Re: Branch offices and not stable WAN links

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



In news:%23YT$vYKpFHA.3756@xxxxxxxxxxxxxxxxxxxx,
Rytis <ask@xxxxxx> made this post, which I then commented about below:
> We have a lot of small branch offices (~5-10 PCs in each), which
> connects to our central office via slow WAN links (256 kbps). And
> these WAN links are not stable - usualy their are down from 10 min to
> ~1 hrs per day. And all branch offices have their own file server.
> In our central office we have Windows 2003 domain. We decided to join
> all branch offices PCs (and servers of course) to our domain. All
> branch offices will use DCs in our central office for authentication.
>
> The problem is that when WAN link goes down, users in branch can not
> access files located in branch`s file server (it is critical point).
> My task is to find a solution, how users can access files on file
> server, when the WAN link is down (= the DC is not accessible).
> One guy recommend us to disable Kerberos.
> How to do this? I found a GP setting in Default Domain policy
> "Enforce user logon restrictions" (Computer Configuration\Windows
> Settings\Security Settings\Account Policies\Kerberos Policy), which
> is Enabled by default in Windows 2003 domain enviroment. Is this can
> help?
> Or maybe there are other solutions or ideas?
>
> Thanks
> Rytis
>
> P.S.
> a) It is impossible to place DC on each branch office.
> b) It is impossible to rise WAN link quality (stability)

I would choose both A and B above. A to have a DC locally so logon and
authentication traffic doesnt consume the WAN link, which it's doing now. I
bet half the traffic going across it now is authentication traffic.

B because AD's default threshold to indicate a "slow" link is 512k. 256k is
way below it. Below this level, many things do not come across, such as
GPOs, and other vital configuration during the logon process.

I wouldn't disable Kerberos. Update your infrastructure to properly support
AD, and provide a DC at each location if there are more than 5 users (that's
my magic number).

--
Regards,
Ace

Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.

This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services
Infinite Diversities in Infinite Combinations.
=================================


.



Relevant Pages

  • Re: DFS and RODC Windows Server 2008
    ... replicate branch data from the branch offices back to corporate for ... map their drives to the branch office server and you would use DFSR ... to replicate the shared folder back to corporate. ... these shares to the head office? ...
    (microsoft.public.windows.server.active_directory)
  • Re: DFS and RODC Windows Server 2008
    ... replicate branch data from the branch offices back to corporate for ... map their drives to the branch office server and you would use DFSR ... to replicate the shared folder back to corporate. ... these shares to the head office? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Fat Client and VPN vs MS Terminal Services
    ... bandwidth, existing client hardware, server hardware and so on. ... Terminal services would require the server to be able to handle all ... > branch offices have no email capability. ...
    (microsoft.public.win2000.networking)
  • RE: 2nd Branch Server and Laptop configuration suggestion
    ... Setup the VPN connections between main office and branch offices. ... please ensure the offices' servers are not SBS server (I suggest use ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Connectivity issues
    ... We are running an SBS2003 std server and are having some connectivity ... The server is located at our HQ and we then have six branch offices ... The HQ is connecting to the datacenter by VPN using a Cisco VPN3002 hardware ...
    (microsoft.public.windows.server.sbs)