Strange Active Directory issue on 2012 R2 2ND-DC with 2003 R2 PRI-DC
i ran issue earlier today haven't seen before.
current setup 1 forest & 1 domain single domain controller (w2003 r2) has fsmo roles since it's dc in domain ever installed. we're ready decommission old w2003r2 server prepped new machine , installed windows server 2012 r2 on it, patched up.
done followings:
1. joined new server domain (successful)
2. promoted new server domain controller (successful without errors or warnings)
3. verified dns records have replicated primary dc 2nd dc (successful)
4. verified able access ad services on new domain controller, users, ou's, sites etc. (successful)
5. verified replication of ad objects adding users/ou's/distribution groups on primary dc , see them replicate on , vice-versa (successful)
i waited hour make sure has replicated on , in sync , decided shutdown primary server (domain controller) make sure things functional on new 1 , old dc shutdown wasn't able open of ad services ad domain , trusts, ad users , computers or ad sites , services. window opened domain wasn't listed , neither of related objects. issue here? shouldn't secondary domain controller replica of primary can see objects , make changes sync once primary comes again. i've worked in setups had 2 dc's in 1 domain , able view ad objects , services regardless if 1 of dc not available, same thing in setup 3 dc's.
if can chime in on great, i'm not sure if i'm missing it's weird.
regards
have made new dc global catalog? see that: https://support.microsoft.com/kb/296882?wa=wsignin1.0
you can check dcs in healthy state , ad replication okay using dcdiag and repadmin commands.
this posting provided no warranties or guarantees , , confers no rights.
ahmed malek
my website link my linkedin profile my mvp profile
Windows Server > Directory Services
Comments
Post a Comment