SolvedPrivate

Active Directory - Disaster Recovery Testing

Posted on 2014-07-22
6
7 Views
Last Modified: 2016-06-21
Hello,

I'm having some issues testing our backups/replicas for disaster recovery purposes when it comes to Active Directory on our domain controllers.

We are currently running Windows 2003 servers for active directory.
We have two forest level controllers, one physical and one virtual.
We have 10 domain level controllers, one physical and the rest virtual.
All virtual controllers are on VMware ESXi 5.1.

I setup an isolated "test" network within VCenter in order to test this disaster recovery.
I made replicas of one virtual forest controller and one domain controller using Veeam 7 and made sure to enable application-aware image processing.
After I boot these VMs in the test environment Active Directory is not working properly.
The error logs show both servers are unable to find the domains they are a part of.

What are some best practices/methods for disaster recovery/testing that could be employed withing the environment we have?
We are obviously missing something to cause these replica servers not to work right.

Thanks.
0
Comment
Question by:asantia
  • 2
  • 2
6 Comments
 
LVL 119

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 250 total points
ID: 40212704
I was at a discussion last week at Microsoft Research, because for the last few months, we have been testing DR scenarios of Active Directory 2003, 2008 and 2012, and we have found, unless "ALL" Domain Controllers are restored from the same backup (time) at the same time, if a single DC as part of the AD DC/Forest is not correct, AD would have issues.

So the question put to Microsoft was "why have more than a single DC" if we can now restore a DC so fast because it's virtual!

and they agreed, just have a single DC!

Now this works, if you do not have Remote Offices, or need more than one because of loading....

but its' food for thought!

Why have you go so many, because we have found the more DCs, the worse DR gets.....I can only assume you have so many because of loading, users, and Remote Offices ?

We are now working on, if a DC goes BAD, do not restore, remove from AD, and Sieze the roles.
0
 

Author Comment

by:asantia
ID: 40212733
Correct. The main reason for the number is remote offices, so no way past keeping at least one at each location.
The physical servers are the originals before the virtual environment was setup, so they are here for now.
We do have two domain controllers in our corporate center because of load.
All the other offices only have one.

The initial test (as described above):
Trying to go almost worse-case scenario...
If all but one forest and one domain controller were gone, how could we get up and running?

The second test:
Our corporate data center is lost...
How can we recover from just our remote offices' domain controllers?
(The forest controllers are only in our corporate office, so assume they are both unavailable.)
0
 
LVL 19

Assisted Solution

by:compdigit44
compdigit44 earned 250 total points
ID: 40215693
At work we have 6 DC's and all FSMO roles on one DC. We then use vRanger backup to restore full images of our FSMO roll holder DC to our lab environment which does not connect to or production network regularly all the time without issue.
0
 
LVL 119
ID: 40215706
@compdigit44 2008 or 2012 ? as part of our head scratching exercise....

This DC with the FSMO rolls, how is DNS configured?

e.g. does it refer to itself as first DNS in TCP/IP settings?

as 127.0.0.1 or IP Address, or is it using a different DNS server ?

and are the other 6 DCs, also DNS ?
0
 

Author Comment

by:asantia
ID: 40283609
All DCs reference themselves as the primary DNS by their actual internal IP address.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article runs through the process of deploying a single EXE application selectively to a group of user.
Learn how the use of a bunch of disparate tools requiring a lot of manual attention led to a series of unfortunate backup events for one company.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question