Re: Active Directory Desgin Advice
- From: "wolfyrabbit" <wolfyrabbit@xxxxxxxxx>
- Date: 13 Feb 2006 22:05:31 -0800
Hi Cary,
Thanks for your reply. I have a few (more) questions :
Ok if I setup a network with Sonicwall site-to-site VPNs like this :
internal main site : 172.22.0.x
internal branch : 172.24.0.x
the branch dc will be dc promo'd once branch firewall is installed and
configured to tunnel / route traffic destined for 172.24 over a
"Sonicwall site to site vpn" via public internet. Therefore whenever
either network needs to get to each other it will go via a virtual
interface over the sonicwall site to site vpn and hence AD sites will
be configured as their (real) 172.2x.x.x ip and hence can take
advantage of the AD sites and services and also therefore not require
multiple AD domains, correct ?
Re point 2) I had envisioned there being a DC (configured as a Global
CAtalog) at each site. I read that you need to put the rpc proxy server
in order to use http over rpc ?
See http://support.microsoft.com/default.aspx?scid=kb;en-us;833401
(article suggests that this is true for a single server setup, but does
not say whether it pertains to single exchange server or a single
server network or single dc ?)
The satellite offices have between 4 - 6 users. 20 users total.
I need to weigh up the pros and cons of having a local server vs
running all apps on terminal server. The first major obstacle is that I
do not think that all apps will run on terminal server nicely.
Ideal situation is that all apps run on a TS, although it then gets
more complicated as if a someone needs to work in a non ts environment
they will have to pull data off from over the sonicwall site-to-site
vpn. Management of the workstation then becomes tricky as WSUS updates
then need to be pushed over the site-to-site vpn. If the TS fails then
everyone stops (having 10 lawyers twiddling their thumbs is a bad
thing).
All of these limit the efficacy of having a ts only environment as
having a branch server is a small price to pay for increased flexiblity
?
Maybe a Citrix Cluster would be the thing to go with if TS is a go ?
.
- Follow-Ups:
- Re: Active Directory Desgin Advice
- From: Cary Shultz
- Re: Active Directory Desgin Advice
- References:
- Active Directory Desgin Advice
- From: wolfyrabbit
- Re: Active Directory Desgin Advice
- From: Cary Shultz
- Active Directory Desgin Advice
- Prev by Date: Re: Automatically disable expired user accounts
- Next by Date: RE: Certificate Authority is also a DC, want to demote?
- Previous by thread: Re: Active Directory Desgin Advice
- Next by thread: Re: Active Directory Desgin Advice
- Index(es):
Relevant Pages
|