SolvedPrivate

Active Directory - Disaster Recovery Testing

Posted on 2014-07-22
6
6 Views
Last Modified: 2016-06-21
Hello,

I'm having some issues testing our backups/replicas for disaster recovery purposes when it comes to Active Directory on our domain controllers.

We are currently running Windows 2003 servers for active directory.
We have two forest level controllers, one physical and one virtual.
We have 10 domain level controllers, one physical and the rest virtual.
All virtual controllers are on VMware ESXi 5.1.

I setup an isolated "test" network within VCenter in order to test this disaster recovery.
I made replicas of one virtual forest controller and one domain controller using Veeam 7 and made sure to enable application-aware image processing.
After I boot these VMs in the test environment Active Directory is not working properly.
The error logs show both servers are unable to find the domains they are a part of.

What are some best practices/methods for disaster recovery/testing that could be employed withing the environment we have?
We are obviously missing something to cause these replica servers not to work right.

Thanks.
0
Comment
Question by:asantia
  • 2
  • 2
6 Comments
 
LVL 119

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 250 total points
ID: 40212704
I was at a discussion last week at Microsoft Research, because for the last few months, we have been testing DR scenarios of Active Directory 2003, 2008 and 2012, and we have found, unless "ALL" Domain Controllers are restored from the same backup (time) at the same time, if a single DC as part of the AD DC/Forest is not correct, AD would have issues.

So the question put to Microsoft was "why have more than a single DC" if we can now restore a DC so fast because it's virtual!

and they agreed, just have a single DC!

Now this works, if you do not have Remote Offices, or need more than one because of loading....

but its' food for thought!

Why have you go so many, because we have found the more DCs, the worse DR gets.....I can only assume you have so many because of loading, users, and Remote Offices ?

We are now working on, if a DC goes BAD, do not restore, remove from AD, and Sieze the roles.
0
 

Author Comment

by:asantia
ID: 40212733
Correct. The main reason for the number is remote offices, so no way past keeping at least one at each location.
The physical servers are the originals before the virtual environment was setup, so they are here for now.
We do have two domain controllers in our corporate center because of load.
All the other offices only have one.

The initial test (as described above):
Trying to go almost worse-case scenario...
If all but one forest and one domain controller were gone, how could we get up and running?

The second test:
Our corporate data center is lost...
How can we recover from just our remote offices' domain controllers?
(The forest controllers are only in our corporate office, so assume they are both unavailable.)
0
 
LVL 19

Assisted Solution

by:compdigit44
compdigit44 earned 250 total points
ID: 40215693
At work we have 6 DC's and all FSMO roles on one DC. We then use vRanger backup to restore full images of our FSMO roll holder DC to our lab environment which does not connect to or production network regularly all the time without issue.
0
 
LVL 119
ID: 40215706
@compdigit44 2008 or 2012 ? as part of our head scratching exercise....

This DC with the FSMO rolls, how is DNS configured?

e.g. does it refer to itself as first DNS in TCP/IP settings?

as 127.0.0.1 or IP Address, or is it using a different DNS server ?

and are the other 6 DCs, also DNS ?
0
 

Author Comment

by:asantia
ID: 40283609
All DCs reference themselves as the primary DNS by their actual internal IP address.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This Micro Tutorial walks you through using a remote console to access a server and install ESXi 5.1. This example is showing remote access and installation using a Dell server. The hypervisor is the very first component of your virtual infrastructu…
This video shows you how to use a vSphere client to connect to your ESX host as the root user. Demonstrates the basic connection of bypassing certification set up. Demonstrates how to access the traditional view to begin managing your virtual mac…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question