Re: AD misbehaving
- From: Tango <tangot2@xxxxxxxx>
- Date: Tue, 23 Oct 2007 07:52:07 -0500
Thank you Tom and Ryan,
Side note -> I HATE DNS.
All of my servers except one are Global Catalogs. The one that is not
is the infrastructure master. Last year when I checked Microsoft
still didn't have their story straight about whether it was OK for the
IM to be a GC too. It didn't seem to matter either way.
All DCs are AD DNS intergrated. All DCs point to thmeselves first
then to my main Admin DC second. All clients point to the local DC
first and the main second.
I'll check on my servers to see where they are pointing adn if they
can ping them.
Thanks!
Fred
On Mon, 22 Oct 2007 19:43:02 -0700, Ryan Hanisco
<RyanHanisco@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
Tango,.
As Tomasz points out the biggest culprit here is probably your DNS. In your
environment, you would want your domain controllers all set up as DNS servers
hosting AD integrated DNS. You would also probably want them all as GCs as
well, though there are some other considerations there too if you have trusts
or Exchange in the mix.
In this way, you would have your workstations pointing at local DNS servers
before pointing at the Central DNS, that way they hardly notice the downed
core. You will have some longer logon times, GPO issues, and the inability
to change passwords as the PDCe will be unreachable.
You also might consider the network structure. If the network (WAN) is a
star, then they can't reach the secondary sites making the network stop.
Generally, you declare a failover site and have secondary PVCs or MPLS links
to that site to provide hot failover of services.
You would also do well to look at your site layout to be sure that the
workstations are associated with remote DCs that are close to them (in
network hops) and have links to additional available sites. You can also
check the overall health with DCDiag and NETDiag.
This should get you in the right direction and ready for the next outage.
- Follow-Ups:
- Re: AD misbehaving
- From: Austin Osuide
- Re: AD misbehaving
- References:
- AD misbehaving
- From: Tango
- RE: AD misbehaving
- From: Ryan Hanisco
- AD misbehaving
- Prev by Date: ms-DS-MachineAccountQuota set to 5000
- Next by Date: Re: Lost First DC in 2 DC Domain - Windows Server 2003 Server Edit
- Previous by thread: RE: AD misbehaving
- Next by thread: Re: AD misbehaving
- Index(es):
Relevant Pages
|