[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Managing AD from Remote DC

Posted on 2007-11-20
9
Medium Priority
?
255 Views
Last Modified: 2010-03-17
Hi when i want to manage my Active Directory from one of my remote site domain controllers its painfully slow. It seems particularly slow when trying to edit GPO's

Any ideas?
0
Comment
Question by:kingcastle
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
9 Comments
 
LVL 38

Expert Comment

by:Hypercat (Deb)
ID: 20322609
How are you connecting to the remote DC - are you using a remote desktop connection or VPN, or both, or something else?
0
 

Author Comment

by:kingcastle
ID: 20323396
im actually at the remote site working on the dc at the site. the sites are linkd via wan links dedicated

ta
0
 
LVL 38

Expert Comment

by:Hypercat (Deb)
ID: 20323715
I imagine the slowness has to do with trying to make changes in AD over a WAN link.  I would try using the administrative remote desktop connection to one of the servers at your main site instead of just opening the management console locally.  If you're not familiar with doing this, you would use the following command line (Start/Run): mstsc /v:[servername or IP] /console
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 

Author Comment

by:kingcastle
ID: 20323784
i thought that if i had a domain controller locally ie at the remote site then everything on ad would run as if i was at the may site. is this not the case then?

ta
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 20323801
if you are working locally, then yes, it should scream....however, if you are using the adminpak on your machine, it is probably binding to the servers in the wrong site.....you would be much better as above, remoting in and doing it that way
0
 

Author Comment

by:kingcastle
ID: 20323845
why would it be hitting the servers in the wrong site?

will it be doing the same thing trying to run gp's ie hitting the wrong serves?
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 20323878
well not the wrong onces as such, but the ones in your other site......just see which DC you are binding too....(i use vista and the adminpak is crap so i cant show you specifically where to check)

Have you got a GC in that site?
0
 

Author Comment

by:kingcastle
ID: 20324102
yeah gc already there how do i now which dc in binded to

cheers
0
 
LVL 38

Accepted Solution

by:
Hypercat (Deb) earned 2000 total points
ID: 20328119
For management of AD Users/Computers and DNS, you can focus the management console on the local DC by selecting that DC from the snap-in, or creating your own custom console and pre-selecting the local DC.  When you open ADUC, for example, if you look at the top level object (Active Directory Users and Computers) it tells you to which DC it is connected. If you are opening the default console (rather than using a customized one), it will always connect to the FSMO role holder (Infrastructure master) in the domain. You can change the focus by right-clicking on the domain name object and choosing "Connect to Domain Controller."

However, for group policies that potentially affect the entire domain, when using the Group Policy Mgmt. console, I'm pretty sure it will always be trying to connect to the FSMO role holder(s) in the domain.  If your local office is a child domain, however, you might be able to create a custom GPMC that focuses only on the child domain. I'm not sure about this, since I manage domains that are too small to require any child domains in the forest.

Another thing you can look at is whether general WAN traffic is simply causing this particularly intensive activity to be slow.  Maybe you should be setting a greater replication interval between this DC and the main office DCs - the default interval is 5 minutes.  Here's an article that contains that info as well as some other ways to control WAN traffic:

http://support.microsoft.com/kb/819108/en-us
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question