Re: build now, join later



In news:eEjT7uSLJHA.4600@xxxxxxxxxxxxxxxxxxxx,
Greg Stigers <gregstigers+msnews@xxxxxxxxxxx> requesting assistance, typed the following:
The forest into which this suite will go is not ours to administer;
there is likely to be some discussion just about us having domain
admin rights in a child domain. And we will not have direct access to
their network; access is mediated thru a separate, third forest to
which each site has access.
But the application build does require us to have domain admin
rights, as we build the apps and create various AD objects, and for
instance configure DNS for failover, etc. Since the app suite
requires more than two dozen servers, which require RAID partitioning
and so on, we perform these builds in our office. We also use iLO on
hp servers, DRACs on Dell servers, etc., so configure those in our
office.
The other site will have their own requirements for configuring these
DCs in the child domain, so that it is far more straightforward for
them to create the child domain and their DCs with it, and ship
either or both of these two DCs to us.

So we should confirm the tombstone lifetime in the forest, and make
sure we can receive the DCs, build our app / member servers, and ship
these racks back within that window.

Should we expect GC issues on reconnect? Servers we've added to the
domain should propogate correctly to the rest of the forest, right?
______
Greg Stigers, MCSE


Whenever there is a situation where you build a DC outside of a site, then ship it, including where there is a time delay, it introduces errors with replication partnership lack of communication. The record will be in the SRV records. When a client or any other machine needs to authenticate to a DC, and that DC is resolved in DNS, but yet the machine cannot find it, and this goes for other DCs which also query DNS for domain resource and service locations (just because a DC is a DC doesn't mean it uses itself if there are more than one in one site - it asks DNS and resolves a resource from DNS, then asks), and disregarding whatever TTL you set on the tombstone, it WILL cause errors. Sure you can build the DC and not make it a GC, which will reduce the errors, but there will be errors and authentication failures. Then when it does get to it's location, the IPs have to be setup correctly, etc, then time to wait for propogation to occur.

All in all, that was why we were suggesting to build the base machine, install whatever apps, services, setup RAID, install the HP/Dell or whatever manufacturer's utilities on it, etc, then ship it to it's destination and using DRAC, RDP, UltraVNC, or whatever remote tool to only then promote it.

I understand your situation, and being a political or administratively restrictive, there are implications with the way AD works. I hope you understand these implications and what to expect if the current plan is carried out.

Ace

.



Relevant Pages

  • Re: ad and dns setup
    ... The child domains must be able to resolve the root domain and each other. ... In the child domains you can configure forwarding pointing to the DNS at the ... search in the Root DC/DNS to search for any other DNS that the child domain ... error no logon servers.. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Default SOA and NS records with Windows 2000 AD Integrated DNS
    ... Just for AD integrated zones? ... Are these DCs your domain controllers for your internal ... We already had DNS ... servers setup for AD I'm sure it just made sense at the time to ...
    (microsoft.public.windows.server.dns)
  • Re: Slow Logins and Slow Boot-up
    ... The DCs all have static IP, Each with DNS servers (pointing to themselves ... Clients have DHCP with DNS pointing to the 2 DCs in my main site. ... in Remote Site Hosted off site Email server -- Firewall site VPN ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS resolving issue with new child domain
    ... What can you tell us about your DNS setup? ... Which zones are on which servers? ... Perhaps I should remove the dns server on the child domain and recreate it ...
    (microsoft.public.windows.server.dns)
  • Re: I can not figure out why?
    ... I have two windows 2000 DCs and two Windows 2003 DCs. ... all workstations new DNS to point the new DNS through the DHCP server ... you must be careful when selecting the new servers to be DNS servers. ... If the zone is ...
    (microsoft.public.windows.server.active_directory)

Loading