Adding 2008 dc to 2003 domain - help..

J

Jake

Hi,

We have just installed a win2008std server onto new hardware and we are
trying to promote it as a domain controller in a w2003 domain.

We have run 2008's adprep /forestprep on the 2003 primary domain
controller and it finished without errors.

However when trying to promote the 2008 server as dc it still requires
us to run adprep.

Despite that we have run adprep on the w2003 dc its AD Domains and
Trusts properties still display Forest functional level: 'Windows 2000'

We have rebooted both boxes. Rerunning adprep just displays that the
changes have already been applied.

What do we do to come past this..?

regards jake
 
M

Meinolf Weber [MVP-DS]

Hello Jake,

You have to run adprep /forestprep in the forest and adprep /domainprep in
each domain contained in the forest. If the Domain was 2000 also run adprep
/domainprep /gpprep and if you think about adding RODCs in the future run
directly adprep /rodcprep.

Also see:
http://technet.microsoft.com/en-us/library...728(WS.10).aspx

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi,
>
> We have just installed a win2008std server onto new hardware and we
> are trying to promote it as a domain controller in a w2003 domain.
>
> We have run 2008's adprep /forestprep on the 2003 primary domain
> controller and it finished without errors.
>
> However when trying to promote the 2008 server as dc it still requires
> us to run adprep.
>
> Despite that we have run adprep on the w2003 dc its AD Domains and
> Trusts properties still display Forest functional level: 'Windows
> 2000'
>
> We have rebooted both boxes. Rerunning adprep just displays that the
> changes have already been applied.
>
> What do we do to come past this..?
>
> regards jake
>
 
J

Jake

Meinolf Weber [MVP-DS] skrev:
> Hello Jake,
>
> You have to run adprep /forestprep in the forest and adprep /domainprep
> in each domain contained in the forest. If the Domain was 2000 also run
> adprep /domainprep /gpprep and if you think about adding RODCs in the
> future run directly adprep /rodcprep.
>
> Also see:
> http://technet.microsoft.com/en-us/library...728(WS.10).aspx
>
> Best regards
>
> Meinolf Weber


Thanks Meinolf,

BTDT... There is only one domain in the forest and one domain
controller running w2003. Domain was at 2003 functional level and
forest at 2000 functional level.

We used the w2008 dvd's adprep at w2003 and run adprep /forestprep which
took several minutes and completed without any error message.

However w2008 still claimed not being able to promote and still wanted
adprep /forestprep to be run.

We rebooted both the w2003 and w2008 boxes. Same problem.

w2003's Domains and Trusts properties still claims that forest
functional level is Windows 2000

adprep /forestprep and adprep /domainprep halt with message 'Changes
already applied, quitting'.

I have also tried to run w2003CD's adprep /forestprep to rise it from
2000 to 2003, but the same message pops up.

What do we do now...?

regards

jake
 
M

Meinolf Weber [MVP-DS]

Hello Jake,

Please run adprep /domainprep from the 2008 installation disk and after that
post the complete adprep logfile.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Meinolf Weber [MVP-DS] skrev:
>
>> Hello Jake,
>>
>> You have to run adprep /forestprep in the forest and adprep
>> /domainprep in each domain contained in the forest. If the Domain was
>> 2000 also run adprep /domainprep /gpprep and if you think about
>> adding RODCs in the future run directly adprep /rodcprep.
>>
>> Also see:
>> http://technet.microsoft.com/en-us/library...728(WS.10).aspx
>> Best regards
>>
>> Meinolf Weber
>>

> Thanks Meinolf,
>
> BTDT... There is only one domain in the forest and one domain
> controller running w2003. Domain was at 2003 functional level and
> forest at 2000 functional level.
>
> We used the w2008 dvd's adprep at w2003 and run adprep /forestprep
> which took several minutes and completed without any error message.
>
> However w2008 still claimed not being able to promote and still wanted
> adprep /forestprep to be run.
>
> We rebooted both the w2003 and w2008 boxes. Same problem.
>
> w2003's Domains and Trusts properties still claims that forest
> functional level is Windows 2000
>
> adprep /forestprep and adprep /domainprep halt with message 'Changes
> already applied, quitting'.
>
> I have also tried to run w2003CD's adprep /forestprep to rise it from
> 2000 to 2003, but the same message pops up.
>
> What do we do now...?
>
> regards
>
> jake
>
 
A

Ace Fekay [MCT]

"Jake" wrote in message
news:uIeqEYbRKHA.4048@TK2MSFTNGP05.phx.gbl...
> Meinolf Weber [MVP-DS] skrev:
>> Hello Jake,
>>
>> You have to run adprep /forestprep in the forest and adprep /domainprep
>> in each domain contained in the forest. If the Domain was 2000 also run
>> adprep /domainprep /gpprep and if you think about adding RODCs in the
>> future run directly adprep /rodcprep.
>>
>> Also see:
>> http://technet.microsoft.com/en-us/library...728(WS.10).aspx
>>
>> Best regards
>>
>> Meinolf Weber

>
> Thanks Meinolf,
>
> BTDT... There is only one domain in the forest and one domain controller
> running w2003. Domain was at 2003 functional level and forest at 2000
> functional level.
>
> We used the w2008 dvd's adprep at w2003 and run adprep /forestprep which
> took several minutes and completed without any error message.
>
> However w2008 still claimed not being able to promote and still wanted
> adprep /forestprep to be run.
>
> We rebooted both the w2003 and w2008 boxes. Same problem.
>
> w2003's Domains and Trusts properties still claims that forest functional
> level is Windows 2000
>
> adprep /forestprep and adprep /domainprep halt with message 'Changes
> already applied, quitting'.
>
> I have also tried to run w2003CD's adprep /forestprep to rise it from 2000
> to 2003, but the same message pops up.
>
> What do we do now...?
>
> regards
>
> jake


In addition to the adprep logs Meinolf requested, please post an ipconfig
/all of your two current DCs, and of the 2008 machine. Also post any Event
log errors (EventID # and Source name).

There may be something else going on, which could be based on configuration.
The event log errors, along with the ipconfigs will help in evaluation.

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Please reply back to the newsgroup or forum for collaboration benefit among
responding engineers, and to help others benefit from your resolution.

Ace Fekay, MCT, MCTS 2008, MCTS Exchange, MCSE, MCSA 2003 & 2000, MCSA
Messaging
Microsoft Certified Trainer

For urgent issues, please contact Microsoft PSS directly. Please check
http://support.microsoft.com for regional support phone numbers.
 
J

Jake

Meinolf Weber [MVP-DS] skrev:
> Hello Jake,
>
> Please run adprep /domainprep from the 2008 installation disk and after
> that post the complete adprep logfile.
>
> Best regards
>
> Meinolf Weber


Meinolf,

Thanks for your help. As you saw I had already rerun adprep /domainprep
from the w2008 dvd, but I redid it as you requested. Here is the log
file for the latest run:




Adprep created the log file ADPrep.log under
C:\WINDOWS\debug\adprep\logs\20091005144444 directory.



Adprep copied file C:\adprep\schema.ini from installation point to local
machine under directory C:\WINDOWS.



Adprep copied file C:\adprep\schupgrade.cat from installation point to
local machine under directory C:\WINDOWS\system32.



Adprep copied file C:\adprep\PAS.ldf from installation point to local
machine under directory C:\WINDOWS\system32.



Adprep successfully made the LDAP connection to the local Active
Directory Domain Controller PETER.



Adprep was about to call the following LDAP API. ldap_search_s(). The
base entry to start the search is (null).



LDAP API ldap_search_s() finished, return code is 0x0



Adprep successfully retrieved information from the local Active
Directory Domain Services.



Adprep successfully initialized global variables.

[Status/Consequence]

Adprep is continuing.



Domain-wide information has already been updated.

[Status/Consequence]

Adprep did not attempt to rerun this operation.



Adprep was about to call the following LDAP API. ldap_search_s(). The
base entry to start the search is
cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN.



LDAP API ldap_search_s() finished, return code is 0x0



Adprep checked to verify whether operation
cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN
has completed.

[Status/Consequence]

The operation GUID already exists so Adprep did not attempt to rerun
this operation but is continuing.



Adprep was about to call the following LDAP API. ldap_search_s(). The
base entry to start the search is
cn=446f24ea-cfd5-4c52-8346-96e170bcb912,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN.



LDAP API ldap_search_s() finished, return code is 0x0



Adprep checked to verify whether operation
cn=446f24ea-cfd5-4c52-8346-96e170bcb912,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN
has completed.

[Status/Consequence]

The operation GUID already exists so Adprep did not attempt to rerun
this operation but is continuing.



Adprep was about to call the following LDAP API. ldap_search_s(). The
base entry to start the search is
cn=51cba88b-99cf-4e16-bef2-c427b38d0767,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN.



LDAP API ldap_search_s() finished, return code is 0x0



Adprep checked to verify whether operation
cn=51cba88b-99cf-4e16-bef2-c427b38d0767,cn=Operations,cn=DomainUpdates,cn=System,DC=ELEVNETT,DC=LAN
has completed.

[Status/Consequence]

The operation GUID already exists so Adprep did not attempt to rerun
this operation but is continuing.
 
J

Jake

Ace Fekay [MCT] skrev:

> In addition to the adprep logs Meinolf requested, please post an ipconfig
> /all of your two current DCs, and of the 2008 machine. Also post any Event
> log errors (EventID # and Source name).
>
> There may be something else going on, which could be based on configuration.
> The event log errors, along with the ipconfigs will help in evaluation.
>


Ace,

There certainly is more going on. First is w2003 dc dns log events,
then same server's ipconfig and last is w2008 ipconfig. Will be offline
a couple of hours but rush back after that. Thanks a lot for any help.

jake


From w2003 dc's dns events:

After reboot - DNS server started and then...:

4015 The DNS server has encountered a critical error from the Active
Directory. Check that the Active Directory is functioning properly. The
extended error debug information (which may be empty) is "". The event
data contains the error.

4004 The DNS server was unable to complete directory service enumeration
of zone .. This DNS server is configured to use information obtained
from Active Directory for this zone and is unable to load the zone
without it. Check that the Active Directory is functioning properly and
repeat enumeration of the zone. The extended error debug information
(which may be empty) is "". The event data contains the error.

4004 The DNS server was unable to complete directory service enumeration
of zone _msdcs.mylocaldomain.LAN. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable
to load the zone without it. Check that the Active Directory is
functioning properly and repeat enumeration of the zone. The extended
error debug information (which may be empty) is "". The event data
contains the error.

4004 The DNS server was unable to complete directory service enumeration
of zone 100.25.172.in-addr.arpa. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable
to load the zone without it. Check that the Active Directory is
functioning properly and repeat enumeration of the zone. The extended
error debug information (which may be empty) is "". The event data
contains the error.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

4004 The DNS server was unable to complete directory service enumeration
of zone mylocaldomain.LAN. This DNS server is configured to use
information obtained from Active Directory for this zone and is unable
to load the zone without it. Check that the Active Directory is
functioning properly and repeat enumeration of the zone. The extended
error debug information (which may be empty) is "". The event data
contains the error.

4004 The DNS server was unable to complete directory service enumeration
of zone LAN. This DNS server is configured to use information obtained
from Active Directory for this zone and is unable to load the zone
without it. Check that the Active Directory is functioning properly and
repeat enumeration of the zone. The extended error debug information
(which may be empty) is "". The event data contains the error.

w2003 dc ipconfig

C:\adprep>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : peter
Primary Dns Suffix . . . . . . . : mylocaldomain.LAN
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : mylocaldomain.LAN

Ethernet adapter NIC OnBoard Top - Classrooms:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel
 
M

Meinolf Weber [MVP-DS]

Hello Jake,

PETER doesn't use x.x.x.11 as DNS server, add that also as with the 2008
server. PETER2 is your WINS server, is this correct?

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Ace Fekay [MCT] skrev:
>
>> In addition to the adprep logs Meinolf requested, please post an
>> ipconfig /all of your two current DCs, and of the 2008 machine. Also
>> post any Event log errors (EventID # and Source name).
>>
>> There may be something else going on, which could be based on
>> configuration. The event log errors, along with the ipconfigs will
>> help in evaluation.
>>

> Ace,
>
> There certainly is more going on. First is w2003 dc dns log events,
> then same server's ipconfig and last is w2008 ipconfig. Will be
> offline a couple of hours but rush back after that. Thanks a lot for
> any help.
>
> jake
>
> From w2003 dc's dns events:
>
> After reboot - DNS server started and then...:
>
> 4015 The DNS server has encountered a critical error from the Active
> Directory. Check that the Active Directory is functioning properly.
> The extended error debug information (which may be empty) is "". The
> event data contains the error.
>
> 4004 The DNS server was unable to complete directory service
> enumeration of zone .. This DNS server is configured to use
> information obtained from Active Directory for this zone and is unable
> to load the zone without it. Check that the Active Directory is
> functioning properly and repeat enumeration of the zone. The extended
> error debug information (which may be empty) is "". The event data
> contains the error.
>
> 4004 The DNS server was unable to complete directory service
> enumeration of zone _msdcs.mylocaldomain.LAN. This DNS server is
> configured to use information obtained from Active Directory for this
> zone and is unable to load the zone without it. Check that the Active
> Directory is functioning properly and repeat enumeration of the zone.
> The extended error debug information (which may be empty) is "". The
> event data contains the error.
>
> 4004 The DNS server was unable to complete directory service
> enumeration of zone 100.25.172.in-addr.arpa. This DNS server is
> configured to use information obtained from Active Directory for this
> zone and is unable to load the zone without it. Check that the Active
> Directory is functioning properly and repeat enumeration of the zone.
> The extended error debug information (which may be empty) is "". The
> event data contains the error.
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> 4004 The DNS server was unable to complete directory service
> enumeration of zone mylocaldomain.LAN. This DNS server is configured
> to use information obtained from Active Directory for this zone and is
> unable to load the zone without it. Check that the Active Directory
> is functioning properly and repeat enumeration of the zone. The
> extended error debug information (which may be empty) is "". The event
> data contains the error.
>
> 4004 The DNS server was unable to complete directory service
> enumeration of zone LAN. This DNS server is configured to use
> information obtained from Active Directory for this zone and is unable
> to load the zone without it. Check that the Active Directory is
> functioning properly and repeat enumeration of the zone. The extended
> error debug information (which may be empty) is "". The event data
> contains the error.
>
> w2003 dc ipconfig
>
> C:adprep>ipconfig /all
>
> Windows IP Configuration
>
> Host Name . . . . . . . . . . . . : peter
> Primary Dns Suffix . . . . . . . : mylocaldomain.LAN
> Node Type . . . . . . . . . . . . : Hybrid
> IP Routing Enabled. . . . . . . . : No
> WINS Proxy Enabled. . . . . . . . : No
> DNS Suffix Search List. . . . . . : mylocaldomain.LAN
> Ethernet adapter NIC OnBoard Top - Classrooms:
>
> Connection-specific DNS Suffix . :
> Description . . . . . . . . . . . : Intel
 
A

Ace Fekay [MCT]

"Jake" wrote in message
news:eLoTI%23bRKHA.4476@TK2MSFTNGP02.phx.gbl...

> Ace,
>
> There certainly is more going on. First is w2003 dc dns log events, then
> same server's ipconfig and last is w2008 ipconfig. Will be offline a
> couple of hours but rush back after that. Thanks a lot for any help.
>
> jake
>
>
> From w2003 dc's dns events:
>
> After reboot - DNS server started and then...:
>
> 4015 The DNS server has encountered a critical error from the Active
> Directory. Check that the Active Directory is functioning properly. The
> extended error debug information (which may be empty) is "". The event
> data contains the error.
>
> 4004 The DNS server was unable to complete directory service enumeration
> of zone .. This DNS server is configured to use information obtained from
> Active Directory for this zone and is unable to load the zone without it.
> Check that the Active Directory is functioning properly and repeat
> enumeration of the zone. The extended error debug information (which may
> be empty) is "". The event data contains the error.
>
> 4004 The DNS server was unable to complete directory service enumeration
> of zone _msdcs.mylocaldomain.LAN. This DNS server is configured to use
> information obtained from Active Directory for this zone and is unable to
> load the zone without it. Check that the Active Directory is functioning
> properly and repeat enumeration of the zone. The extended error debug
> information (which may be empty) is "". The event data contains the error.
>
> 4004 The DNS server was unable to complete directory service enumeration
> of zone 100.25.172.in-addr.arpa. This DNS server is configured to use
> information obtained from Active Directory for this zone and is unable to
> load the zone without it. Check that the Active Directory is functioning
> properly and repeat enumeration of the zone. The extended error debug
> information (which may be empty) is "". The event data contains the error.
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> 4004 The DNS server was unable to complete directory service enumeration
> of zone mylocaldomain.LAN. This DNS server is configured to use
> information obtained from Active Directory for this zone and is unable to
> load the zone without it. Check that the Active Directory is functioning
> properly and repeat enumeration of the zone. The extended error debug
> information (which may be empty) is "". The event data contains the error.
>
> 4004 The DNS server was unable to complete directory service enumeration
> of zone LAN. This DNS server is configured to use information obtained
> from Active Directory for this zone and is unable to load the zone without
> it. Check that the Active Directory is functioning properly and repeat
> enumeration of the zone. The extended error debug information (which may
> be empty) is "". The event data contains the error.
>
> w2003 dc ipconfig
>
> C:adprep>ipconfig /all
>
> Windows IP Configuration
>
> Host Name . . . . . . . . . . . . : peter
> Primary Dns Suffix . . . . . . . : mylocaldomain.LAN
> Node Type . . . . . . . . . . . . : Hybrid
> IP Routing Enabled. . . . . . . . : No
> WINS Proxy Enabled. . . . . . . . : No
> DNS Suffix Search List. . . . . . : mylocaldomain.LAN
>
> Ethernet adapter NIC OnBoard Top - Classrooms:
>
> Connection-specific DNS Suffix . :
> Description . . . . . . . . . . . : Intel
 
H

Hugo

Hi Jake !

Did you tried to raise all fonctional level to 2003 ?

Hugo


"Jake" a écrit dans le message de groupe de discussion :
uIeqEYbRKHA.4048@TK2MSFTNGP05.phx.gbl...
> Meinolf Weber [MVP-DS] skrev:
>> Hello Jake,
>>
>> You have to run adprep /forestprep in the forest and adprep /domainprep
>> in each domain contained in the forest. If the Domain was 2000 also run
>> adprep /domainprep /gpprep and if you think about adding RODCs in the
>> future run directly adprep /rodcprep.
>>
>> Also see:
>> http://technet.microsoft.com/en-us/library...728(WS.10).aspx
>>
>> Best regards
>>
>> Meinolf Weber

>
> Thanks Meinolf,
>
> BTDT... There is only one domain in the forest and one domain controller
> running w2003. Domain was at 2003 functional level and forest at 2000
> functional level.
>
> We used the w2008 dvd's adprep at w2003 and run adprep /forestprep which
> took several minutes and completed without any error message.
>
> However w2008 still claimed not being able to promote and still wanted
> adprep /forestprep to be run.
>
> We rebooted both the w2003 and w2008 boxes. Same problem.
>
> w2003's Domains and Trusts properties still claims that forest functional
> level is Windows 2000
>
> adprep /forestprep and adprep /domainprep halt with message 'Changes
> already applied, quitting'.
>
> I have also tried to run w2003CD's adprep /forestprep to rise it from 2000
> to 2003, but the same message pops up.
>
> What do we do now...?
>
> regards
>
> jake
 
J

Jake

Ace Fekay [MCT] skrev:
>
> Thanks for posting this info.
>
> I would suggest on the 2003 machine to leave DNS pointing to itself, but add
> the 2008 machine as the second DNS entry.

Done.

> On the 2008 machine, if DNS is installed, make it point to itself first, and
> 2003 machine as the second entry.

Done.
>
> Windows 2008 has a missing WINS entry. Not that it matters with this issue,
> but you'll want to add that to be consitent.

Fixed.
>
> Are 172.25.100.11 and 172.25.100.10 other DCs?

..11 has been removed. .10 is the current master DC. Will be denoted
when i have two new w2008 dcs and these dns /ad issues have been resolved.
>
> When you went through the domain rename process, were there any errors
> encountered?

That was years ago. Not that I remember, the process itself went
without any error messages, but I saw that was dns red events after each
reboot of the server. Everything worked fine though, so it hasn't been
addressed before now when I want all ok in the process of moving to w2008.
>
> Does the zone mylocaldomain.LAN exist in DNS, and are updates allowed?

_msdcs.mydomain.lan allows for secure (only) updates
mylocaldomain.lan and .lan exists as forward dns zones

But there is more to it than this. There must be a reason that I cannot
raise my forest functional level any higher than w2000 level. What do
I do now...?

thanks again, this is a great coimmunity

jake
 
J

Jake

Meinolf Weber [MVP-DS] skrev:
> Hello Jake,
>
> PETER doesn't use x.x.x.11 as DNS server, add that also as with the 2008
> server. PETER2 is your WINS server, is this correct?
>
> Best regards
>
> Meinolf Weber


...11 has been denoted and removed some time ago, sorry about that.

Peter-2 (w2008) will be my master DC when I (we) have resolved these
issues.

..13 (Peter) is currently my wins server. Peter-2 will take over as wins
server when I transfer the fsmo roles later.

jake
 
J

Jake

Hugo skrev:
> Hi Jake !
>
> Did you tried to raise all fonctional level to 2003 ?
>
> Hugo


That was when it all began. Even w2008's adprep /forestprep did not
manage to raise the forest functional level from 2000 to 2003...

jake
 
A

Ace Fekay [MCT]

"Jake" wrote in message
news:u3MD2jdRKHA.4116@TK2MSFTNGP04.phx.gbl...
> Ace Fekay [MCT] skrev:
>>
>> Thanks for posting this info.
>>
>> I would suggest on the 2003 machine to leave DNS pointing to itself, but
>> add the 2008 machine as the second DNS entry.

> Done.
>
>> On the 2008 machine, if DNS is installed, make it point to itself first,
>> and 2003 machine as the second entry.

> Done.
>>
>> Windows 2008 has a missing WINS entry. Not that it matters with this
>> issue, but you'll want to add that to be consitent.

> Fixed.
>>
>> Are 172.25.100.11 and 172.25.100.10 other DCs?

> .11 has been removed. .10 is the current master DC. Will be denoted when
> i have two new w2008 dcs and these dns /ad issues have been resolved.
>>
>> When you went through the domain rename process, were there any errors
>> encountered?

> That was years ago. Not that I remember, the process itself went without
> any error messages, but I saw that was dns red events after each reboot of
> the server. Everything worked fine though, so it hasn't been addressed
> before now when I want all ok in the process of moving to w2008.
>>
>> Does the zone mylocaldomain.LAN exist in DNS, and are updates allowed?

> _msdcs.mydomain.lan allows for secure (only) updates
> mylocaldomain.lan and .lan exists as forward dns zones
>
> But there is more to it than this. There must be a reason that I cannot
> raise my forest functional level any higher than w2000 level. What do I
> do now...?
>
> thanks again, this is a great coimmunity
>
> jake


You are welcome!

As far as not being able to raise the functional levels, what errors are you
getting? Is there an old 2000 DC still referenced in the AD database? Use
Metadata cleanup to insure that all DCs that were previously removed, are
actually gone out of the database. Use the following to guide you.

Cleanup (Metadata Cleanup) the AD database from the crashed DC - How to
remove data in Active Directory after an unsuccessful domain controller
demotion
http://support.microsoft.com/kb/216498

Ace
 
F

Florian Frommherz [MVP]

Jake,

Jake schrieb:
> That was when it all began. Even w2008's adprep /forestprep did not
> manage to raise the forest functional level from 2000 to 2003...


What do you mean? /forestprep doesn't do that automatically - raising a
forest functional level is a different thing from installing the schema.

Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
 
A

Ace Fekay [MCT]

"Florian Frommherz [MVP]" wrote in
message news:%23R2%233YeRKHA.1280@TK2MSFTNGP04.phx.gbl...
> Jake,
>
> Jake schrieb:
>> That was when it all began. Even w2008's adprep /forestprep did not
>> manage to raise the forest functional level from 2000 to 2003...

>
> What do you mean? /forestprep doesn't do that automatically - raising a
> forest functional level is a different thing from installing the schema.
>
> Cheers,
> Florian


I missed this post. Good thought, and I agree. Possibly Jake meant he tried
to raise it using normal procedures?

Ace
 
J

Jake

Florian Frommherz [MVP] skrev:
> Jake,
>
> Jake schrieb:
>> That was when it all began. Even w2008's adprep /forestprep did not
>> manage to raise the forest functional level from 2000 to 2003...

>
> What do you mean? /forestprep doesn't do that automatically - raising a
> forest functional level is a different thing from installing the schema.
>
> Cheers,
> Florian

Got me with the pants down here. I thought adprep /forestprep would do that.

I opened AD Domains and Trusts and right clicked the domain name. Only
Raise Domain functional level... and not Raise Forest functional
level... appeared at the context meny list.

So how do I raise my Forest functional level in my w2003R2sp2?

regards
jake
 
J

Jake

Ace Fekay [MCT] skrev:
> I missed this post. Good thought, and I agree. Possibly Jake meant he tried
> to raise it using normal procedures?
>
> Ace
>

Pls elaborate 'normal procedures' (see my post above)..

jake
 
A

Ace Fekay [MCT]

"Jake" wrote in message
news:%23KtYPyeRKHA.5052@TK2MSFTNGP06.phx.gbl...
> Florian Frommherz [MVP] skrev:
>> Jake,
>>
>> Jake schrieb:
>>> That was when it all began. Even w2008's adprep /forestprep did not
>>> manage to raise the forest functional level from 2000 to 2003...

>>
>> What do you mean? /forestprep doesn't do that automatically - raising a
>> forest functional level is a different thing from installing the schema.
>>
>> Cheers,
>> Florian
>
> Got me with the pants down here. I thought adprep /forestprep would do
> that.
>
> I opened AD Domains and Trusts and right clicked the domain name. Only
> Raise Domain functional level... and not Raise Forest functional level...
> appeared at the context meny list.
>
> So how do I raise my Forest functional level in my w2003R2sp2?
>
> regards
> jake


No, that's not one of it's features.

In Domains and Trust. Which server are you on? 2003 or 2008?

If on the 2003 DC, what level does it say it's at? How about from the 2008
DC?

Ace
 
J

Jake

Ace Fekay [MCT] skrev:
> No, that's not one of it's features.
>
> In Domains and Trust. Which server are you on? 2003 or 2008?
>
> If on the 2003 DC, what level does it say it's at? How about from the 2008
> DC?
>
> Ace


I right-clicked Domains and Trusts domain name instead of its root node,
that's why I did not find the 'Raise forest functional level...' item.

The 'upgrade' went fine once I found out this. Both domain and forest
are at 2003 level now. I will come back later today with an update of
my DNS event situation. Thanks again for the help you provided.

jake
 
Back
Top Bottom