Multiple Domain Controllers

I have  9 windows 2000 servers in a domain. 7 of the servers are on a wan connection. We want
the 7 locations to be able authenticate locally.  Those servers are small with a limited connection.
We don't want the remote servers authenticating for anyone but users at its location. Now
we may have users from one remote location authenticating to another remote location.
We don't mind the authenticating from the 2 servers in house, because we have multiple connections
and those servers can handle the traffic. Does that make sense?

Thanks in advance!


Larry

LVL 1
pathwayscsbAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

juraganCommented:
I believe that if you have mapped all of your IP subnets into corresponding AD sites, then the clients will be authenticated by DC in the same site.  In Windows 2003, if a subnet is not mapped to a site then the client on that subnet may get authenticated by any DC in the domain (which could be in far distance), this recorded in Event Viewer with ID 5807.

- J -
pathwayscsbAuthor Commented:
Well...I have the local pc's DNS set to the local server first. Then I have the Main Server as its alternate.
I don't have any remote pc's set to the remote servers for dns.

I am going to give you an example...may this will clear up some stuff.

Main Site

Main Server 10.1.1.20
Dns - 10.1.1.20
Secondary Main Server 10.1.1.69
Dns - 10.1.1.69

Pc's
Dns 1 - 10.1.1.20
Dns 2 - 10.1.1.69

Remote Site 1

Remote Server 1 - 10.1.8.1
Dns 1 - 10.1.1.20
Dns 2 - 10.1.8.1
Dns 3 - 10.1.9.1 (remote server 2)
Dns 4 - 10.1.10.1 (remote server 3)
Dns 5 - 10.1.11.1 (remote server 4)
all Ips of remote servers are in as DNS entries

Pc's are 10.1.8.*
Dns 1 - 10.1.8.1
Dns 2 - 10.1.1.20

Etc

Thats the way each site is laid out.
Thanks!


carl_legereCommented:
You need to configure the Active directory Sites and Services module to reflect the above subnet settings.  That and making all WAN DC's GC's then you are good to go
Exploring SharePoint 2016

Explore SharePoint 2016, the web-based, collaborative platform that integrates with Microsoft Office to provide intranets, secure document management, and collaboration so you can develop your online and offline capabilities.

Jay_Jay70Commented:
Hi pathwayscsb,

just clarify for me, how many of your Servers are Domain Controllers? do you have at least one per site?

Cheers!
pathwayscsbAuthor Commented:
Carl,
What does GC mean? Do you mean the active directory sites and services on each DC?

Jay,
There are 9 domain controllers. 2 in our main office... and then 1 in each remote site.

Thanks everyone!

Jay_Jay70Commented:
ahh in that case then i agree with carl

under sites and services you need to create a logical site for each physical site and assign the approp DC to it

also you can define subnets and assign them to a site and that will affectively force users within a certain site to authenticate to the local DC

under the NTDS settings of each DC in sites and servies you can select properties and from there make them a global catalog

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
pathwayscsbAuthor Commented:
Do I need to create the logical site on each server? or do I create all logical sites on the main server and it replicate
out?

Thanks again!


Jay_Jay70Commented:
once created at the root it will replicate
pathwayscsbAuthor Commented:
Ok guys... I got that done!
Thanks!!
Do I need to do anything with Site Linking?

Jay_Jay70Commented:
i usually use the site links as default unless yo specifically want something else.......KCC will automatically establish the best links for you
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Networking

From novice to tech pro — start learning today.