Solved

DC in the "Cloud"

Posted on 2012-12-20
6
356 Views
Last Modified: 2013-01-23
Hello;

My company is currently putting together a disaster recovery plan, and along with it comes the infrastructure.

We have created a DC on WIN2K8 R2, and it is hosted out in the cloud.  We are wondering the best way to configure this for a failover scenario.

One scenario in particular, as you may have already guess, is our Pri and Secondary DCs fail in house, and we want to failover to the one out in the cloud...

Or, here is another, more disastrous scenario:  Our building is destroyed, and we need to be able to work from home, or a new office, and authenticate to our DC that is in the cloud.  I am guessing we would want VPN for this...

That means we would need NPS...

I also read that running a DC and VPN server on same box is not a good idea, from a security standpoint...  is this true/accurate?  Why?
0
Comment
Question by:cschmidt5
  • 4
6 Comments
 

Author Comment

by:cschmidt5
Comment Utility
No takers?
0
 
LVL 14

Expert Comment

by:shahzoor
Comment Utility
your scenario is interesting but i would do it in a different way
i would pay for a reliable backup system and would upload image to the cloud.
So that i could download the last image created and deploy it to the machine

the other solution is Windows Azure Virtual Network
http://www.windowsazure.com/en-us/manage/services/networking/replica-domain-controller/

i think it would solve your problem
0
 

Author Comment

by:cschmidt5
Comment Utility
Well, we already have a DC hosted in the cloud, it is part of our "reliable" backup system.  If our building were to be destroyed our ultimate goal is to allow our users to VPN from home, and use the DC in the cloud for authentication.

I have been screwing around with a PPTP VPN server (Win2k8) but cannot for the life of me get my Cisco router to forward GRE port 47, even though the NAT rule is verified and configured right.  

Have any experience with this?
0
Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

 
LVL 24

Accepted Solution

by:
smckeown777 earned 500 total points
Comment Utility
You mention NAT rules are setup ok - what about firewall? Need that port opened as well to allow the VPN to work...

How did you 'verify' that its configured right?
0
 

Author Comment

by:cschmidt5
Comment Utility
Hi guys, once I got rid of the Cisco router (was using PAT) everything worked.  The cisco device was not using any firewall or ACL rules, just NAT.  The environment I am in is a test environment, so I just put my VPN server one one VLAN and the client on the other and of course everything works.  Now that I have this working I can test the other things I need to before I do this for real.  The actual VPN server will be in the cloud, hosted by someone (not sure who, my boss knows)   the NAT will be really simple.  I am now looking into getting IPSEC instead of PPTP - this looks tricky.
0
 

Author Closing Comment

by:cschmidt5
Comment Utility
Your comment prompted me to just get rid of the old cisco router, as I suspected it was interfering with GRE to begin with  (  I just KNOW I had the ports forwarded right...)

I had also read elsewhere that too many switches and devices between the VPN server and client causes issues too, so that is another reason I ditched the cisco, on less "hop"
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

As companies replace their old PBX phone systems with Unified IP Communications, many are finding out that legacy applications such as fax do not work well with VoIP. Fortunately, Cloud Faxing provides a cost-effective alternative that works over an…
When the confidentiality and security of your data is a must, trust the highly encrypted cloud fax portfolio used by 12 million businesses worldwide, including nearly half of the Fortune 500.
This Micro Tutorial will explain how to export DynamoDB tables in Amazon Web Services.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now