Oliver,

I agree with Rick, you go much father with your dollar if you place DC/GC's
from the root domain onto networks that have high population of users, and
for smaller networks you can have the authentication traffic and Name
Resolution traffic across the WAN to central DC/GC's.  Windows 200x and
Windows 2K/XP using Kerberos is much better than NTLM when it comes to file
and print access, authentication, etc.  

Todd Myrick
http://www.toddm.org/adog
Become ADOG now!

-----Original Message-----
From: Kingslan, Rick T. [mailto:[EMAIL PROTECTED] 
Sent: Monday, October 20, 2003 8:49 AM
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] Remote network AD setup


Oliver,

Personally, unless there is a specific security (minimal protection
anyway....but it's a 'feature) or password / account lockout issue that
would require a new domain, the benefit is minimal.  There is replication
boundary to consider, but unless you're talking many, many changes and many
objects, it's not worth the added effort, expense (multiple DC's per
domain), etc. of maintaining a bunch of added domains.

My company has 4 domains - an empty root and three child domains.  The
children were created for specific independent operating units.  A
separation of church and state, if you will.

In our largest domain, we have ~ 16k users and workstations.  In that one
domain, I have 15 remote sites spread around the country - from Virginia to
Nevada.  We separate all of these sites out by OU because we
can:

*  Manage them independently
*  Apply Group Policy as necessary
*  Use Delegation to give the remote site personnel the proper authority

Now, we don't have a speed of replication issues as all of our sites are
connected via either multiple T-1s, T-3s, or ATM.

I guess what I'm saying is if you're dealing with Branch Office scenarios (I
support anywhere from 150 to 1000 people in a per site basis - depending on
which one), domains are not the right solution unless password / account
lockout are the real problem.  And, in most cases, replication traffic is
not the reason to create domains over OUs. The only traffic that you're
saving is the domain-related traffic. Global catalog and schema are still
replicated to all DC's in the forest.

Rick Kingslan  MCSE, MCSA, MCT
Microsoft MVP - Active Directory
LAN Administration - Windows 2000
West Corporation
[EMAIL PROTECTED]


-----Original Message-----
From: Oliver Marshall [mailto:[EMAIL PROTECTED] 
Sent: Monday, October 20, 2003 3:45 AM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Remote network AD setup


We have an head office running an AD based network. We have several smaller
satellite offices running workgroup based networks.

We now need to integrate all the offices into one AD so that users can move
able with the same logons, and that all the AD management and maintainance
can be done from one place.

I was thinking of settup up the smaller offices as child domains of the main
one, so small_office1.mydomain.com etc, which, as I understand it, should
allow me to manage all the user accounts from one place. I was also going to
have a GC at each small office so that they can still logon etc if the lines
are disconnected.

The question I have though is (maybe) a simple one. How do I setup the DNS
so that the DCPROMO applet in each satellite office will work ? Currently
the sites are connected via VPN, and each satellite office has forward and
reverse DNS entries pointing to the Head Offices domain (using the internal
IP's). However, when we enter the domain into the domain section of the
DCPROMO applet, it barfs a lung.

I know that im missing something, or coming at this the wrong way, but I
have no idea where to start. If you could help that would be great.

Olly
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to