Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 341
  • Last Modified:

Branch office has severed ties...

We have a branch office that has a DC(a GC), running DNS and DHCP. In their infinite wisdom, they decided to detach their connection with our network and re-attach their previous connection to the internet(bigger pipe). Long and short of it, they don't see us and we don't see them. They are still using the DC for authentication, DNS(partially), and DHCP. The question is: What are the ramifications for our active directory, with all their objects being  unavailable? Can the absence of their objects, DC being one of them, cause harm to our directory?

Thanks for any input!  
0
IATexpert
Asked:
IATexpert
  • 6
  • 6
1 Solution
 
JBond2010Commented:
With the connection been severed, this means that the Active Directory Database is not able to replicate. Any changes made to Active Directory such as user objects, these changes will not replicate. It is important to note that each Domain Controller has USN - Update Sequence Number, when changes are made are Active Directory it is able to distinguish which Domain Controller made the changes.

Also, are these Domain Controllers on the same Active Directory Domain, or is it a Child Domain of the Forest? This is very important, because you need to verify which Domain Controller is holding the 5 FSMO Roles. The 5 FSMO Roles are The Schema Master Role, The Domain Naming Master Role, The PDC Emulator, The Rid Master Role and The Infrastructure Master Role.

If the site were the link was severed tried to demote or promote or add a new Domain Controller they won't be able to this if the FSMO Roles are held on the other site. Also, if the site were the link was severed runs out of RIDs - Relative Identifiers they will not be able to create new objects.

Also, the PDC Emulator Role is responsible for Time Syncronisation. All Domain Controllers update their time from the PDC Emulator. This is also for backward compatability for Windows NT clients logging onto the network.

The Infrastructure Master Role is responsible for updating Active Directory and it does this by interacting with the Global Catalog.

Their is alot to be concerned about.


Regards,

JBond2010
0
 
JBond2010Commented:
Also, the Domain Naming Master Role is responsible for keeping update information of all Domain Controllers in the Forest.
0
 
IATexpertAuthor Commented:
No it doesn't hold any of the 5 roles, and it is in the same domain. There are no child domains.
0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 
IATexpertAuthor Commented:
How many RIDs would you imagine that they have?
0
 
JBond2010Commented:
The Rid supplies Relative Identifier in pools of 500, so when the Domain Controller reaches the half way point it requests more RIDs.
0
 
IATexpertAuthor Commented:
So if they don't reconnect in 60 days, and provided they aren't going to try and create more than a couple hundred objects, is it safe to say that AD will just grumble a lot, but that no real harm will come to it?
0
 
JBond2010Commented:
Also, you need to acertain which Domain Controller or Domain Controllers are holding the 5 FSMO Roles. The FSMO Roles are by default created on the first Domain Controller installed in the Forest.
0
 
IATexpertAuthor Commented:
Those roles are here with us, in the home office.
0
 
JBond2010Commented:
OK.
0
 
IATexpertAuthor Commented:
So if they don't reconnect in say 60 days, and provided they aren't going to try and create more than a couple hundred objects, is it safe to say that AD will just grumble a lot, but that no real harm will come to it?
0
 
JBond2010Commented:
Yes this is correct! But the Servers are not able to update their time from the PDC Emulator Role, so this could cause problems. Also, as I said in my first comment they will not be able to demote DCs or promote Servers to DC. When the DCs run out of RIDs they will not be able to create new Objects. The Infrastructure Master Role is not able to update Active Directory because it cannot communicate with the Global Catalog on the other site.
0
 
IATexpertAuthor Commented:
Thanks!
0

Featured Post

Become an Android App Developer

Ready to kick start your career in 2018? Learn how to build an Android app in January’s Course of the Month and open the door to new opportunities.

  • 6
  • 6
Tackle projects and never again get stuck behind a technical roadblock.
Join Now