Active Directory Design - Syncing new site very slow

Hi All,

We have a AD infra with around 10000 user account and 20000 computer accounts. We have a Primary AD at head office and Child AD at each location which are remote sites having MPLS or VPN tunnels configured to sync with Primary AD.

Our issue is when we add more remotes sites and setup an Child AD the syncing between the Primary AD and Child AD take a long time. Is there any way to make it fast or is there any other design for AD with multiple remote sites.

Thanks and Regards
Darshan
dd2775Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Will SzymkowskiSenior Solution ArchitectCommented:
Not sure why you are creating Child Domains for ALL of your remote sites? This is not necessary and it just creates more complexity.

However child domains will use the InterSite replicaiton which is in AD Sites and services. The default value for AD Sites replication between each other is 180 minutes (3 hours).

You can modify this to be as low as every 15 minutes which i would recommend unless you have network constraints.

I would recommend checking out my two part series on AD Site and Services which will give you a better understanding of how it works and how it should be configured for best practices.

AD Sites and Services
http://www.wsit.ca/how-tos/active-directory/active-directory-sites-and-services-part-1/

Will.
1

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
ZenVenkyArchitectCommented:
Darshan I didn't understand what do you mean Child AD. Are you referring to another domain controller from different site or a DC part of child domain.

I assume that you are talking about additional DC, so make sure VPN tunnel configured correct, like site-to-site configuration is correct. As Will mentioned reduce replication interval to 15 minutes. Also if DCs are in different subnets, then make sure these subnets are configured properly over firewall.

Venkat
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.