Solved

domain controller in branch office

Posted on 2004-09-20
2
203 Views
Last Modified: 2010-04-19
Hello,

We are planning the deployment of the domain controllers to remote office. Now the question,
We have about 200 locations (some of them with 10 or 15 users only). We would like to deploy domain controllers only to
those place where it is necessary. The links are reliable and the phisical acess to the office is secure: There is no Exchange in the company and there is not other application which require a DC. It will be necessary DHCP, WINS and DNS (it could be a dns cache)


We would like to apply GPO :
- Default domain security policy
- a GPO based on the company
- a generic GPO for XP and W2K workstations.
- logon scripts based on each of locations.

Taking in accunt your experience,

Do you think with 20 or 30 users in a location it is justified to place a domain controller ?
Links are around 64kb (CIR) DSL.

if we decide to reduce the number of DC in the spoke locations, does it necessary a greater number of DC in the HUB location?

Regards,
Richard

0
Comment
Question by:intentalo69
2 Comments
 
LVL 16

Accepted Solution

by:
JamesDS earned 500 total points
ID: 12100411
intentalo69
A GPO will not apply over a slow link. Slow link speed is also defined with GPOs - but by default is 500k.

I personally set my thresholds as follows for a similar sounding deployment (actually a police force):
Up to 20 users - No DC
20-100 Users - 1 DC
100+ Users - 2 DCs
every 500 users after that gets another DC

While this sounds easy enough, it depends largely on what traffic other than basic authentication traffic is hitting your DCs and how important it is that AD Services are maintained in the event of a WAN outage of one of more links.

Cheers

JamesDS
0
 

Expert Comment

by:downeysavings
ID: 14967908
Our company (Banking Instituition) is also planning to deploy DC  at all our 180 branches, the reason we need to use a DC at all location, is to allow our tellers to access a file share on their branch server, even if the WAN link is not available.
 I rather not introduce 180 DC (HQ's is running Windows 2003 AD) at our remote locations, do you have any suggestions ?

Thanks
Bill
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
In a recent question (https://www.experts-exchange.com/questions/28997919/Pagination-in-Adobe-Acrobat.html) here at Experts Exchange, a member asked how to add page numbers to a PDF file using Adobe Acrobat XI Pro. This short video Micro Tutorial sh…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

778 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question