Re: User authenication from remote site ?

Tech-Archive recommends: Fix windows errors by optimizing your registry



Dear Meinolf,

I have followed your advice and run "echo %logonserver%", it gives me \\SR. In this way, we believe that end users at remote site authenticate to the network via the DC at remote site.

Thanks again
Patrick

"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message news:ff16fb66125118cb3fa7a66d3684@xxxxxxxxxxxxxxxxxxxxxxx
Hello Patrick,

An easy option:

"echo %logonserver%" without the quotes in a command prompt should show the DC in the site where the client is.

Also this should show the site information on a client machine:

nltest /dsgetdc:domainname
Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

Dear all,

Thank you for your advice. It is pretty helpful.

We have set up site and assign subnet to it. We would like to know is
there any easy way to check whether it works or not ?

Thanks again
Patrick
"Paul Bergson" <pbbergs@xxxxxxxxxxxxx> wrote in message
news:3F68935B-EFA6-42D9-A406-6030045137AD@xxxxxxxxxxxxxxxx

To authenticate at the remote site you should have the following
configured:
A seperate site defined in Sites and services along with the ip
addresses
of the RS
A global catalog defined at the remote site
A dns server at the RS, this will protect them in the event of a lost
link
All clients at RS point to local RS for dns and then HQ for dns
This won't help for any data that needs to traverse the connection

As far as data access from RS to HQ all of this probably has no
connection. If you are attempting to bring data accross the link
examine the bandwidth and purchase a bigger pipe if need be.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights. "Patrick" <Patrick@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:%23g2nJEKcJHA.1336@xxxxxxxxxxxxxxxxxxxxxxx

We just migrate to Active Directory from another NOS.

There is a domain controller at the Head Quarter (Let us call it HQ)
and there is another at remote site (Let use call it RS). Both DCs
belong to the same domain. The implementation is set up by a
consultant.

Users at remote site finds that the response time for accessing data
from HQ is not good.

The consultant says that it is due to
1) Replication of data of AD between HQ and RS
2) Users at RS has to authenticate via HQ (Not RS)
In this way, he says that he has done the following 1) Schedule for
replicate is limited to 4 times a day 2) Not much can be done though
he has set up Global Catalog on RS

I would like to seek your advice on whether his saying is correct ?
Besides, which component makes HQ as the domain controller that is
responsible for authentication.




.



Relevant Pages

  • Re: DC Apparently lost authentication to domain
    ... > one DC will not authenticate with the other ... > in the remote site without problem. ... > [WARNING] Failed to query SPN registration on DC ...
    (microsoft.public.win2000.active_directory)
  • DC Apparently lost authentication to domain
    ... one DC (in a remote site) will not authenticate with the other DC's. ... clients that authenticate with the bad DC cannot access ... [WARNING] ... Failed to query SPN registration on DC ...
    (microsoft.public.win2000.active_directory)
  • How Can I direct accounts/PCs to Specific DCs for Authentication
    ... I have a bandwidth issue at a remote site (cable modem speed ... that server at the remote site to authenticate. ...
    (microsoft.public.win2000.active_directory)
  • Re: User authenication from remote site ?
    ... To authenticate at the remote site you should have the following configured: ... A dns server at the RS, this will protect them in the event of a lost link ... There is a domain controller at the Head Quarter and there is another at remote site. ... Users at RS has to authenticate via HQ ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to clean up some cache
    ... make sure he doesnt still have an ip address form the remote site ... We have one domain and 3 site in three different countries and connect ... site to authenticate and there might be some policies or settings from ...
    (microsoft.public.windows.server.active_directory)