Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Help!! Adding a second DC

Status
Not open for further replies.

Eddiefdz

IS-IT--Management
Joined
Mar 20, 2002
Messages
273
Location
US
I recently upgraded my NT.4 PDC to a 2000 Server. I loaded AD and everything seems great... or so i thought. Today i build a 2000 server and i now want to add it to the active directory so i ran DCPROMO on it. Well when i run DCPROMO and it tries to connect. I get an error stating that the Active Directory domain connot be found. I checked the DNS settings on the AD server that i have running and i do have all the correct settings that i know of. Also i checked the second server that i just built and when i ping the domain name it is replying with the correct address of the server. So at this point i dont know what else to do. Also, is there any way to export the list of users that i have on my domain and back them up lets say, in case i need to rebuild the server. That way i wouldnt have to add the users back one by one.

Thanks,
Eddie
 
If you like to users to be replicated to the standalone server be sure to join the domain first before DCPROMO and DNS must be installed and pointed to itself
 
check the username you are using to join the domain. If you can ping the net link is ok. Check on the AD box in domain controllers. Is the other one there? If so, remove it then redo the dcpromo. If it still fails use netdom from the 2000 tools CD, but you'll need to read up the command line syntax.
 
I think i may have problems with the way that DNS is setup. What should i look for in the DNS's of both the AD server and the 2000 Server that i am trying to add on. I have tried to ping back and forth and both servers do see each other. I had tried multiple commands and they seem to connect. They are passing all the tests except for the DNS and the Kerberos testing.
 
ok, then the upgrade NT box could be a DNS server and the second should have that server as its DNS server. In DNS add A records for both server with the right IP address.

Can each server ping the other by FQDN?
 
Sorry but what is FQDN?? ok so what you are telling me is to add the second server to the DNS forward lookup entry of the AD DC. I will do that. I know that there is an entry on the second server's DNS forward lookup that is pointing to the AD DC.
 
OK!! I finally got it to go a step further. It was the DNS entry on the second server. I had to set it to first point to the AD DC and then to itself, i had them backwards. Ok well now its telling me somthing else.. Its telling me that it failed to modify the necessary properties for the machine account on the second server because access is denied.

Then it tells me to add the user name and password for a user with enought rights to add an additional domain.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top