Solved

Wanted: Advice on server configuration for Active Directory with hot failover & DR capability

Posted on 2004-09-24
5
211 Views
Last Modified: 2010-04-19
My company needs an appropriate physical server configuration for Active Directory authentication that provides hot failover and DR capability.  We have approximately 3000 users across 12 sites, plus printers, etc and several hundred application servers.

Current design is for a centralised four clustered server solution (ie 2 x root, 2 x child) which does load sharing and provides failover.  In the event of failure of any one server, the redundancy will eliminate any user impact.

However we also require rapid recovery (or preferrably no user impact) in the event that the data centre is lost.

One solution is to split the cluster across two physical locations (which are connected by wideband ethernet), but I am told this is not advisable due to reliability concerns and the additional network traffic would be high.  

Proposed solution is to provide two additional servers at the second location (ie 6 servers in total) - but this seems an overkill.  Also have separate DNS and DHCP servers which will also require backup devices for disaster recovery.

Any comments, proposed solutions, considerations, etc much appreciated !!!
0
Comment
Question by:Nicwix999
  • 2
  • 2
5 Comments
 
LVL 51

Expert Comment

by:Netman66
ID: 12148883
This should answer at least some of your questions:

http://support.microsoft.com/default.aspx?scid=kb;en-us;280743&Product=winsvr2003

See the link at the bottom of the article for further details.


Actually, MS supports this design.  When I sat in on a Cluster seminar at our MVP Summit it was interesting to hear how this works.  As long as majority quorom survives the cluster will work.

Have a read.

0
 

Author Comment

by:Nicwix999
ID: 12149283
Thanks Netman66, those links are helpful.  

The geographically dispersed custer looks complex - what are alternative disaster recovery solutions?  Presumably if some user impact is acceptable, that opens up some other options?

Also, what about DNS & DHCP?  And what else needs to be considered?
0
 
LVL 2

Expert Comment

by:ndy78
ID: 12150812
You should think about using Powerquest V2i for easy and fast Recovery. I got it running on 10 servers and its reliable and easy to use.
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 250 total points
ID: 12151671
The only other *reliable* thing I have seen used is a piece of software called "Double-Take"  

See the info here: http://www.sunbelt-software.com/product.cfm?id=111

I see now they have something that might actually be a perfect fit for you: http://www.sunbelt-software.com/product.cfm?id=133

These guys are fantastic to deal with and have all the answers - if you decide to buy, make sure to bargain for some promo stuff - like shirts, hats, pens or mugs.  They'll give you some stuff if you ask nice enough after you purchase.


DNS is no problem - if it's AD integrated and there are more than one server local then it will work provided your DHCP hands out the alternates.  If you can't afford multiple servers then you might consider using your routers to hand out DHCP and DNS info for each site.

DHCP can also be setup in one site with relay agents on all the other sites.  This way you can manage everything on one server.  Otherwise, you can run a few of them with split scopes for redundancy that can be activated as needed in the event of a failure.

Hope all this is somewhat helpful.


0
 
LVL 2

Expert Comment

by:ndy78
ID: 12165540
nice hint, netman666, that solution seems more suitable for the large scenario nicwix999 described. maybe a bit pricey, but if it really does what it states it should be well spend.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Moving Files servers to DFS 11 57
Computer software inventory 5 108
What is this Task? 4 130
ticket bloat 3 51
by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question