Score:0

Migrating Old Active directory Forest with two domains

in flag

We have single AD forest with two domains as follows:

Domain A:

  • Contains nearly 30 servers (7 physicals and 23 VMs) all hosted on Microsoft Hyper-V server
  • Nearly 500 Active user accounts
  • A huge file server with 3 TB active data on nearly 4000 share folders
  • A DHCP server that serve around 100 VLANs is member of this Domain
  • Two domain controllers in domain A are running on W2k12R2 with highest domain and forest Functional level
  • Almost all critical servers are located in this domain apart from Print server located in domain B

Domain B:

  • Contain two domain controllers in domain A are running on W2k12R2 with highest domain Functional level
  • A print server is located in This domain and contain around 150 network printers
  • Nearly 4000 user accounts(nearly 2000 are active)
  • A Huge file server with 5 TB of data on nearly 2000 share folders

General information

  • Domain A is forest root Domain
  • In summery we have four virtualized domain controllers running on W2K12R2
  • All servers (for both domains) are part on single Vlan and we use Microsoft Network policy server for Dynamic Vlan on domain controllers
  • Dynamic vlan will be used for wireless devices like phones
  • Now the management forced us to create a single domain with new name and merge both domains (create domain C in brand new forest)

My plan is to promote new W2K22 to a domain controller then the second one, and enable bidirectional forest trust between both forests in order to both domains can operate normally and ensure work continuity Install AD migration toolkit on both domains and start migrating to Domain c gradually

My questions:

Is creating new Vlan necessary for domain C or is it OK to have both forests old and new one in the same Vlan? Because if I create a new vlan for domain c network people have to do lots of works since we heavily rely on firewalls for vlan interconnecting. How can I migrate the DHCP server I cant see this part?

Any ideas or help will be appreciated.

Score:1
cv flag

VLAN's don't have anything to do with AD, so yes, put the new domain servers in the same VLAN unless you have specific security needs or restrictions that would require putting the new servers in a separate VLAN. It seems to me that there probably wouldn't or shouldn't be any reason to put the new servers in a separate VLAN.

As for migrating the DHCP server, install DHCP on the new server. Export the DHCP configuration from the old server and import it to the new server.

John Rese avatar
in flag
many thanks for the replay and sorry for the late reply I was busy with COVID during past couple of weeks . one more thing to ask if you don't mind my current root domain is abc.local and the secont domain is xyz-abc.local now i want to have single domain with name abc.something.com here is an issue the NetBIOS name shows ABC0 since they can see each other on the network moreover when I promote the new forest NetBIOS name for the new forest will became ABC0 is that okay ?
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.