I think,reading between the lines, that OU's would be good. The main
issue is to be able to have all the users, in all the offices existing
under one Forest. If that means several child domains, so be it, if that
means all in one domain, again, so be it.

However, whether it be child domains or bringing their workgroup servers
into ou existing AD domain as remote GC's, the fact remains that we
don't know how to go about starting the process.

If I can quote from my original email, I need some advice on setting up
the DNS at both ends so that when we enter the domain name into the
DCPROMO util at the remote sites, it will stop throwing up an error
about how it cant find an AD install at that domain. The forward and
reverse zones seem to be setup ok, and the VPN allows us to ping the
machines across the network, but clearly something is wrong.

Olly 

-----Original Message-----
From: Kingslan, Rick T. [mailto:[EMAIL PROTECTED] 
Sent: 20 October 2003 13:49
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] Remote network AD setup

Oliver,

Personally, unless there is a specific security (minimal protection
anyway....but it's a 'feature) or password / account lockout issue that
would require a new domain, the benefit is minimal.  There is
replication boundary to consider, but unless you're talking many, many
changes and many objects, it's not worth the added effort, expense
(multiple DC's per domain), etc. of maintaining a bunch of added
domains.

My company has 4 domains - an empty root and three child domains.  The
children were created for specific independent operating units.  A
separation of church and state, if you will.

In our largest domain, we have ~ 16k users and workstations.  In that
one domain, I have 15 remote sites spread around the country - from
Virginia to Nevada.  We separate all of these sites out by OU because we
can:

*  Manage them independently
*  Apply Group Policy as necessary
*  Use Delegation to give the remote site personnel the proper authority

Now, we don't have a speed of replication issues as all of our sites are
connected via either multiple T-1s, T-3s, or ATM.

I guess what I'm saying is if you're dealing with Branch Office
scenarios (I support anywhere from 150 to 1000 people in a per site
basis - depending on which one), domains are not the right solution
unless password / account lockout are the real problem.  And, in most
cases, replication traffic is not the reason to create domains over OUs.
The only traffic that you're saving is the domain-related traffic.
Global catalog and schema are still replicated to all DC's in the
forest.

Rick Kingslan  MCSE, MCSA, MCT
Microsoft MVP - Active Directory
LAN Administration - Windows 2000
West Corporation
[EMAIL PROTECTED]


-----Original Message-----
From: Oliver Marshall [mailto:[EMAIL PROTECTED]
Sent: Monday, October 20, 2003 3:45 AM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Remote network AD setup


We have an head office running an AD based network. We have several
smaller satellite offices running workgroup based networks.

We now need to integrate all the offices into one AD so that users can
move able with the same logons, and that all the AD management and
maintainance can be done from one place.

I was thinking of settup up the smaller offices as child domains of the
main one, so small_office1.mydomain.com etc, which, as I understand it,
should allow me to manage all the user accounts from one place. I was
also going to have a GC at each small office so that they can still
logon etc if the lines are disconnected.

The question I have though is (maybe) a simple one. How do I setup the
DNS so that the DCPROMO applet in each satellite office will work ?
Currently the sites are connected via VPN, and each satellite office has
forward and reverse DNS entries pointing to the Head Offices domain
(using the internal IP's). However, when we enter the domain into the
domain section of the DCPROMO applet, it barfs a lung.

I know that im missing something, or coming at this the wrong way, but I
have no idea where to start. If you could help that would be great.

Olly
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/


List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to