RE: REPOST - Site Design



Hi Jonathan,

Thanks for posting here.

From your post, I understand that you want to know how to configure DNS
between two offices that are connected through hardware VPN tunnel. If I am
off base, please feel free to let me know.

Based on my knowledge and the current information, I believe the Windows
Server 2003 is the additional Domain Controller in Windows SBS 2003 domain.
So in this case, I suggest you consider the following things:

Replication between two sites:
-----------------------------------
Active Directory balances the need for up-to-date directory information
with the need for bandwidth optimization by replicating information within
a site more frequently than between sites. You can also configure the
relative cost of connectivity between sites to further optimize replication.

1. The DNS replication between two sites. You can set the primary zone type
in Windows SBS 2003 DNS server, and set the secondary zone type in Windows
Server 2003 DNS server.

2. The directory service replication between two sites. If you have more
Domain Controller in every site, you can configure Bridge Header in every
site. The Bridge Header server can help you reduce the network traffic of
AD replication.

Authentication:
--------------------------
Site information helps make authentication faster and more efficient. When
a client logs on to a domain, it first searches its local site for a domain
controller to authenticate against. By establishing multiple sites, you can
ensure that clients authenticate against domain controllers nearest to
them, reducing authentication latency and keeping traffic off WAN
connections.

For more information about AD Site, please refer to the following MS
article:

Sites overview
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/Serve
rHelp/30e18d11-89f3-4744-9a3a-88a69a8ec1bb.mspx

More Information:
------------------------
To consolidate the AD sites, you may refer to the following articles:

Move a domain controller between sites:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/Serve
rHelp/95e9b458-29f1-4b09-81ab-5b2a96b86af2.mspx

Associate the subnet or subnets with the appropriate site:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/Opera
tions/a131fc0b-7427-415a-858c-94eb63347004.mspx

I hope the above information helps.

Have a nice day.

Best Regards,

Steven Zhu
MCSE
Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
======================================================
PLEASE NOTE the newsgroup SECURE CODE and PASSWORD were
updated on February 14, 2006.? Please complete a re-registration process
by entering the secure code mmpng06 when prompted. Once you have
entered the secure code mmpng06, you will be able to update your profile
and access the partner newsgroups.
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
======================================================







.



Relevant Pages

  • Re: SBS 2003 and Replication Errors with Remote DC
    ... I just promoted the remote DC last week, so I still have time to solve the replication issues. ... Domain Controller Diagnosis ... Connecting to directory service on server alpha. ... Performing upstream analysis. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 and Replication Errors with Remote DC
    ... alpha server as soon as you can to get things going. ... A simple DNS replication test is to create a host record in the SBS server ... Domain Controller Diagnosis ...
    (microsoft.public.windows.server.sbs)
  • Re: Thoroughly confused SBS 2003 Server
    ... fact I first had SBS running on the box that now has the Server Enterprise ... A year ago or moe I put up the second server and made it a domain controller ... The replication generated an error: ...
    (microsoft.public.windows.server.sbs)
  • Re: multiple errors in Active Directory
    ... Connection-specific DNS suffix: ... If this computer is a domain controller for the specified domain, ... DNS server has updated its own host records. ... If this DNS server's Active Directory replication partners do not have the ...
    (microsoft.public.windows.server.active_directory)
  • Re: multiple errors in Active Directory
    ... Connection-specific DNS suffix: ... If this computer is a domain controller for the specified domain, ... The attempt to establish a replication link for the following writable ... DNS server has updated its own host records. ...
    (microsoft.public.windows.server.active_directory)