Re: AD Disaster Recovery Test in Lab Environment

From: Simon Geary (simon_geary_at_hotmail.com)
Date: 09/17/04


Date: Fri, 17 Sep 2004 11:23:17 +0100

I don't like the sound of your plan Jason, anything that involves having the
restored DC on the same routed network as the live AD is asking for trouble.
All you need for an isolated network is a cheap 10Mbit hub, you can pick up
one of these for a few pounds. It may be slow but it would do for testing.
As for the backups, why don't you use ntbackup on one of the live DC's to
take a System State backup to a flat .bkf file, then you can copy this file
to a laptop. Plug this laptop into your new hub and then restore AD in
isolation using that backup file.
Alternatively, if your restore hardware is identical to the live stuff, you
could take a Ghost image and restore that.

"Jason S" <JasonS@discussions.microsoft.com> wrote in message
news:D0E89EC5-D7B5-43F4-B89B-95154F31E9A6@microsoft.com...
> They are two different subnets, but the two subnets can talk to each other
> over the LAN. This is something I can't change for two reasons:
> 1. The tape backup and restore server is on the same subnet as the
> production servers and
> 2. I don't have access to the Cisco Equipment that would allow me to shut
> off communication between the two subnets.
>
> So I'm tasked with proving that we can recover with tape backups, but
> stuck
> in this corner of not being able to physically seperate the two. My
> thinking
> so far has been that if I restore one of the servers, unplug the network
> cable, reboot, change the IP address and DNS settings to it's new self,
> and
> reboot again, I should be able to plug in the network cable without issue,
> but I want to be sure.
>
> The only other thing I have been able to verify so far is that network
> broadcasts aren't crossing the two subnets.
>
> Jason
>
> "Simon Geary" wrote:
>
>> Do you mean that the test servers will be on the same physical subnet as
>> your production servers? i.e. the servers have connectivity to each
>> other?
>> If so, this would be a mistake, you shouldn't mix live and test servers
>> on
>> the same network, especially as in a DR scenario you may want to give the
>> DR
>> servers the same name as the live ones.
>> What you should do is create a physically isolated test lab which will
>> allow
>> you to experiment without risking your live servers.
>>
>> "Jason S" <Jason S@discussions.microsoft.com> wrote in message
>> news:65F14AEA-EECA-433C-8E1B-59969AEE4DD9@microsoft.com...
>> > Hello,
>> >
>> > I have a lab environment that I need to test DR with for our ADS and
>> > DNS
>> > servers. The problem is that I these servers can, and have to, see the
>> > same
>> > subnet as the production servers. I want to make sure I don't take
>> > down
>> > production when I perform the test. How can I do that?
>>
>>
>>



Relevant Pages

  • Help with initial small org AD setup convention when using DMZ network
    ... firewall which then connects the public IP dmz network to a private IP ... domain name for such subnets based on the nearest airport code, ... Yahoo to manage my externally-visible DNS names on the acme.com domain. ... and servers that use this domain, ...
    (microsoft.public.win2000.active_directory)
  • Re: Computer Browser/ Netbios Issue
    ... I look in DHCP and there wasnt any ... domains in "My Network Places" in place of Wins? ... browse - and if you want to browse across routed subnets you'll need it. ... transferred the DHCP information to the new servers and also ...
    (microsoft.public.windows.server.networking)
  • Re: Help with initial small org AD setup convention when using DMZ network
    ... Consider using Dynamic DNS internally (aka Active Directory Integrated ... > firewall which then connects the public IP dmz network to a private IP ... > domain name for such subnets based on the nearest airport code, ... > servers to serve acme.com names for external users. ...
    (microsoft.public.win2000.active_directory)
  • Re: Computer Browser/ Netbios Issue
    ... I look in DHCP ... those machines and domains in "My Network Places" in place of Wins? ... across routed subnets you'll need it. ... transferred the DHCP information to the new servers and also ...
    (microsoft.public.windows.server.networking)
  • Re: AD Disaster Recovery Test in Lab Environment
    ... You can isolated the network by restricting routing between production and ... Plug this laptop into your new hub and then restore AD ... > in isolation using that backup file. ... >> They are two different subnets, but the two subnets can talk to each ...
    (microsoft.public.win2000.active_directory)