Link to home
Start Free TrialLog in
Avatar of iNetSystem
iNetSystemFlag for United States of America

asked on

Best Practices to add a new DC

I have a remote site with a single Windows 2003 Domain Controller that is replicating to the DC's at Headquarters..  It is setup as a separate site in Active Directory.  What are the steps I should take to add a new DC in that site including replicating to that's sites Domain Controller?  Is there anything I need to do in Sites & Services or should my focuse be on replication to the remote site?  The remote site is running Integrated DNS; should the new DC run Integrated DNS as well and if so what steps need to be taken?Please give me granular bullets that I should perform.
ASKER CERTIFIED SOLUTION
Avatar of Brian Pierce
Brian Pierce
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of iNetSystem

ASKER

WOW
Extremely well stated...very impressed.
Please clarif why the new DC running DNS would have the first DNS server pointed to iteself.  The existing single DC in the remote site IS running DNS but is pointing to the PDC at headquarters as well as the secondary DNS server at Headquarters.  A little confused here as the setup seems to run great.  

What else do I need to do to ensure replication throughout and to prepare for, in the event of the original DC going down?  Since remote sites is a bit new for me, what would happen if the single DC failed, would my users there authenticate to Headquarters OK since I have a dedicated MPLS circuit between the sites?

THANKS!
All DNS servers should point to themselves as preferred DNS server - it avoids nework traffic for DNS lookups - especially id it involves cross site lookups. (are you sure the existing DC in the site had had DNS installed - check - if not this would be a great idea !)

So long as you have muultiple Global catalogs availabe (which I why I siggested make the new DC a GC and DNS is available then authentication can occur - again worth checking that the current DC on the site is a GC)

To avoid cross-site DNS lookups, you also need to make sure that all machines are configured with the DNS servers relating to their own site.