DR environment - loose connectivity ?!
Hi all,
I've a DR environment with 30 Windows XPs and 1 DC that are all available in a private network for DR test purposes. Basically they are a copy of production environment.
What happens is that a bunch of xp (not all, but random) loose domain connectivity, and i have to rejoin domain within DR private network.
Can someone tell me what is happening and if there's a quick way to solve this when DR tests occur? in the present i have to logon locally to every xp client and rejoin manually. I need some kind of quick solution.
Many thanks,Lus Carmo
May 14th, 2012 12:18pm
I tried to reset domain computer account, but with no success...
Lus Carmo
Free Windows Admin Tool Kit Click here and download it now
May 14th, 2012 12:23pm
Hello,
If they lose connectivity then there is no need to rejoin them. Losing connectivity does not mean that you are no longer part of the domain. However, you can use your cached credentials to logon.
Since it seems that you have the same copy of your AD domain in production then, if resized FSMO roles,
never connect both AD environments as you may be impacted by severe effects!
But now, if you want switch from the test environment to the production one, you will need to disjoin and join again the computer. There is no workaround since the production AD environment does not have any reference about these computers.
For DR, I would recommend having a DC / DNS / GC server in the DR site and maintain a VPN connection with the main site. Like that, you will receive AD replication with no issues.
This
posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Microsoft
Student Partner 2010 / 2011
Microsoft
Certified Professional
Microsoft
Certified Systems Administrator: Security
Microsoft
Certified Systems Engineer: Security
Microsoft
Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
Microsoft
Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows 7, Configuring
Microsoft
Certified Technology Specialist: Designing and Providing Volume Licensing Solutions to Large Organizations
Microsoft
Certified IT Professional: Enterprise Administrator
Microsoft Certified IT Professional: Server Administrator
Microsoft Certified Trainer
May 14th, 2012 12:30pm
Hi,
Environments are not connected with each other. When on DR tests, every VM (30 xp and 1 DC) boot in private network, with last copy of Server/DC/Clients image. I don't want to switch from test to production. We're working with ESX DR environment, i just
want to work with test environment, with last "image". I don't need to replicate data.
When i say "loose conectivity" it means that i stop to make domain logons. Clients deny connection saying that domain is not reachable... but if i rejoin after local logon, i reach the domain and rejoin. After boot i start do make domain logons.
Lus Carmo
Free Windows Admin Tool Kit Click here and download it now
May 14th, 2012 12:49pm
Hi,
Environments are not connected with each other. When on DR tests, every VM (30 xp and 1 DC) boot in private network, with last copy of Server/DC/Clients image. I don't want to switch from test to production. We're working with ESX DR environment, i just
want to work with test environment, with last "image". I don't need to replicate data.
When i say "loose conectivity" it means that i stop to make domain logons. Clients deny connection saying that domain is not reachable... but if i rejoin after local logon, i reach the domain and rejoin. After boot i start do make domain logons.
Lus Carmo
First of all, using images / clones is not supported by Microsoft since with restoring them you may turn in a USN rollback issue.
If connection us not reachable and there is no more DCs available then I don't see any workaround. Losing connectivity does not disjoin the computer from the domain so I don't see the need for rejoining.
This
posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Microsoft
Student Partner 2010 / 2011
Microsoft
Certified Professional
Microsoft
Certified Systems Administrator: Security
Microsoft
Certified Systems Engineer: Security
Microsoft
Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
Microsoft
Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows 7, Configuring
Microsoft
Certified Technology Specialist: Designing and Providing Volume Licensing Solutions to Large Organizations
Microsoft
Certified IT Professional: Enterprise Administrator
Microsoft Certified IT Professional: Server Administrator
Microsoft Certified Trainer
May 14th, 2012 12:56pm
They are not images, it's a ESX solution for DR environments that i don't have a lot of knowledge because they are managed by other team. We don't need restores or rollbacks. They have to be rejoined to work normally again. Is there something i can do
in DC side? Or in alternative, run a rejoin via script do several workstations (remotely). What i know is that netdom can't rejoin, just add to a new domain. Is this correct?Lus Carmo
Free Windows Admin Tool Kit Click here and download it now
May 14th, 2012 1:17pm
Hello,
it sopunds that your domain copy is NOT AD aware, images/snapshots/clones are NOT supported.
If you have a copy from the domain and use this anyware and switch workstations without rejoining them there may be mismatch from the machine account passwords. This result in loss of the secure channel and require the rejoin to the domain.Best regards
Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/
Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
May 14th, 2012 2:54pm
Hello,
it sopunds that your domain copy is NOT AD aware, images/snapshots/clones are NOT supported.
If you have a copy from the domain and use this anyware and switch workstations without rejoining them there may be mismatch from the machine account passwords. This result in loss of the secure channel and require the rejoin to the domain.Best regards
Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/
Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
May 14th, 2012 2:54pm


