Re: configuration of 2 remote sites
- From: Ryan Hanisco <RyanHanisco@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 20 Jun 2007 20:03:00 -0700
Dan,
I am jumping in here in the middle of the conversation, so forgive me if I
am repeating something that was stated earlier.
Generally, there are only a few circumstances where you want to create more
domains in your forest or a subdomain. These are: to provide security
boundaries (different security or password policies), to support
administrative fiat or regulatory compliance, to protect yourself from
geopolitical security issues.
Generally, you can handle most situations with a single domain and
appropriate use of OUs. There are exceptions to everything, but this is a
good general guideline.
Hope this helps.
--
Ryan Hanisco
MCSE, MCTS: SQL 2005, Project+
Chicago, IL
Remember: Marking helpful answers helps everyone find the info they need
quickly.
"Dan Andrews" wrote:
.I'm assuming that you want to add the new servers as additional DCs,
correct?
Yes, thats correct. So when running dcpromo on the remote sites I would
create an additional domain controller for an existing domain? Or create a
separate domain? NOTE: The users at the remote siites will need to access
the exchange mailboxes.
--
Thanks a lot,
Dan
"Jorge Silva" wrote:
please see inline
I will add the 2 remote sites into AD Sites and services at corporate withCorrect. You should (IMO) configure the sites and assign the proper subnets
the appropriate subnets, then when you say "When running DC promo..." you
mean on the 2 remote servers correct?
to these sites and then use IFM to promote the new additional servers, by
doing this way the servers will be automatically placed on the correct site.
Would these then be part of theI'm assuming that you want to add the new servers as additional DCs,
existing forest at Corporate?
correct? If I'm wrong, and you only want to add the new servers as member
servers (NO AD) then you shouldn't need to create additional Sites (unless
you're using DFS or any other app site aware), instead just assign the
subnet to the site where you want the servers to be authenticated.
--
I hope that the information above helps you.
Have a Nice day.
Jorge Silva
MCSE, MVP Directory Services
"Dan Andrews" <dan4u2@xxxxxxxxxxxxxxxx> wrote in message
news:1F3874EC-1ABE-4A3C-8808-F05F174DF7D7@xxxxxxxxxxxxxxxx
Thank you Jorge for your fast response! I have a couple questions if I
may?
I will add the 2 remote sites into AD Sites and services at corporate with
the appropriate subnets, then when you say "When running DC promo..." you
mean on the 2 remote servers correct? Would these then be part of the
existing forest at Corporate?
--
Thanks,
Dan
"Jorge Silva" wrote:
Hi
Create the Remote Sites on the Active Directory Sites and services,
configure and assign the correct subnet to that site(s).
To save bandwidth you can use IFM CHECK:
http://support.microsoft.com/kb/311078
When running Dcpromo, AD will automatically place the servers in the
correct
site assuming that you already configured them.
All the rest of the process is equal as adding a additional DC. Is a good
practice to have a DNS at these locations, the DC should be GC, because
you're using different subnets you may want to setup WINS at these remote
locations, etc...
--
I hope that the information above helps you.
Have a Nice day.
Jorge Silva
MCSE, MVP Directory Services
"Dan Andrews" <dan4u2@xxxxxxxxxxxxxxxx> wrote in message
news:D89C206C-2679-4C77-A9E3-048605E2A548@xxxxxxxxxxxxxxxx
Hello,
I am looking for some help on how to setup 2 remote locations and
what
is
required. Corporate has 2 windows 2003 servers 1 domain controller 1
exchange server as a member server. We need to setup 2 remote
locations
and
are purchasing 2 new servers running 2003 server. There will be a vpn
configured to corporate from each of the locations. What is the
recommended
setup for the remote locations? Would I install AD or run them as
members
of
the domain? How would AD be setup as to not take up too much bandwidth?
In
this configuration I am assuming the remote user would authenticate to
the
local DC? What about the Global Catalog? would I make a remote DC a GC
as
well?
Thanks a lot,
Dan Andrews
--
Thanks,
Dan
- Follow-Ups:
- Re: configuration of 2 remote sites
- From: Dan Andrews
- Re: configuration of 2 remote sites
- References:
- Re: configuration of 2 remote sites
- From: Jorge Silva
- Re: configuration of 2 remote sites
- From: Jorge Silva
- Re: configuration of 2 remote sites
- From: Dan Andrews
- Re: configuration of 2 remote sites
- Prev by Date: Re: If a computer is not used for more than 3 months auto disable
- Next by Date: Re: replication access denied
- Previous by thread: Re: configuration of 2 remote sites
- Next by thread: Re: configuration of 2 remote sites
- Index(es):
Relevant Pages
|