General discussion

Locked

Setting up 2nd DC over WAN in W2k?

By jaybrdie ·
Anyone familiar with setting up a single domain over a WAN? I've set up a test environment to try a single domain over a WAN. The first domain controller is running Acitve Directory (first controller in the network) with Proxy Server 2.0. The domain controller has two NICs (one internal and one external connected to the internet through DSL. I tried setting up a Server at my other location, set up a VPN to the first domain controller, and was even able to get it to join the domain. When I went to run DCPROMO I would get all the way to where it started the Active Directory installation and it would pop an error saying it can't find the domain controller for the domain.

Since this didn't work I decided to test another theory. I tookthe second server to the physical location of the Domain Controller, plugged into the local network and ran the DCPROMO utility without any problems. I took the second server down and set it up at the remote location. I set up the VPN between the two networks and tested the replication. Everything worked except one thing: I could no longer edit any policies. When I would right-click on a Organizational Unit, select properties, went to Group Policy and selected Edit or New I would get an error stating either I didn't have the appropriate permissions (I'm the Administrator) and/or the network path couldn't be found. I am still capable of editing the Group Policy Objects at the main domain controller but the policies won't propagate to the second domain controller. I've tried updating the DNS on both servers to point to the appropriate servers but with no success. I can't understand why I can edit the AD on either DC and it will replicate to the other but the Group Policy won't work on the second DC.

I'm wondering if this might have anything to do with the Proxy Server. If so why does it effect only the Group Policy?

This conversation is currently closed to new comments.

8 total posts (Page 1 of 1)  
| Thread display: Collapse - | Expand +

All Comments

Collapse -

Setting up 2nd DC over WAN in W2k?

by jmulvey In reply to Setting up 2nd DC over WA ...

I've had (and fixed) the exact same problems when using VPNs. Only in my case, I was using Windows 2000 RRAS instead of Proxy server.

In my case, I had NAT (Network Address Translation) installed on one of the Windows 2000 routers. This caused the problems you described above. My guess is that you will find you are not able to do LDAP queries across your VPN WAN.

Try disabling NAT, and making sure you can do LDAP queries across the WAN (the LDP tool is very useful for this testing). Then you should be able to DCPROMO and modify GPOs over the VPN.

Good luck, I know how frustrating this can be!!!

Collapse -

Setting up 2nd DC over WAN in W2k?

by jaybrdie In reply to Setting up 2nd DC over WA ...

I found that the problem wasn't with the LDAP queries or NAT. The problem was that I didn't give the Domain Controllers permission to pass through the firewall. I had access for only the Domain Users. Once I granted permission to the Domain Controllers to access the Proxy Server it worked ok. Thanks for the help though!

Collapse -

Setting up 2nd DC over WAN in W2k?

by flashelp In reply to Setting up 2nd DC over WA ...

I'd like to back up a few steps and know how you were able to get a server as a PDC to connect over DSL - I've ran into a stumbling block with this. My original config was a primary domain controler with 4 clients, using dialup. I just got DSL but could not connect. Well it connects, but the server gets no packets. I reinstalled - it works as a new install ... but when I promote it - it fails. If I demote it - it still fails. I've tried everything.. I'm on my 5th reinstall.

Collapse -

Setting up 2nd DC over WAN in W2k?

by jaybrdie In reply to Setting up 2nd DC over WA ...

I did try promoting remotely first but I couldn't get that to work either. I installed the second server onsite and promoted it there. After I had everything working locally I powered down the server then moved it to the new location. After I brought the Server up at the new location I established the VPN between the two servers using PPTP. Everything works great but I can't access Group Policy features on the remote server.

Collapse -

Setting up 2nd DC over WAN in W2k?

by jaybrdie In reply to Setting up 2nd DC over WA ...

I did try promoting remotely first but I couldn't get that to work either. I installed the second server onsite and promoted it there. After I had everything working locally I powered down the server then moved it to the new location. After I brought the Server up at the new location I established the VPN between the two servers using PPTP. Everything works great but I can't access Group Policy features on the remote server.

Collapse -

Setting up 2nd DC over WAN in W2k?

by Gregory W. Smith In reply to Setting up 2nd DC over WA ...

I understand you say DNS is properly configured, but could this be resolved using a HOSTS file? Just a thought.

Collapse -

Setting up 2nd DC over WAN in W2k?

by jaybrdie In reply to Setting up 2nd DC over WA ...

The problem isn't that the servers can't see each other. It's that Group Policy Objects won't work on any server but the Global Catalog Server. Everything in Active Directory will replicate flawlessly between the two servers except Policies.

Collapse -

Setting up 2nd DC over WAN in W2k?

by jaybrdie In reply to Setting up 2nd DC over WA ...

This question was closed by the author

Back to Windows Forum
8 total posts (Page 1 of 1)  

Related Discussions

Related Forums