Re: Whitepaper on win2003 DNS performance ?

From: Ace Fekay [MVP] (PleaseSubstituteMyActualFirstName&LastNameHere_at_hotmail.com)
Date: 01/03/05


Date: Sun, 2 Jan 2005 19:09:03 -0500

In news:OneHZhC8EHA.3700@tk2msftngp13.phx.gbl,
Marlon Brown <marlon_brownj@hotmail.com> made a post then I commented below
::: How many (major) network locations on the WAN?
:: I have 18 small branch offices (less than 150 people/office) that
:: currently come thru the T1 to authenticate.
:: Total of 5,000 users coming thru the T1 for authentication.

I would honestly put a DC/DNS server in each location with 150 or less
users. I understand you have a T1 from each location, but the
logon/authentication and DNS query traffic, besides Internet browsing and
email traffic can get quite heavy at peak times. Performance gains will be
realized immediately with a DC/DNS in each of these locations.

::: Largest LAN location? General size of other locations?
:: 4 major branch offices have one DC/GC per site; about 800
:: users/machines on remote branch offices.

That is fine from a design perspective for DC distribution and DNS
availability.

For more info on how to design and implement AD in a multi location branch
office scenario, along with DNS availability, see this article:

Active Directory Deployment including Branch Office Guide Series:
http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/activedirectory/deploy/adguide/default.mspx

Chapter 4 - Active Directory Design:
http://www.microsoft.com/resources/documentation/exchange/2000/all/reskit/en-us/part2/c04names.mspx

Chapter 9 - Designing the Active Directory Structure:
http://www.microsoft.com/resources/documentation/windows/2000/server/reskit/en-us/deploy/part3/chapt-9.mspx

Best Practice Active Directory Design for Managing Windows Networks [and
DNS]:
http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/activedirectory/plan/bpaddsgn.mspx

-- 
Regards,
Ace
G O   E A G L E S !!!
Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.
This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.
Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services
Security Is Like An Onion, It Has Layers
HAM AND EGGS: A day's work for a chicken;
A lifetime commitment for a pig.
-- 
=================================


Relevant Pages

  • Re: How to setup authentication across domains within a forest?
    ... forest, regardless of their location. ... DCs for the domain ... Windows 2003 Server Deployment Guide (Active Directory ... >> authentication db and users authenticate to the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forms Authentication non-persistent cookie not expiring after closing the browser
    ... If you authenticate against the Active Directory, why not host your solution under intergrated security? ... I use non-persistent cookie so ... that the user is NOT remembered across browser sessions. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Problems with Digest Authentication
    ... Active Directory will store a copy of their password ... > told to store the passwords using reversible encryption, ... > Digest/Advanced digest auth. ... > installing the webserver, I can't authenticate. ...
    (microsoft.public.inetserver.iis)
  • Re: How to change domain name?
    ... Only if you can go up to Windows Server 2003 Forest Functional Mode. ... to it with something like ADMT (Active Directory Migration Tool). ... > of joesfruitemporium.com with the old NT domain as 'apples'. ... > login they use the old NTdomain of apples\username to authenticate. ...
    (microsoft.public.win2000.active_directory)
  • RE: how to login a Windows domaine/user programaticaly in a Web Service ?
    ... You need to authenticate the users against the Active Directory. ... This causes ASP.NET to impersonate the account that is configured as the ... As a result of this configuration, ...
    (microsoft.public.dotnet.framework.aspnet.security)