Solved

ADS OVER WAN

Posted on 2011-02-21
6
264 Views
Last Modified: 2012-05-11
I have a scenario of implementing ADS synchorisation over internet . I have a local ADS running in 2003 server .I planned to  install exchange server in a remote location where my production servers are located .I have Ipsec VPN connectivity between local to remote .Which is the best way to replicte ADS with exchange in this case .Do I need to install another ADC in the remote location and create atwo way trust between these DCs or I can directly sync to the remote exchange server ? Si any other way to accomplish this without VPN? I mean through direct internet? .Please give your suggestions.
0
Comment
Question by:sumeshbnr
  • 3
  • 2
6 Comments
 
LVL 29

Accepted Solution

by:
pwindell earned 500 total points
Comment Utility
The network connectivity is independent of any of the Domain stuff.  Mainly it just has to "work",...connectivity and routing correct,...it "works",...your ready to go there.   IP Scheme needs each location to be a different subnet to avoid burdening the slow WAN link with broadcasts,...meaning it needs to be a routed conenction,...not bridged

When you have two locations separated by a WAN link (VPN or whatever) you place a DC in each location. These would be DCs for the same domain,...there is only one domain,...particularly if you want to keep this simple (and there is no reason to over-complicate it).   Then configure Active Directory Sites & Services.  When doing that you create the Subnet Objects, Site Objects (just leave the "Default Site" there and don't use it).  Then create a Site Connector Object.  The built in Help in the AD Sites & Services MMC should have all the details you need,...it is not complicated as long as you don't make it complicated,..."keep it simple" applies here.  When finished you can set the Replication Rate between the Sites.  If you have a good solid VPN witrh reasonable bandwidth set it to the lowest rate (the fastest).  I think that is 5 minutes or 15 minutes, I forget which.

The AD Sites & Services also ensures that users and their workstations use the DC closest to them to keep excess traffic off the sow WAN link.

Basically it is the AD Sites & Services tha manage all this and it is not that complex.

Exchange,...well just do what you want there. You can place one at each Site or just use one central Exchange,...either way it works.  You can also start with just one and add the other one later after all the other WAN stuff is tweeked and running well,...Exchange depends on AD so it is good to make sure the WAN and AD are all happy and smiling first.  Then it also gives you time to study up on Exchange and how to deal with a "pair" of Exchanges in the same Exchange Organization.  The fact that the two Exchanges being separated by a slow WAN -vs- a fast local LAN Connection is pretty much just irrelevant other than performing a bit slower,...but functionaly nothing changes
0
 
LVL 11

Author Comment

by:sumeshbnr
Comment Utility
Thanks Any other comments?
0
 
LVL 10

Expert Comment

by:santhoshu
Comment Utility
It is always recommended to have a ADC in the Exchange site, so that the users doesn't get affected if the ADS in the primary site is down.  

You need not create a trust relationship between the DC's because as soon as you create a ADC the two way trust will get automatically established.
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 29

Assisted Solution

by:pwindell
pwindell earned 500 total points
Comment Utility
There is no ADC here.  This is all one Domain (or should be) and all one Exchange Organization.  You can even create the new DC with it sitting 6 inches away from the existing one then transport it to the new Site afterwards and readjust the addressing.  As far as Exchange the only ADC (Active Directory Connector) with it was with Exchange 5.5 to interact with Exchange2000 or newer because Ex5.5 was not Active Directory enabled.

If it is Exchange2007 or 2010 then it uses the AD Sites & Services to cover it's routing mechanism because the old Routing Groups in Exchange2003 has be replaced with the AD Sites & Services.
0
 
LVL 10

Expert Comment

by:santhoshu
Comment Utility
Hello Pwindell, Sorry for the confusion.
By ADC I meant Additonal Domain Controller.
0
 
LVL 29

Expert Comment

by:pwindell
Comment Utility
Ah!  Ok,...sorry  :-)   I feel stupid now.
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Security is one of the biggest concerns when moving and migrating your data from your on-premise location to the Public Cloud.  Where is your data? Who can access it? Will it be safe from accidental deletion?  All of these questions and more are imp…
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now