R
Ryan
Hi guys,
I'm planning to transfer all the 5 FSMO roles to another DC. My current
scenario: single domain with 3 DCs. Note: There is another domain that
tusted with our domain.
Currently, we have 1 GC that holds the FSMO Roles (DC1). DC1 is also the
exchange server, we decided to change the roles to another DC (DC2) to
reduce the workload of DC1.
Expected outcome:
3 DC in the domain, 2 GC (DC1 and DC2) and change FSMO roles from DC1 to
DC2.
My plan is (please correct me if I'm wrong):
1) Run DCDIAG, NETDIAG, NTDSUTIL and AD Replication Monitor and clear any
error found (Is there other tools I can use to check the AD consistency? Bad
DNS always relate to AD problem, how to make sure my DNS is running well?)
2) Enable DC2 as GC, restart the DC2 and wait for some time for DC2 to
publish itself as GC (how long should this be?)
3) Check for event 1119, run repadmin /showrep, repdamin /showconn, use
DSDIAG to view cached server list by DSACCESS. Test Exchange & Network
client connections.
4) Do the 5 role transfer (because this step is quite straightforward and
has no progress stated, do I need to restart the new Operation Master server
(D2) after changing the role, will this cause any problem? I think the
server should be kept alive for proper synchronization, how long should I
wait until I start diagnosing the AD condition? Any tool recommended? Do I
need to "push" replication at this stage?).
** Since there's another trusted domain available, any things I need to be
aware in order not to temper the trust relationship? **
Best regards,
Ryan
I'm planning to transfer all the 5 FSMO roles to another DC. My current
scenario: single domain with 3 DCs. Note: There is another domain that
tusted with our domain.
Currently, we have 1 GC that holds the FSMO Roles (DC1). DC1 is also the
exchange server, we decided to change the roles to another DC (DC2) to
reduce the workload of DC1.
Expected outcome:
3 DC in the domain, 2 GC (DC1 and DC2) and change FSMO roles from DC1 to
DC2.
My plan is (please correct me if I'm wrong):
1) Run DCDIAG, NETDIAG, NTDSUTIL and AD Replication Monitor and clear any
error found (Is there other tools I can use to check the AD consistency? Bad
DNS always relate to AD problem, how to make sure my DNS is running well?)
2) Enable DC2 as GC, restart the DC2 and wait for some time for DC2 to
publish itself as GC (how long should this be?)
3) Check for event 1119, run repadmin /showrep, repdamin /showconn, use
DSDIAG to view cached server list by DSACCESS. Test Exchange & Network
client connections.
4) Do the 5 role transfer (because this step is quite straightforward and
has no progress stated, do I need to restart the new Operation Master server
(D2) after changing the role, will this cause any problem? I think the
server should be kept alive for proper synchronization, how long should I
wait until I start diagnosing the AD condition? Any tool recommended? Do I
need to "push" replication at this stage?).
** Since there's another trusted domain available, any things I need to be
aware in order not to temper the trust relationship? **
Best regards,
Ryan