Suggested Number of Active Directory Site Links For a Small Network

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello,
I have a small network that consists of 5 geographical sites with a
single DC at each location. All 5 sites are interconnected by VPN
tunnels in a mesh topology (meaning each site has a direct VPN tunnel
to each location). Each location has the same connection speed to the
ISP (about 1024K). Three sites have about around 40 users and the
others have much less.

Currently they are still using the DefaultSiteLink. Boss likes that
all DCs can get updates from any server. I think a separate site link
should be created for each location pointing back to the home office
where the 1st DC is located.

1. The other admin feels the company is to small to create separate
site links. Do you agree?
2. Please get me more knowledge to backup my reasoning for create
separate site links.
3. Please explain any other thoughts you may have that says why we
should not have all 5 sites using the same DefaultSiteLink.
4. How much bandwidth can replication eat up on a small network like
this?

.



Relevant Pages

  • Re: Possibility of routing through internet with private IP address
    ... > VPN tunnels from the WAN side end at the netscreen. ... and have the packets routed back to them properly? ... Better Management for Network Security ...
    (Security-Basics)
  • RE: Possibility of routing through internet with private IP address
    ... or spoofed source addresses such as private ranges) with VPN ... tunnels, even when both were on the same NetScreen box. ... Better Management for Network Security ...
    (Security-Basics)
  • Re: PIX vpn client cant terminal server
    ... network between different cities, in addition to this we use vpn ... tunnels with cisco PIX because one of the cities isn't on the other ... can connect via vpn to other city. ... other vpn tunnels do. ...
    (comp.dcom.sys.cisco)
  • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
    ... This set of steps is redundant in many places, and it's also enormously expensive, since you're using no less than three different expensive bits of networking hardware (AP, PIX, VPN Concentrator), in addition to a bunch of x86 server hardware, windows server licenses, and at least one ISA license. ... Your computers necessarily don't have full access to your network infrastructure when they aren't logged on, so GPOs, software updates, etc can't be applied at the times you want them to be applied. ... Turning on, enabling, and implementing every possible security setting and device you think of is not defence in depth, and will probably only have two effects - your users won't use your wireless network, and you'll burn so much cash you won't have any left to spend on *useful* security measures. ...
    (Full-Disclosure)
  • TidBITS#792/15-Aug-05
    ... We also note the release of Security Update 2005-007, ... Macintosh FTP client, free for educational and charitable use. ... mentioned virtual private network (VPN) technologies. ...
    (comp.sys.mac.digest)