Solved

DFS-R Design

Posted on 2010-09-09
5
1,138 Views
Last Modified: 2013-11-05
So, I am in the process of deploying a simple DFS-R infrastructure.  I have about 70+ servers in just as many remote offices that act as File & Print servers but, they also will double as App-V streaming servers.  I want to use DFS-R to keep the App-V content share consistent on each server.  Now I know that DFS-R uses RPC to replicate the data to each server.

My road blocks are: We will have a mixed bag of '03 R2 and '08 R2 systems which use different RPC ports.  Another is: our network security team will not allow these RPC random ports.  Rather than just isolate DFS-R replication to a single port as outlined in:  http://support.microsoft.com/kb/319553/en-us.  I was thinking I can accomplish both issues by limiting all RPC coming from the server on a port range of 300 (Example: 5000-5300)  I chose 300 because the minimum port range for Windows server '08 is 255 and I wanted a round number:).

I was going to follow the following articles:

Windows Server 2003: http://support.microsoft.com/kb/154596

Windows Server 2008: http://blogs.technet.com/b/askds/archive/2007/08/24/dynamic-client-ports-in-windows-server-2008-and-windows-vista-or-how-i-learned-to-stop-worrying-and-love-the-iana.aspx

I was hoping that someone could provide feedback or flaws.

Thanks,
0
Comment
Question by:JTOCCO
  • 3
  • 2
5 Comments
 
LVL 26

Expert Comment

by:Pber
ID: 33645812
Ugh, I feel your pain.  Anything that I deploy usually has to deal with a firewall and my network guys are very stingy when it comes to what I can do.  
The Microsoft article 319553 will work.  I've used this before through the firewalls as well.    Normally you would need high ports to a destination of 135 and then it will negotiate a random high port, but hardcoding it as per the 319553 works.  
I have also limited the RPC ports ranges as you also are considering.  The one thing to keep in mind is that limiting your RPC ports can have some downside if your servers are really busy because they may run out of ports.
My network guys also like the limited range as well.  If I can give them a port rule small source port range, they are usually much happier.
 
0
 
LVL 1

Author Comment

by:JTOCCO
ID: 33646110
Thanks for the info!

So, as far as restricting RPC as a whole from the server.  Would you suggest increasing the amount of ports to say 1000 from 300?

Also, have you run DFSR in an enviornment this way instead of using microsoft's KB319553.
0
 
LVL 26

Accepted Solution

by:
Pber earned 500 total points
ID: 33646285
You can monitor it.  Low usage servers you might be fine with 100 ports, Servers with lots of users or applications such as SQL, you may deplete the available RPC ports quickly.  You'll get RPC errors if you run out.
You can also sniff with netmon and watch the RPC ports.  You'll see the source ports go up from your defined range.  They eventually get re-used as connections come up and drop.  Experiment with 300 and see how it goes.
As far as DFSR, that is generally how I've done it not restricting to a specific port, but to use a constricted RPC range.  Works fine.
0
 
LVL 1

Author Closing Comment

by:JTOCCO
ID: 33646600
I appreciate the input!
0
 
LVL 26

Expert Comment

by:Pber
ID: 33647412
Glad to help.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now