Advertisement

07.15.2008 at 04:24AM PDT, ID: 23565654
[x]
Attachment Details

Deploying Windows domain controllers to remote locations

Asked by ebjers in Active Directory, Windows Networking, Windows 2003 Server

We have a rather large international domain that at the moment is a flat domain structure, everything is part of Globaldomain.net.  We do have sites setup for each location with different subnets and everything is connected VIA CISCO equipment, and we are constantly adding new locations and closing old ones (closing old ones is not a problem)

Our current procedure for a new site is to setup the DC in our server room at HQ allow full replication and install other required software such as AV and mail server.  We then ship the server to where ever it is going (drives shipped separately or hand carried later).  And that is the problem.  Often a server will get tied up in shipping or customs somewhere and may not make it to the final destination for up to two months, and then once it is there a tech has to go out and setup the VPN tunnel and connect the DC to the network, but by then replication will no longer work due to tombstone, expired kerberos password, lingering objects, and anything else you want to throw out there.

Most of the techs know how to handle these problems but it can cause significant delays in setting up a site, and in my case I got to a site that had a DC that was built and shipped before I was hired so my account did not exist on it (no replication) and I could not fix any of the problems.  We are looking at a few options to implement in the future including; promoting the server to a DC once it is in the field using a backup copy of AD (to prevent massive replication over the WAN), and going to a parent/ child domain structure.  Unfortunately both options, while mine to research, document, and prepare are at least a year down the line so we need a solution for now.

Does anyone know of any steps that we can do to help prevent things like expired kerberos passwords for a DC that has been off line for long periods of time and the other problems I mentioned above.

Start Free Trial
[+][-]07.15.2008 at 04:32AM PDT, ID: 22005851

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Active Directory, Windows Networking, Windows 2003 Server
Sign Up Now!
Solution Provided By: craigothy
Participating Experts: 3
Solution Grade: A
 
 
[+][-]07.15.2008 at 05:31AM PDT, ID: 22006203

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.15.2008 at 07:30AM PDT, ID: 22007361

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]07.15.2008 at 07:48AM PDT, ID: 22007543

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]07.16.2008 at 09:26AM PDT, ID: 22017509

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.17.2008 at 05:12AM PDT, ID: 22024523

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.24.2008 at 08:28AM PDT, ID: 22080236

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628