Re: Win2k server in remote office

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Mark Warbeck (mwarbeck_at_vt.edu)
Date: 05/28/04


Date: Fri, 28 May 2004 12:29:36 -0400

Not sure about possible VPN issues, but with regard to making the server a
DC, you should consider if you can physically secure the machine (place it
behind locked doors with limited key distribution). In not, don't make it a
DC, since without physical security there is no security at all. If you can
secure it, try to determine how much authentication traffic the users in the
remote office will generate. If you have more than five or ten users, it may
be a good idea to make it a DC. DNS doesn't add much load to a machine so it
may be wise to make it a DNS server with an AD-integrated zone. Since
clients will be looking to DNS for locating the DC, WINS shouldn't be needed
unless you're running applications that need it.

"Randall" <aim7sparrow@hotmail.com> wrote in message
news:eX3Vy2MREHA.628@TK2MSFTNGP11.phx.gbl...
> Hello;
>
> I am going to deploy a Win2k servers in remote offices for file storage
and
> printing. Currently, all workstations are in the domain. The AD
> controllers are at the corporate office. The users transverse the WAN to
> authenticate to the Domain. The office will be connected via a VPN to the
> corporate office. DNS and WINS are also controlled from the corporate
> office, however, each office has it's own internet connection.
>
> Here's my questions:
>
> Any problems using a Branch to Branch VPN with Win2k/AD?
>
> Do I want the server in the remote office to be a Domain Controller?
>
> Do I want to make the remote office server a DNS server as well?
>
> Do I want to make the server a WINS server for the office?
>
> Thanks
>
>
>



Relevant Pages

  • Re: feeling dizzy about setting up a small remote office.
    ... | dcpromo a new server ... | - installed dns, killed the dns wizard ... | the remote end of the vpn tunnel. ... |> of the VPN router to its public IP address, ...
    (microsoft.public.windows.server.active_directory)
  • RE: VPN Clients Not Registering in AD DNS
    ... via VPN, the DNS records of the VPN clients are unable to be registered. ... Windows 2003 server? ... please let me know whether the clients get the IP ...
    (microsoft.public.windows.server.sbs)
  • Re: feeling dizzy about setting up a small remote office.
    ... dcpromo a new server ... - installed dns, killed the dns wizard ... the remote end of the vpn tunnel. ... > of the VPN router to its public IP address, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Error: cant find _ldap._tcp.dc._msdc.
    ... domain over a VPN? ... The DNS server name as listed in the DNS manager is cda.cdaxxxx.org.uk ... VPN connection to the top of the connections list. ...
    (microsoft.public.windows.server.dns)
  • Re: How to configure for Two different IP subnets
    ... Active Directory will go haywire in a setup like that. ... AD integrates with the local DNS, so you cannot use the DNS at your ISP ... With Server 2003 Standard ... for its internal interface (ie the VPN endpoint). ...
    (microsoft.public.windows.server.networking)