Solved

DC in the "Cloud"

Posted on 2012-12-20
6
419 Views
Last Modified: 2013-01-23
Hello;

My company is currently putting together a disaster recovery plan, and along with it comes the infrastructure.

We have created a DC on WIN2K8 R2, and it is hosted out in the cloud.  We are wondering the best way to configure this for a failover scenario.

One scenario in particular, as you may have already guess, is our Pri and Secondary DCs fail in house, and we want to failover to the one out in the cloud...

Or, here is another, more disastrous scenario:  Our building is destroyed, and we need to be able to work from home, or a new office, and authenticate to our DC that is in the cloud.  I am guessing we would want VPN for this...

That means we would need NPS...

I also read that running a DC and VPN server on same box is not a good idea, from a security standpoint...  is this true/accurate?  Why?
0
Comment
Question by:cschmidt5
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 

Author Comment

by:cschmidt5
ID: 38710467
No takers?
0
 
LVL 14

Expert Comment

by:shahzoor
ID: 38717038
your scenario is interesting but i would do it in a different way
i would pay for a reliable backup system and would upload image to the cloud.
So that i could download the last image created and deploy it to the machine

the other solution is Windows Azure Virtual Network
http://www.windowsazure.com/en-us/manage/services/networking/replica-domain-controller/

i think it would solve your problem
0
 

Author Comment

by:cschmidt5
ID: 38740914
Well, we already have a DC hosted in the cloud, it is part of our "reliable" backup system.  If our building were to be destroyed our ultimate goal is to allow our users to VPN from home, and use the DC in the cloud for authentication.

I have been screwing around with a PPTP VPN server (Win2k8) but cannot for the life of me get my Cisco router to forward GRE port 47, even though the NAT rule is verified and configured right.  

Have any experience with this?
0
ScreenConnect 6.0 Free Trial

Explore all the enhancements in one game-changing release, ScreenConnect 6.0, based on partner feedback. New features include a redesigned UI, app configurations and chat acknowledgement to improve customer engagement!

 
LVL 24

Accepted Solution

by:
smckeown777 earned 500 total points
ID: 38740953
You mention NAT rules are setup ok - what about firewall? Need that port opened as well to allow the VPN to work...

How did you 'verify' that its configured right?
0
 

Author Comment

by:cschmidt5
ID: 38811186
Hi guys, once I got rid of the Cisco router (was using PAT) everything worked.  The cisco device was not using any firewall or ACL rules, just NAT.  The environment I am in is a test environment, so I just put my VPN server one one VLAN and the client on the other and of course everything works.  Now that I have this working I can test the other things I need to before I do this for real.  The actual VPN server will be in the cloud, hosted by someone (not sure who, my boss knows)   the NAT will be really simple.  I am now looking into getting IPSEC instead of PPTP - this looks tricky.
0
 

Author Closing Comment

by:cschmidt5
ID: 38811193
Your comment prompted me to just get rid of the old cisco router, as I suspected it was interfering with GRE to begin with  (  I just KNOW I had the ports forwarded right...)

I had also read elsewhere that too many switches and devices between the VPN server and client causes issues too, so that is another reason I ditched the cisco, on less "hop"
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For cloud, the “train has left the station” and in the Microsoft ERP & CRM world, that means the next generation of enterprise software from Microsoft is here: Dynamics 365 is Microsoft’s new integrated business solution that unifies CRM and ERP fun…
When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Need to grow your business through quality cloud solutions? With everything required to build a cloud platform and solution, you may feel like the distance between you and the cloud is quite long. Help is here. Spend some time learning about the Con…

735 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question