Did you tried to raise all fonctional level to 2003 ?
Hugo
"Jake" <jake44@gmail.com> a écrit dans le message de groupe de discussion :
uIeqEYbRKHA.4048@TK2MSFTNGP05.phx.gbl...
| Quote: | Meinolf Weber [MVP-DS] skrev:
Hello Jake,
You have to run adprep /forestprep in the forest and adprep /domainprep
in each domain contained in the forest. If the Domain was 2000 also run
adprep /domainprep /gpprep and if you think about adding RODCs in the
future run directly adprep /rodcprep.
Also see:
http://technet.microsoft.com/en-us/library/cc731728(WS.10).aspx
Best regards
Meinolf Weber
Thanks Meinolf,
BTDT... There is only one domain in the forest and one domain controller
running w2003. Domain was at 2003 functional level and forest at 2000
functional level.
We used the w2008 dvd's adprep at w2003 and run adprep /forestprep which
took several minutes and completed without any error message.
However w2008 still claimed not being able to promote and still wanted
adprep /forestprep to be run.
We rebooted both the w2003 and w2008 boxes. Same problem.
w2003's Domains and Trusts properties still claims that forest functional
level is Windows 2000
adprep /forestprep and adprep /domainprep halt with message 'Changes
already applied, quitting'.
I have also tried to run w2003CD's adprep /forestprep to rise it from 2000
to 2003, but the same message pops up.
What do we do now...?
regards
jake |
|
|
| Back to top |
|
 |
Meinolf Weber [MVP-DS] Guest
|
Posted: Mon Oct 05, 2009 1:37 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Hello Jake,
PETER doesn't use x.x.x. 11 as DNS server, add that also as with the 2008
server. PETER2 is your WINS server, is this correct?
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
| Quote: | Ace Fekay [MCT] skrev:
In addition to the adprep logs Meinolf requested, please post an
ipconfig /all of your two current DCs, and of the 2008 machine. Also
post any Event log errors (EventID # and Source name).
There may be something else going on, which could be based on
configuration. The event log errors, along with the ipconfigs will
help in evaluation.
Ace,
There certainly is more going on. First is w2003 dc dns log events,
then same server's ipconfig and last is w2008 ipconfig. Will be
offline a couple of hours but rush back after that. Thanks a lot for
any help.
jake
From w2003 dc's dns events:
After reboot - DNS server started and then...:
4015 The DNS server has encountered a critical error from the Active
Directory. Check that the Active Directory is functioning properly.
The extended error debug information (which may be empty) is "". The
event data contains the error.
4004 The DNS server was unable to complete directory service
enumeration of zone .. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable
to load the zone without it. Check that the Active Directory is
functioning properly and repeat enumeration of the zone. The extended
error debug information (which may be empty) is "". The event data
contains the error.
4004 The DNS server was unable to complete directory service
enumeration of zone _msdcs.mylocaldomain.LAN. This DNS server is
configured to use information obtained from Active Directory for this
zone and is unable to load the zone without it. Check that the Active
Directory is functioning properly and repeat enumeration of the zone.
The extended error debug information (which may be empty) is "". The
event data contains the error.
4004 The DNS server was unable to complete directory service
enumeration of zone 100.25.172.in-addr.arpa. This DNS server is
configured to use information obtained from Active Directory for this
zone and is unable to load the zone without it. Check that the Active
Directory is functioning properly and repeat enumeration of the zone.
The extended error debug information (which may be empty) is "". The
event data contains the error.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
4004 The DNS server was unable to complete directory service
enumeration of zone mylocaldomain.LAN. This DNS server is configured
to use information obtained from Active Directory for this zone and is
unable to load the zone without it. Check that the Active Directory
is functioning properly and repeat enumeration of the zone. The
extended error debug information (which may be empty) is "". The event
data contains the error.
4004 The DNS server was unable to complete directory service
enumeration of zone LAN. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable
to load the zone without it. Check that the Active Directory is
functioning properly and repeat enumeration of the zone. The extended
error debug information (which may be empty) is "". The event data
contains the error.
w2003 dc ipconfig
C:\adprep>ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : peter
Primary Dns Suffix . . . . . . . : mylocaldomain.LAN
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : mylocaldomain.LAN
Ethernet adapter NIC OnBoard Top - Classrooms:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection #
2
Physical Address. . . . . . . . . : 00-13-72-F9-45-2A
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 172.25.100.13
Subnet Mask . . . . . . . . . . . : 255.255.254.0
Default Gateway . . . . . . . . . : 172.25.100.1
DNS Servers . . . . . . . . . . . : 172.25.100.13
Primary WINS Server . . . . . . . : 172.25.100.10
C:\adprep
win2008:
Microsoft Windows [Version 6.0.6002]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.
C:\Users\Administrator>ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : Peter-2
Primary Dns Suffix . . . . . . . : mylocaldomain.LAN
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : mylocaldomain.LAN
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection
Physical Address. . . . . . . . . : 00-0C-29-19-D2-90
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 172.25.100.10(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.254.0
Default Gateway . . . . . . . . . : 172.25.100.1
DNS Servers . . . . . . . . . . . : 172.25.100.13
172.25.100.11
NetBIOS over Tcpip. . . . . . . . : Enabled
Tunnel adapter Local Area Connection* 8:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . :
isatap.{0ACD987E-9352-4079-B47A-38C0C44B
13D}
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Local Area Connection* 9:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling
Pseudo-Interface
Physical Address. . . . . . . . . : 02-00-54-55-4E-01
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
C:\Users\Administrator
|
|
|
| Back to top |
|
 |
Jake Guest
|
Posted: Mon Oct 05, 2009 2:29 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Ace Fekay [MCT] skrev:
| Quote: |
Thanks for posting this info.
I would suggest on the 2003 machine to leave DNS pointing to itself, but add
the 2008 machine as the second DNS entry.
Done. |
| Quote: | On the 2008 machine, if DNS is installed, make it point to itself first, and
2003 machine as the second entry.
Done.
Windows 2008 has a missing WINS entry. Not that it matters with this issue,
but you'll want to add that to be consitent.
Fixed.
Are 172.25.100.11 and 172.25.100.10 other DCs?
..11 has been removed. .10 is the current master DC. Will be denoted |
when i have two new w2008 dcs and these dns /ad issues have been resolved.
| Quote: |
When you went through the domain rename process, were there any errors
encountered?
That was years ago. Not that I remember, the process itself went |
without any error messages, but I saw that was dns red events after each
reboot of the server. Everything worked fine though, so it hasn't been
addressed before now when I want all ok in the process of moving to w2008.
| Quote: |
Does the zone mylocaldomain.LAN exist in DNS, and are updates allowed?
_msdcs.mydomain.lan allows for secure (only) updates |
mylocaldomain.lan and .lan exists as forward dns zones
But there is more to it than this. There must be a reason that I cannot
raise my forest functional level any higher than w2000 level. What do
I do now...?
thanks again, this is a great coimmunity
jake
|
|
| Back to top |
|
 |
Jake Guest
|
Posted: Mon Oct 05, 2009 2:33 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Meinolf Weber [MVP-DS] skrev:
| Quote: | Hello Jake,
PETER doesn't use x.x.x.11 as DNS server, add that also as with the 2008
server. PETER2 is your WINS server, is this correct?
Best regards
Meinolf Weber
|
...11 has been denoted and removed some time ago, sorry about that.
Peter-2 (w2008) will be my master DC when I (we) have resolved these
issues.
..13 (Peter) is currently my wins server. Peter-2 will take over as wins
server when I transfer the fsmo roles later.
jake
|
|
| Back to top |
|
 |
Jake Guest
|
Posted: Mon Oct 05, 2009 2:35 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Hugo skrev:
| Quote: | Hi Jake !
Did you tried to raise all fonctional level to 2003 ?
Hugo
|
That was when it all began. Even w2008's adprep /forestprep did not
manage to raise the forest functional level from 2000 to 2003...
jake
|
|
| Back to top |
|
 |
Ace Fekay [MCT] Guest
|
Posted: Mon Oct 05, 2009 2:39 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
"Jake" <jake44@gmail.com> wrote in message
news:u3MD2jdRKHA.4116@TK2MSFTNGP04.phx.gbl...
| Quote: | Ace Fekay [MCT] skrev:
Thanks for posting this info.
I would suggest on the 2003 machine to leave DNS pointing to itself, but
add the 2008 machine as the second DNS entry.
Done.
On the 2008 machine, if DNS is installed, make it point to itself first,
and 2003 machine as the second entry.
Done.
Windows 2008 has a missing WINS entry. Not that it matters with this
issue, but you'll want to add that to be consitent.
Fixed.
Are 172.25.100.11 and 172.25.100.10 other DCs?
.11 has been removed. .10 is the current master DC. Will be denoted when
i have two new w2008 dcs and these dns /ad issues have been resolved.
When you went through the domain rename process, were there any errors
encountered?
That was years ago. Not that I remember, the process itself went without
any error messages, but I saw that was dns red events after each reboot of
the server. Everything worked fine though, so it hasn't been addressed
before now when I want all ok in the process of moving to w2008.
Does the zone mylocaldomain.LAN exist in DNS, and are updates allowed?
_msdcs.mydomain.lan allows for secure (only) updates
mylocaldomain.lan and .lan exists as forward dns zones
But there is more to it than this. There must be a reason that I cannot
raise my forest functional level any higher than w2000 level. What do I
do now...?
thanks again, this is a great coimmunity
jake
|
You are welcome!
As far as not being able to raise the functional levels, what errors are you
getting? Is there an old 2000 DC still referenced in the AD database? Use
Metadata cleanup to insure that all DCs that were previously removed, are
actually gone out of the database. Use the following to guide you.
Cleanup (Metadata Cleanup) the AD database from the crashed DC - How to
remove data in Active Directory after an unsuccessful domain controller
demotion
http://support.microsoft.com/kb/216498
Ace
|
|
| Back to top |
|
 |
Florian Frommherz [MVP] Guest
|
Posted: Mon Oct 05, 2009 4:03 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Jake,
Jake schrieb:
| Quote: | That was when it all began. Even w2008's adprep /forestprep did not
manage to raise the forest functional level from 2000 to 2003...
|
What do you mean? /forestprep doesn't do that automatically - raising a
forest functional level is a different thing from installing the schema.
Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
|
|
| Back to top |
|
 |
Ace Fekay [MCT] Guest
|
Posted: Mon Oct 05, 2009 4:12 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
"Florian Frommherz [MVP]" <florian@frickelsoft.DELETETHIS.net> wrote in
message news:%23R2%233YeRKHA.1280@TK2MSFTNGP04.phx.gbl...
| Quote: | Jake,
Jake schrieb:
That was when it all began. Even w2008's adprep /forestprep did not
manage to raise the forest functional level from 2000 to 2003...
What do you mean? /forestprep doesn't do that automatically - raising a
forest functional level is a different thing from installing the schema.
Cheers,
Florian
|
I missed this post. Good thought, and I agree. Possibly Jake meant he tried
to raise it using normal procedures?
Ace
|
|
| Back to top |
|
 |
Jake Guest
|
Posted: Mon Oct 05, 2009 4:49 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Florian Frommherz [MVP] skrev:
| Quote: | Jake,
Jake schrieb:
That was when it all began. Even w2008's adprep /forestprep did not
manage to raise the forest functional level from 2000 to 2003...
What do you mean? /forestprep doesn't do that automatically - raising a
forest functional level is a different thing from installing the schema.
Cheers,
Florian
|
Got me with the pants down here. I thought adprep /forestprep would do that.
I opened AD Domains and Trusts and right clicked the domain name. Only
Raise Domain functional level... and not Raise Forest functional
level... appeared at the context meny list.
So how do I raise my Forest functional level in my w2003R2sp2?
regards
jake
|
|
| Back to top |
|
 |
Jake Guest
|
Posted: Mon Oct 05, 2009 4:50 pm Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Ace Fekay [MCT] skrev:
| Quote: | I missed this post. Good thought, and I agree. Possibly Jake meant he tried
to raise it using normal procedures?
Ace
Pls elaborate 'normal procedures' (see my post above).. |
jake
|
|
| Back to top |
|
 |
Ace Fekay [MCT] Guest
|
Posted: Tue Oct 06, 2009 1:54 am Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
"Jake" <jake44@gmail.com> wrote in message
news:%23KtYPyeRKHA.5052@TK2MSFTNGP06.phx.gbl...
| Quote: | Florian Frommherz [MVP] skrev:
Jake,
Jake schrieb:
That was when it all began. Even w2008's adprep /forestprep did not
manage to raise the forest functional level from 2000 to 2003...
What do you mean? /forestprep doesn't do that automatically - raising a
forest functional level is a different thing from installing the schema.
Cheers,
Florian
Got me with the pants down here. I thought adprep /forestprep would do
that.
I opened AD Domains and Trusts and right clicked the domain name. Only
Raise Domain functional level... and not Raise Forest functional level...
appeared at the context meny list.
So how do I raise my Forest functional level in my w2003R2sp2?
regards
jake
|
No, that's not one of it's features.
In Domains and Trust. Which server are you on? 2003 or 2008?
If on the 2003 DC, what level does it say it's at? How about from the 2008
DC?
Ace
|
|
| Back to top |
|
 |
Jake Guest
|
Posted: Tue Oct 06, 2009 4:34 am Post subject: Re: Adding 2008 dc to 2003 domain - help.. |
|
|
Ace Fekay [MCT] skrev:
| Quote: | No, that's not one of it's features.
In Domains and Trust. Which server are you on? 2003 or 2008?
If on the 2003 DC, what level does it say it's at? How about from the 2008
DC?
Ace
|
I right-clicked Domains and Trusts domain name instead of its root node,
that's why I did not find the 'Raise forest functional level...' item.
The 'upgrade' went fine once I found out this. Both domain and forest
are at 2003 level now. I will come back later today with an update of
my DNS event situation. Thanks again for the help you provided.
jake
|
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
Topic Links: syslog
Powered by phpBB © 2001, 2005 phpBB Group
|