Our organization is retiring one AD domain (ORANGE), and I'm tasked with moving all of our CIFS servers into a new AD domain (PURPLE). We have a trust relationship between them, and I've ACL'd every file with rights from both domains, ie.e. \\ORANGE-PROD1\ADMIN has Full Control for ORANGE\NAS-Admins and PURPLE\DEPT-NAS-Admins. I've been reading and re-reading Managing EMC® Celerra® for the Windows Environment and Configuring CIFS on Celerra and I think I've got a problem with my plan. Here are my high-level step to move CIFS servers from ORANGE to PURPLE:
Pre-stage computer object DEPT-PROD1 in PURPLE AD.
Unjoin CIFS server ORANGE\PROD1 from ORANGE AD (to free up the IP interface) with server_cifs -unjoin command
Create new CIFS server, DEPT-PROD1 on Celerra with server_cifs -create command
Join new CIFS server, PURPLE\DEPT-PROD1 to PURPLE AD with server_cifs -Join command
Re-create CIFS shares using server_export command
Delete old CIFS server ORANGE\PROD1 with server_cifs -delete command
My problem is, I think when I unjoin ORANGE-PROD1, the interface IF_PROD1 is still in use (can't find any docs that tell me one way or the other). Do I need to add a step to delete the CIFS server to free up the interface? I was hoping to not delete anything, until all steps were 100% complete. Is there anything else that I haven't accounted for?
When you create a new CIFS server (DEPT-PROD1) - you need an IP address for this CIFS server irrespective of whether you join it to the domain or not. Each CIFS server requires at least one unique IP Address on the network.
Having said that, if you unjoin PROD1 from Orange AD - the CIFS server is no more available to the users for access, but the CIFS server in still there on the Celerra and uses the IP Address what it had. That will not be an issue to my understanding when you use a New IP Address for the new CIFS server DEPT-PROD1.
In other words - on the Celerra, you have now two CIFS servers using two different IP Addresses - but only the new CIFS server is joined to the PURPLE AD and available to user access.
You need not to delete the old CIFS server on the Celerra as long as you don't need the same IP Address used by the old CIFS server.
Hope this answers your query.
On a side note - I am not sure what exactly you mean to say by "pre-stage computer object DEPT-PROD1 in Purple AD" - does that mean, you are creating a computer account in the AD beforehand? This may not be needed, as when you join the CIFS server from the Celerra, it automatically creates the Computer account in the AD under the specified OU.
By "pre-stage", I mean pre-create the computer account in AD. I get delegated authority to join CIFS servers to AD - our Windows team prefers to put the computers into a different OU, per an internal policy. This is to prevent me from goofing up where the object goes, and they can be sure it matches their naming convention.
Here's the wrinkle - I'd like to use the same IP address when the CIFS servers move between domains. We manage DNS in the new domain as well, but we get the IP allocations from another party. They're not willing to relinquish enough IP addresses for me to give the CIFS servers new IP addresses, so I'll need to reuse them. Yes - I know that users will experience an outage, if I have to temporarily remove the IP, but this decision is being driven by politics (wait, aren't all IT decisions basically political?!?).
So, I'll have to add a step for "delete CIFS server" before I can even create the new CIFS server with the same IP?
Thanks, Sandip - I just looked up Rainer's post on the interface stealing trick, and this looks pretty good.
I'm scheduled to make all of these changes April 25-30th, so I'll test this out over the next few weeks. If I have any other useful tips, tricks or "Do NOT do this!" discoveries, I'll put them here.
I am pretty confident, you NEED NOTto delete the old CIFS server - once you unjoin the old CIFS server from the domain, it still uses the IP Address - but what you can do is - you then create the new CIFS server and use the same IP Address which was used by the old CIFS server.
This will steal the Interface (IP Address) from the Old CIFS server to the new CIFS server. I remember, Rainer had mentioned Interface Stealing few times earlier in this forum - for some other purpose.
So, now - you have two CIFS servers - the new one is having the IP and joined to the Purple AD - the old one is unjoined and does not have any IP Address.
Hope this helps - to be in safer side, you may test this out before implementing,
So far, so good. On Friday, I tried to moved my first server with this procedure. However, the admins did not give me rights to unjoin the objects from the old AD (ORANGE) and the new AD (PURPLE). I shortened my steps to the following:
Pre-stage computer object DEPT-PROD1 in PURPLE AD
Unjoin CIFS server ORANGE\PROD1 from ORANGE AD (to free up the IP interface) with server_cifs -unjoin command
Delete old CIFS server ORANGE\PROD1 with server_cifs -delete command (this freed up the IP interface and left the old computer object in ORANGE AD)
Create new CIFS server, DEPT-PROD1 on Celerra with server_cifs -create command
Join new CIFS server, PURPLE\DEPT-PROD1 to PURPLE AD with server_cifs -Join command
Re-create CIFS shares using server_export command
Notify Windows Admins to remove the old computer objects from ORANGE AD
This worked swimmingly, save for lengthy AD DDNS and DC replication delays (almost 30 minutes). There was no need to recreate the share permissions - they were embedded in the filesystem (or perhaps hidden in .etc in the VDM, someplace). Users were disconnected from the NAS, when the old CIFS server was deleted, but most of them seemed to reconnect automatically when DNS finally lined up. All told, the process to move each CIFS server takes less than three minutes from the CLI - our own DNS delays made it take much longer.
I made a similar change today, moving two more CIFS servers. I saw the same DNS delays (on the AD side, again, not with the Celerra). I also discovered that the Windows guys appeared to pre-stage ACLs on the computer object (or perhaps they had a GPO that did it for them). When I joined one CIFS server, it had automatically picked up an administrative group from the new AD. If you've got access to this in your AD, you might want to take advantage of this.
It looks like it worked for you pretty good, I have a customer with over 100+ cifs servers planning to migrate all of them to a different domain as they are going to retire the current one. I did the same process on a test case and was fine and the customer had all ACL's and SID's intact. But I am planning to use Migrate/Replace instead of this process. The following is my approach. Can anybody comment on pros/cons of this approach Please.
Unjoined from AD domain <<<< To get the CIFS server to move to CTL the only way is to delete from AD and recreate (Add & Join) to CTL Domain) : NEED SOME VERIFICATION
nandas
6 Operator
•
1473 Posts
5113
0
Posted April 2nd, 2010 11:00
Hi Karl,
When you create a new CIFS server (DEPT-PROD1) - you need an IP address for this CIFS server irrespective of whether you join it to the domain or not. Each CIFS server requires at least one unique IP Address on the network.
Having said that, if you unjoin PROD1 from Orange AD - the CIFS server is no more available to the users for access, but the CIFS server in still there on the Celerra and uses the IP Address what it had. That will not be an issue to my understanding when you use a New IP Address for the new CIFS server DEPT-PROD1.
In other words - on the Celerra, you have now two CIFS servers using two different IP Addresses - but only the new CIFS server is joined to the PURPLE AD and available to user access.
You need not to delete the old CIFS server on the Celerra as long as you don't need the same IP Address used by the old CIFS server.
Hope this answers your query.
On a side note - I am not sure what exactly you mean to say by "pre-stage computer object DEPT-PROD1 in Purple AD" - does that mean, you are creating a computer account in the AD beforehand? This may not be needed, as when you join the CIFS server from the Celerra, it automatically creates the Computer account in the AD under the specified OU.
Thanks,
Sandip