Solved

Backup virtual domain controller replication

Posted on 2011-09-13
3
251 Views
Last Modified: 2012-05-12
My company wants to create two virtual 2008 R2 servers on laptops in case of emergency. This way we can run a bare bones network with a DC and file server until we bring the main network back online. My question is that if I create a new DC with DNS obviously and then shut down the virtual machine until several days before a storm is likely to hit us will AD ans DNS continue to try and replicate to that machine even though it is not on? Also, will the  PDC put that DC into tombstone state if is unable to successfully replicate to it for a certain period of time. I would like to be able to set this emergency DC up, so I can use my NTFS permissions on the file server, but I do not want to cause more problems in the meantime. Any help and advice would be much appreciated with this.
0
Comment
Question by:KBElectronics
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 36529522
They will try and then see that the DC is offline.  If they can't replicate before the tombstone lifetime period (either 60 or 180 days) then yes it will be put into tombstone state

You can check the TSL http://markparris.co.uk/2010/02/01/active-directory-tombstone-lifetime-set-it-to-the-correct-value/

The good news is having at least 2 DCs in any network is important.   Just make sure that the laptops are secure too, you don't want someone stealing a laptop and walking away with the domain.

Obviously a second server or more traditional virtualization solution is better than a laptop but a laptop for a second DC is better than not having a second DC.

Thanks

Mike
0
 

Author Comment

by:KBElectronics
ID: 36529688
Thanks Mike. We actually do have to physical DC's in the building, the virtual DC on the laptop was meant to be physically locked up and brought out in the event a hurricane was approaching us. Then I would bring the server online, have it replicate and I could atleast have AD info on the laptop to run a skleton network if we lose the main. Once they see the DC is offline, will they continuously try to replicate, I do not want to stuff the event log with Ntfrs errors all day long ? Great link, exactly what my next questions was going to be regarding TSL.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 36530373
Can your laptop not be physically locked up in a place that has power and wifi? You could then just leave it on ALL the time and you have a second DC AND it will always be 100% upto date and ready to go.
P.S.
dont foget to make it a Global Catalog Server :P
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question