Solved

Sub Domain and Site Replication

Posted on 2013-11-13
5
652 Views
Last Modified: 2013-11-21
I have a corporate AD domain running on 2008 servers, for this question it is called X.com.
I also have an engineering group at a separate site, we are creating a separate network for them and want to add them as eng.x.com, they are running 2012

So, adding the subdomain to my AD should be easy, but since they are at another lcation, I am going to need to do Site replication and a bridgehead server, correct?

I have read up on doing the site replication and bridgehead server and how it works.  But, I have a few questions.

1-I will need to setup an permanent VPN tunnel up between the 2 sites correct?
2-I am assuming that I have the right idea here.
3-When I setup the new controller on the new network, I don't have to be connected to the Corporate network?  

Any other suggestions/information you can provide would be extremely helplful.
0
Comment
Question by:Buffl
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 12

Assisted Solution

by:piattnd
piattnd earned 250 total points
ID: 39645519
1) It is recommended to use a VPN rather than adjusting firewalls on both ends to allow all necessary network traffic, though the true requirement is simply network connectivity.

2) To know whether you have the right idea or not, you'll need to identify why you're creating this subdomain.  Why do you feel you need a subdomain?  How much of the infrastructure will be different than what you have?  For example, you seem to have a 2008 domain and forest, do you have a requirement for engineering to have a higher functional level and a reason not to raise the level of the forest/primary domain?  Unless you have some compelling reason for creating this child domain, I'd personally go for just creating another site and breaking them and their devices off onto a separate OU for group policy management.

3)  You have to have connectivity to the root domain, yes.  In order to create a child domain in a domain, the DC in the child domain has to be able to verify and communicate with the parent domain.  You will need to create a AD site that resembles this new site for replication reasons (it's not a LAN link, so replication intervals will likely be spread out more).
0
 
LVL 24

Accepted Solution

by:
Sandeshdubey earned 250 total points
ID: 39646781
One best practice is to try and limit the number of domains, is there a reason you are going with a child domain in this situation.Avoid having a multi-domain forest In pre-Windows Server 2008-based AD, creating multiple domains would typically be necessary to accomodate different password policies - but, with the introduction of Fine Grained Password Policy in Windows 2008 DFL, this is no longer the case.

Instead of creating child domain you can promote the server in remote site as additional DC(ADC).You can create seperate OU for remote users and computer and apply the policies as per requirement.You can also delegate admin related permission to remote site admin user as per requirement.

Determining the Number of Domains Required
http://technet.microsoft.com/en-us/library/cc732201(WS.10).aspx

Domain controllers # Determining the number of domain controllers you need
http://technet.microsoft.com/en-us/library/cc759623(v=WS.10).aspx

In general it is recommended that at least two DCs in a domain for high availablity and fault tolerance, but how many DCs at each site will depend on your requirement. Normally one DC at each site can serve thousands of users with regard to authentication.

Yes,there should be connectivity between the sites continuosly and VPN is the way to go.In either case child domain or ADC you need to have site connectivity to main office.
0
 
LVL 20

Expert Comment

by:compdigit44
ID: 39649736
Sandeshdubey, brings up a very good point. You really should limit the number of domains you create unless it is absolutely necessary. You should only create a new domain if there is a requirement for the sub-domain to govern themselves. Although for true separate to control in high security environments is to create a separate forest since it is possible of a sub-domain admin to elevate there rights to be an enterprise admin.
0
 

Author Comment

by:Buffl
ID: 39667240
I have been convinced that we will do a site and not a sub domain.   Thanks

Now I just have to get the step by steps for setting it up on the 2008 server and 2012 server.
0
 

Author Comment

by:Buffl
ID: 39667275
I was reading up on this on another forum..that it would not be a good idea to have my RRAS server and my DC on the same server?

I have that currently on my 2008 AD server, but from what I read having the RRAS server on the DC in a replication setup could be a problem?
0

Featured Post

Is Your DevOps Pipeline Leaking?

Is your CI/CD pipeline a hodge-podge of randomly connected tools? You’ve likely got a tool to fix one problem & then a different tool to fix another, resulting in a cluster of tools with overlapping functionality. Learn how to optimize your pipeline with Gartner's recommendations

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question