Solved

Help with domain over vpn

Posted on 2011-03-10
5
592 Views
Last Modified: 2012-05-11
I need some help before I begin my task. Here is the current setup. I have 3 sites all connected over a vpn. They are all using Cisco rvs4000 routers for the site to site tunnels.  Currently each site is in a workgroup setting and receiving dhcp and dns by their respective routers.  Site 1 has a single windows 2008 server.  Each site also lan different local lan ip subnets. Site1: 10.0.0.X, Site2: 192.168.1.X, Site3 192.168.2.X.  All clients are running Windows 7.

What I want to do is promote the server to a domain controller so I can centralize everything and invoke mandatory desktops, basically have all users log in and only see one single icon on their desktop.  So, here is what I need to know.

If I promote this domain controller, what will be the impact if I leave DHCP and DNS on all the routers as-is?
Will I be able to join the remote clients to the domain without having any issues of finding the domain name?

Or, what should be the proper steps to take to do this correctly?


0
Comment
Question by:schmad01
  • 3
  • 2
5 Comments
 
LVL 42

Expert Comment

by:kevinhsieh
Comment Utility
You correctly identified problem that you will have with DNS, and to a lessor degree DHCP. In order for Active Directory to work, you need to have a working DNS system working. Since you don't have a domain yet, here are some tips.

1. Make your domain name domain.local instead of domain.com . It will simplify things down the line.
2. Every member of the domain needs to use a domain controller for DNS. Do not configure them to use any other DNS servers, not even as secondaries.
3. Using the Microsoft DHCP server gives you better management and is easier than the Cisco DHCP server. Turn off the DHCP server for the site with the server and use DHCP on the server.
4. You can continue to use DHCP on the other routers, but make sure that you reconfigure them to give out on ly the IP address of your server as the DNS server to use.
5. You need to configure Active Directory Sites and Services. It won't get done for you by a wizard.
6. Sine you will probably be storing some things on your server, it is easier if you start by using a domain based DFS root as the path for files, profiles, etc. The advantage is that the paths look like \\domain.local\dfs\users\profiles instead of \\server1\users\profiles . The advantage is that you can move the files to another server in the future without needing to reconfigure anything on the clients.
0
 

Author Comment

by:schmad01
Comment Utility
I thought that AD sites and services is installed automatically when the first domain controller gets set up.
0
 
LVL 42

Accepted Solution

by:
kevinhsieh earned 500 total points
Comment Utility
Sites and Services won't be configured with multiple sites, and the subnets won't get defined. You have to do that yourself. AD has no way of automatically determining whether or not two subnets are local to each other or remote. You could theoretically say that maybe anything less than 10 ms away was the same site, but maybe you want a whole state to be in the same site, or maybe just a city, or maybe just a building, or just maybe want need your LAN to be in multiple sites. That's really hard to automagically configure with a wizard.
0
 

Author Comment

by:schmad01
Comment Utility
So would I configure my setup as one site or multiple sites?
0
 

Author Closing Comment

by:schmad01
Comment Utility
Thank you!
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now