Solved

Query regarding Active Directory SRV records

Posted on 2009-05-05
5
517 Views
Last Modified: 2013-12-24
Hi Experts

I had a query regarding LDAP/Kerberos SRV records I was hoping someone could help me with.

Let's say I have 5 DC's in my site. I want users to be able to authenticate to each.

Would I have LDAP and Kerberos SRV records with each of the 5 DC's listed? Is it one LDAP/Kerberos SRV record per DC, or is there only one LDAP/Kerberos record which holds all the DC's?

Secondly, say I want users to use on DC preferentially...I understand that I can set the priority/weight...would i be correct in saying that that the lower the priority the higher preference the DC has? And if the priorities are equal, then the lower the weight the higher the preference?

I have been reading from here, but it doesn't go into too much detail;

http://technet.microsoft.com/en-us/library/cc961719.aspx
0
Comment
Question by:kam_uk
  • 2
  • 2
5 Comments
 
LVL 70

Accepted Solution

by:
KCTS earned 200 total points
ID: 24303585
The DNS server will automatically maintain SRV records for all DCs
If you want to start tinkering with the priority/weight (and I advise against it then)

Priority - low number = greater preference
Weight - high number = greater preference
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 200 total points
ID: 24303586
Yes you would have SRV records for each server.  See my screenshot -- I have 3 DCs in this test network
The lower weight would get less preference
See if this link helps with understanding weight/priority
http://technet.microsoft.com/en-us/library/cc787370.aspx
Thanks
Mike

ldap-kerberos-SRV.jpg
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24303606
KCTS -- if you have time can you send me an email off line (email on my profile) just want to ask you a quick question
Thanks
Mike
0
 
LVL 71

Assisted Solution

by:Chris Dent
Chris Dent earned 100 total points
ID: 24303801

If you have multiple records of equal priority then the weights are summed and queries distributed according to the relative weights.

For example, if I had these two:

_ldap   SRV   0 25 389  server1.domain.com.
_ldap   SRV   0 50 389  server2.domain.com.
_ldap   SRV   0 25 389  server3.domain.com.

In this case the total weight is 100, conveniently converted into a percentage that's 100%. Seeing the weights above, we can see that the division of queries would be 25% to server1, 50% to server2 and 25% to server3.

If you were to determine usage and the weights don't all neatly match up to 100 you would do:

Percentage Usage = (Record Weight / Total Weight) * 100

Chris
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 24303804

> if I had these two:

Three... I can do math, but I can't count ;)

Chris
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
As technology users and professionals, we’re always learning. Our universal interest in advancing our knowledge of the trade is unmatched by most industries. It’s a curiosity that makes sense, given the climate of change. Within that, there lies a…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question