Re: Windows 2003 Domain Replication & Security

From: Ace Fekay [MVP] (PleaseSubstituteMyActualFirstName&LastNameHere_at_hotmail.com)
Date: 02/01/05


Date: Tue, 1 Feb 2005 02:20:59 -0500

In news:%231LUpR6BFHA.936@TK2MSFTNGP12.phx.gbl,
msw <msw@hotmail.com> made a post then I commented below
> Thank You for your reply
>
> Yes my first question is if it secure?
>
> Second the exchange server is runing as exchange as well as a dc and
> the application server is also a seprate dc on the other hand they
> both replicate but both are seprate DC. when I go inside Active
> Directory Site the two domain are listed and I am 99% sure each one
> of them is a DC
> I don't know why the exchange was setup on a server as a DC is there a
> reason behind that.
>
> Is it your recommendation that exchange should not be a DC and just a
> part of DC. I think IIS is runing on the exchange box I have Outlook
> OWA runing already
>
> If I can not set another server is there another option.
>
> I hope this is not too many questions.
>
> Thank You

I see. Exchange or any other application, for that matter, the best practice
is that it should not be run on a DC. Install and run them on a member
server, if possible, especially Exchange, since it's exposed and accessible
from the Internet. You are exposing your DC on the Internet. Another reason
is the write-behind cache is disabled on domain controllers to aid in the AD
transaction log processes. This cuts performance almost 10% compared to a
member server. Usually the reason Exchange would get setup on a DC is either
due to lack of knowledge, funds, politics, or it's an SBS (Small Business
Server 2000) server.

Your wording:
> Is it your recommendation that exchange should not be a DC and just a
> part of DC

Is a bit off. I believe you meant to say; as "part of" or a "member of" a
domain.

A DC is a physical component of Active Directory. Apparently your two DCs
seem to be part of the same domain. A DC will replicate it's Sysvol and
NTDS database among other DCs. Simple stated, there are different facets of
replication, depending on whether the DCs are part of the same domain in a
forest or part of different domains in the same forest, but not between DCs
that are DCs for a domain in different forests.

I made some security suggestions concerning Exchange designs in my previous
post. Your best bet for security is either use a Front End/Back End design,
or install an smtp gateway.

IIS is a required user pre-configured component for Exchange 2000 and 2003.
Exchange requires a number of services to be running prior to instalation,
such as SMTP, HTTP (wth specific componenets), and NNTP. OWA gets installed
by default.

A DC is a physical component of Active Directory. A DC will replicate it's
Sysvol and NTDS database among other DCs. Apparently your two DCs seem to be
part of the same domain.

I hope that helps. Keep in mind, there are many factors in designing an
infrastructure, and there is not one design that will be good for everyone.
It depends on your business requirements, security requirements, budget, and
of course, political influences.

If you don't me suggesting something, it would greatly benefit you if you
can attend classes on Windows 2000 and/or Windows Server 2003 Active
Directory and Exchange 2000 and/or 2003. This way you get a better handle on
how all of this stuff works, and acquire the knowledge to secure it
properly. If you attend a class, the instructor will be a valuable resource
for questions.

I hope that helps.

Ace



Relevant Pages

  • Re: Sites & Services - DSAccess w/E2K3 SP2
    ... I don't believe the firewalls are the issue as they are set to any-any among ... the all the DCs and exchange server. ... All the DCs replicate information in a mesh ... Immediately after upgrading to Exchange 2003 SP2, ...
    (microsoft.public.exchange.admin)
  • Re: Exchange Disaster Recovery Server
    ... The backup server is setup also in the lab so I ... >>> The Microsoft Exchange Server computer is not available. ... >>> Microsoft Exchange Server Information Store ...
    (microsoft.public.exchange2000.admin)
  • Exchange 2003 SP1 periodicaly losses connection to active directory for about 30 minutes
    ... We have active directory in two servers but the mail server fails to ... the promotion of the server to active directory the exchange was up. ... After a Domain Controller is promoted to a Global Catalog, ...
    (microsoft.public.exchange.connectivity)
  • Exchange 2003 SP1 periodicaly losses connection to active directory for about 30 minutes
    ... We have active directory in two servers but the mail server fails to ... the promotion of the server to active directory the exchange was up. ... After a Domain Controller is promoted to a Global Catalog, ...
    (microsoft.public.exchange.misc)
  • Re: LDAP Bind Unsuccessful
    ... We have a similar problem with Exchange 2003 and two DC servers 2003. ... After a Domain Controller is promoted to a Global Catalog, ... server that is designated to be a Global Catalog Server but did ...
    (microsoft.public.exchange2000.active.directory.integration)

Loading