How should I migrate Windows DNS to new domain controllers with different IPs?

0
0
Asked By MellowQuasar47 On

We currently use two Windows Server 2016 domain controllers for DNS. I've built Server 2022 replacement domain controllers, but our IP addressing scheme has changed, so the new servers have different addresses. We also have many non-Windows devices configured with the existing DNS server IPs, and manually updating all of them could temporarily disrupt access to DNS. What is the safest migration strategy? Would assigning the old DNS IPs to a second network interface on the new domain controllers be reliable, or is there a better approach?

4 Answers

Answered By CopperWillow24 On

Another option is to avoid changing the resolver addresses at all: add the new servers, migrate the domain controller roles, then decommission the old DCs and assign their former addresses to the replacements one at a time. Keep another healthy DC available throughout the process, verify Sites and Services and DNS replication, and allow time for clients to refresh their resolver settings. This can reduce changes to firewall rules, documentation, appliances, and other systems that reference the old IPs.

Answered By NorthstarPine31 On

If you absolutely cannot update every legacy device immediately, put a temporary DNS forwarder or proxy on the old DNS addresses and have it forward requests to the new domain controllers. A dedicated DNS service is preferable to putting the old address on a DC. NAT can work as a short-term emergency measure, but DNS is not the only traffic domain controllers handle, so do not assume forwarding all traffic will preserve AD, RPC, SMB, TLS, or Netlogon functionality.

VioletKite_58 -

A DNS-only forwarder avoids pretending the new DC owns the old identity. Make sure the temporary service is restricted to DNS and has a removal date.

Answered By OrbitingMango6 On

The cleanest long-term fix is to update DHCP scopes and reservations so managed clients receive the new DNS servers automatically. For devices with static settings, use whatever remote-management or scripting tools you have, and check the old DNS server logs to identify systems that still need updating. This is also a good opportunity to stop hard-coding DNS and NTP servers on devices where possible.

MellowQuasar47 -

Most of the devices use DHCP, but some appliances have static network settings and can only be updated individually. I’ll make an inventory of those before the cutover.

Answered By CedarFox_82 On

Do not add a second NIC or reuse an old address on a domain controller. Multihomed DCs can register unexpected addresses through Netlogon and dynamic DNS, which can break domain controller discovery, authentication, SMB, and other Active Directory functions. Bring the new DCs online with their proper addresses, update clients gradually, transfer the required roles, and then retire the old DCs.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.