Re: Remote Domain Controllers and replication



Hello physikal,

As Ace give's you a good way for dealing with the connectivity, i will make some thoughts to the server part. You have not that amount of user's in the moment, but your setup with separate DC's for each site is a good plan.

You should make all DC's in your environment Global catalog servers, no problem in a single forest domain like yours.

Also choose AD integrated zones in DNS so replication is done with AD and all DNS servers are full writable.

For DHCP i would NOT use the DSL router, use the server in the site, you have more options to assign different settings to the clients.

Also you can integrate updating of DNS according to this, to prevent multiple records in the zones for one computer: http://technet.microsoft.com/en-us/library/cc787034.aspx

In the WHQ site i would personally not built the environment with an old machine and a VM together. Even that VM's as DC are supported, the 5 FSMO roles should be placed on a physical machine. All recommendations you will find state that at least one physical DC should exist and i think a "crappy box" maybe is not the best solution for this.

See here about DC's and VM:
http://support.microsoft.com/kb/888794

Even if you don't use VS2005, the recommendation's still apply:
http://www.microsoft.com/downloads/details.aspx?FamilyId=64DB845D-F7A3-4209-8ED2-E261A117FC6B&displaylang=en

http://support.microsoft.com/kb/897614/en-us

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello all,

I'm having a real issue deciding on what route to take for 2 remote
sites that we have. I'll layout our setup and give my thoughts and
theories on it, then if you could, give me your input and hopefully
share your better ideas!

We have 3 sites:

WHQ
Site 1
Site 2
# of users:
WHQ = 10-15
Site 1 = 10-15
Site 2 = 10-15
The goal is to keep it as cheap as possible, taking the Open Source
route wherever possible.

WHQ Setup:
1 DC being emulated with VirtualBox running DHCP/DNS. Hamachi
Installed.
1 Backup DC on a crappy old box running DNS and acts as a GCS. Hamachi
Installed.
Endian firewall on a T1.
Site 1 Setup:
1 DC and File Server running DNS. DHCP is handled by a cable/dsl
router. Hamachi installed for replication from WHQ to Site 1.
Site 2 Setup:
1 DC and File Server running DNS. DHCP is handled by a cable/dsl
router. Hamachi installed for replication from WHQ to Site 1.
In my tests using Hamachi for replication has been hit and miss. I
could just be doing something wrong, but I just don't trust its
reliability enough. I keep thinking there has to be a more reliable,
and
probably more secure solution.
Any input you could provide would be great!

-Phys

http://forums.techarena.in



.



Relevant Pages

  • Remote Domain Controllers and replication
    ... WHQ Setup: ... Hamachi ... Backup DC on a crappy old box running DNS and acts as a GCS. ...
    (microsoft.public.windows.server.active_directory)
  • Re: one of two dcs crashed
    ... Make sure that you have all the fsmo roles residing on your existing dc. ... has all 5 FSMO rules and is a GC server. ... The NIC must point to the running DNS server.Also check ... I have no plans ...
    (microsoft.public.win2000.active_directory)
  • Re: Another T1 Line
    ... running DNS but not DHCP.. ... static IP addresses for each computer and the server. ... connected via a switch. ...
    (microsoft.public.win2000.dns)
  • Re: one of two dcs crashed
    ... You didn't have any backup solution for your lost DC to bring it back? ... The NIC must point to the running DNS server.Also check before you start with the promotion from the new server that it has a fixed ip address and is also pointing to the running DNS server for a good replication of your AD. ... I have no plans ...
    (microsoft.public.win2000.active_directory)
  • RE: Replacing primary DC with new server...
    ... The current DC is running DNS in AD Integrated mode ... and the new DC that is replacing it will become ... the primary DC in the domain (so will re-take all of the FSMO roles once in ... life cycle and we've purchased a new server to replace it. ...
    (microsoft.public.windows.server.setup)