Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Recommended Setup

Status
Not open for further replies.
Mar 8, 2004
89
CA
Good day all,

I have come into a network which had utilized their IT budget in getting numerous servers. Currently the have just under 150 users in 3 separate locations and VPN(s) connecting all the locations.

Currently they have a setup similar to this

Location 1:
2 2003 domain controllers running AD and active Directory DNS for the domain (domain.local). The 2nd DC was supposed to act as a failover. IP address scheme is 192.168.1.x

Location 2:
1 2003 DC running AD (for the same domain.local domain) and DNS configured also with AD integrated. IP address scheme is 192.168.2.x

Location 3:

1 2003 DC running AD (for the same domain.local domain) and DNS configured also with AD integrated. IP address scheme is 192.168.3.x


All locations have XP and Vista clients, they have a WINS server configured ( I assume this only to be old technology never removed) but none of the machines are using NeiBeui.


Basically they have a number of different latency issues in different areas, Without a complete rework segmenting the domain into sections and having the appropriate DNS setup like I would have done originally, I am thinking of the following.. Pros, Cons?? am I out to lunch?

Location 1:

1 AD Server Running DNS Primary Zone

Location 2:

1 AD Server for replication running a DNS Secondary zone

Location 3:

1 AD Server for replication running DNS Secondary zone


All client machines would be configured to their local DNS for resolution, all DNS servers would forward to external DNS server should name not be resolvable internally. WINS Server removed or at least install NetBeui if they want to keep it for whatever reason.
 
I would use DNS AD-Integrated Zones and get rid of the Secondaries. And verify that all servers are Global Catalogs (in case the WAN/VPN links go down)and clients can authenticate properly at the local site. reducing WAN traffic.

I would still recommend 2 DC's at the primary location especially if there is some distance between sites. This way FSMO roles can be spread out. Schema/Domain and PDCe on one and RID and Infrastructure on the other.

Add all networks (subnets) in the sites and Services for proper replication.


_______________________________________
Great knowledge can be obtained by mastering the Google algorithm.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top