Advertisement

07.26.2007 at 11:59AM PDT, ID: 22723690
[x]
Attachment Details

Active Directory and subnets

Asked by lrmoore in Windows 2003 Server, Active Directory

Tags: active, directory, subnet, multiple

In a single, simple stand-alone AD with just one site that has multiple IP subnets routed internally, do you have to add each subnet to the site within AD? What symptoms would you see if you don't?
Start Free Trial
[+][-]07.26.2007 at 12:05PM PDT, ID: 19577259

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Windows 2003 Server, Active Directory
Tags: active, directory, subnet, multiple
Sign Up Now!
Solution Provided By: LauraEHunterMVP
Participating Experts: 3
Solution Grade: A
 
 
[+][-]07.26.2007 at 12:15PM PDT, ID: 19577354

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.26.2007 at 12:19PM PDT, ID: 19577390

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]07.26.2007 at 12:22PM PDT, ID: 19577430

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.26.2007 at 12:29PM PDT, ID: 19577502

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.26.2007 at 12:31PM PDT, ID: 19577519

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • Automotive
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Displays / Monitors
  • Handhelds / PDAs
  • Components
  • Peripherals
  • Laptops/Notebooks
  • Servers
  • Misc
  • Apple
  • Embedded Hardware
  • Networking Hardware
  • Storage
  • Desktops
  • New Users
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMware
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Virtualization
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • Web Computing
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Consulting
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMware
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Automation
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Web Services
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Web Computing
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Lounge
  • Business Travel
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
  • Automotive
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
07.26.2007 at 12:05PM PDT, ID: 19577259
In a single site there's no real reason to configure subnets manually - all of your clients will default to the single site, and will authenticate against the DCs in that single site.
Accepted Solution
 
07.26.2007 at 12:15PM PDT, ID: 19577354
I didn't think so, but wanted to run it by the Experts for a second opinion.
Thanks Laura!

If I have multiple sites should I then register each appropriate subnet to the appropriate site?
 
07.26.2007 at 12:19PM PDT, ID: 19577390
The subnets are used to determine the best Domain controller to authenticate to.  If you have multiple subnets AND some of those subnets have their own domain controller, then you should set them up and set up sites, then associate the proper subnets with the proper sites.
Assisted Solution
 
07.26.2007 at 12:22PM PDT, ID: 19577430
So, as far as symptoms, here is the scenario

Subnet A 192.168.0.x - With Domain Controller - Core Site
Subnet B 192.168.1.x - With Domain Controller - WAN Site, T1 to Sub A
Subnet C 192.168.2.x - No Domain Controller - WAN Site, T1 to Sub A

If you don't have any subnets and sites set up in AD Sites and Services, then users from Subnet C might be persistently authenticating to Subnet B, wasting precious T1 bandwidth at 2 sites.  You may also find users from Subnet B also authenticating to Subnet A, wasting yet more WAN bandwidth.
 
07.26.2007 at 12:29PM PDT, ID: 19577502
That's all I needed to know.
Thanks!
 
07.26.2007 at 12:31PM PDT, ID: 19577519
An AD site is assumed to be "well-connected", in other words a single LAN - even if that LAN extends to multiple physical locations, if all machine can connect to each other at LAN speed, you're fine.

As benhanson describes, if you have bandwidth limitations between your subnets such that you generally want workstations on SubnetA to authenticate to a DC on SubnetA and so forth, then configure a separate site for each well-connected location and site links between them.
 
 
01.31.2008 at 05:45AM PST, ID: 20786402
Hi,
IF you assign class A Ip address then you need to enter subnet as 255.0.0.0 and for classB it is 255.255.0.0 for classC 255.255.255.0 depending on this you need to specify the subnet mask.
 
 
06.26.2008 at 06:18AM PDT, ID: 21874442
Hi,
Subnets are assigned automatically accordingly on range of ip address like classA,ClassB,ClassC,and ClassD ,for classA Ip address subnet mask is 255.0.0.0 for classB it is 255.255.0.0,for classC it is 255.255.255.0 and for classD it is 255.255.255.255.
 
 
 
 
20080716-EE-VQP-32