catsup3
asked on
Design advice for multi site network - AD & VPNs
I have a client with 15 small offices in country towns (10-15 people in each office) currently running 1 SBS 2003 box in each site. Each site has a different domain with different users but sometimes they move between offices. Administration is a pain and its going to get worse as they're growing at a rate of knotts - 1 new site every few months.
I am looking to run a single domain for the entire organisation and provide exchange from a single point. The plan is to put 1 domain controller & 1 exchange server in a city based data centre and install a fileserver/DC in all country offices. The internet connections for each site are a minimum of 512kb/512kb and will only be used for internet browsing, occasional downloads and remote support.
I have a few questions regarding AD & WAN/VPN design:
________Data Centre______
| | | |
| | | |
Site1 Site2 Site3 .. Site15
Is an IPSec VPN from each site to the data centre the best design? This VPN will only be used for replication at this stage. Should I be looking at links between sites or is that a waste? MPLS? Should I look to put a GC at each site, use UGMC or logon over the VPNs? Is there anything else to consider or a better way to approach this?
Thanks in advance
I am looking to run a single domain for the entire organisation and provide exchange from a single point. The plan is to put 1 domain controller & 1 exchange server in a city based data centre and install a fileserver/DC in all country offices. The internet connections for each site are a minimum of 512kb/512kb and will only be used for internet browsing, occasional downloads and remote support.
I have a few questions regarding AD & WAN/VPN design:
________Data Centre______
| | | |
| | | |
Site1 Site2 Site3 .. Site15
Is an IPSec VPN from each site to the data centre the best design? This VPN will only be used for replication at this stage. Should I be looking at links between sites or is that a waste? MPLS? Should I look to put a GC at each site, use UGMC or logon over the VPNs? Is there anything else to consider or a better way to approach this?
Thanks in advance
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.