You can create as many DNS Zones below the parent zone or TLD as you want
even with one AD Domain.  As part of the GPO you can set workstations DNS
prefix settings so that they register to the subzone instead of the parent
zone.  It does require the workstations to reboot though.

So if your AD is XYZ.COM, you could create a zone called ws.xyz.com for your
workstations to register dynamically in, and just set the GPO to set the
settings on their workstation.  Most people recommend that you setup your
zones based on geography though.

Todd Myrick
http://www.toddm.org/adog
Become ADOG now!
 

-----Original Message-----
From: Oliver Marshall [mailto:[EMAIL PROTECTED] 
Sent: Monday, October 20, 2003 9:20 AM
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] Remote network AD setup


I think,reading between the lines, that OU's would be good. The main issue
is to be able to have all the users, in all the offices existing under one
Forest. If that means several child domains, so be it, if that means all in
one domain, again, so be it.

However, whether it be child domains or bringing their workgroup servers
into ou existing AD domain as remote GC's, the fact remains that we don't
know how to go about starting the process.

If I can quote from my original email, I need some advice on setting up the
DNS at both ends so that when we enter the domain name into the DCPROMO util
at the remote sites, it will stop throwing up an error about how it cant
find an AD install at that domain. The forward and reverse zones seem to be
setup ok, and the VPN allows us to ping the machines across the network, but
clearly something is wrong.

Olly 

-----Original Message-----
From: Kingslan, Rick T. [mailto:[EMAIL PROTECTED] 
Sent: 20 October 2003 13:49
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] Remote network AD setup

Oliver,

Personally, unless there is a specific security (minimal protection
anyway....but it's a 'feature) or password / account lockout issue that
would require a new domain, the benefit is minimal.  There is replication
boundary to consider, but unless you're talking many, many changes and many
objects, it's not worth the added effort, expense (multiple DC's per
domain), etc. of maintaining a bunch of added domains.

My company has 4 domains - an empty root and three child domains.  The
children were created for specific independent operating units.  A
separation of church and state, if you will.

In our largest domain, we have ~ 16k users and workstations.  In that one
domain, I have 15 remote sites spread around the country - from Virginia to
Nevada.  We separate all of these sites out by OU because we
can:

*  Manage them independently
*  Apply Group Policy as necessary
*  Use Delegation to give the remote site personnel the proper authority

Now, we don't have a speed of replication issues as all of our sites are
connected via either multiple T-1s, T-3s, or ATM.

I guess what I'm saying is if you're dealing with Branch Office scenarios (I
support anywhere from 150 to 1000 people in a per site basis - depending on
which one), domains are not the right solution unless password / account
lockout are the real problem.  And, in most cases, replication traffic is
not the reason to create domains over OUs. The only traffic that you're
saving is the domain-related traffic. Global catalog and schema are still
replicated to all DC's in the forest.

Rick Kingslan  MCSE, MCSA, MCT
Microsoft MVP - Active Directory
LAN Administration - Windows 2000
West Corporation
[EMAIL PROTECTED]


-----Original Message-----
From: Oliver Marshall [mailto:[EMAIL PROTECTED]
Sent: Monday, October 20, 2003 3:45 AM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Remote network AD setup


We have an head office running an AD based network. We have several smaller
satellite offices running workgroup based networks.

We now need to integrate all the offices into one AD so that users can move
able with the same logons, and that all the AD management and maintainance
can be done from one place.

I was thinking of settup up the smaller offices as child domains of the main
one, so small_office1.mydomain.com etc, which, as I understand it, should
allow me to manage all the user accounts from one place. I was also going to
have a GC at each small office so that they can still logon etc if the lines
are disconnected.

The question I have though is (maybe) a simple one. How do I setup the DNS
so that the DCPROMO applet in each satellite office will work ? Currently
the sites are connected via VPN, and each satellite office has forward and
reverse DNS entries pointing to the Head Offices domain (using the internal
IP's). However, when we enter the domain into the domain section of the
DCPROMO applet, it barfs a lung.

I know that im missing something, or coming at this the wrong way, but I
have no idea where to start. If you could help that would be great.

Olly
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/


List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to