Let's see if I have it then; and this time I'll use punctuation and spell check 
(it seems I'm my own worst pet peeve).  

The hypervisor WILL boot without AD authentication.  As long as you have no 
other services or servers needing AD authentication besides the ones on the VM, 
the Physical DC provides no necessary AUTHENTICATION.  

Booting a hypervisor IS quicker and easier if there is a DNS server available.  
And since your DNS is often on a DC, it is better to keep the DC/DNS server 
accessible.

The real value of the physical DC is the same as the best practice of having 
multiple DCs altogether:  If you completely ruin a DC you won't lose any AD 
information.  And if you have a disk catastrophe on your VM/SAN, you greatly 
increase the likelihood of ruining multiple DCs if multiple DCs do inhabit that 
VM.

Am I on track?

A lot of Best Practices don't scale well to a small organization, but some 
things are just flat out good ideas.  I'm making VMs an integral part of my 
server maintenance and DR plans.  One of the main reasons is to leverage more 
reliable hardware by putting most of my machines on a single, more robust 
machine.  The other is to reduce the downtime of hardware repairs if/when 
needed.  I will as a result of this conversation, be putting a DC on a separate 
physical machine and storage array.  I'll just virtualize it there.

Unless of course, I'm still missing something...

Bill 


-----Original Message-----
From: John Cook [mailto:[email protected]] 
Sent: Monday, March 30, 2009 3:48 PM
To: NT System Admin Issues
Subject: Re: Pros/Cons of putting PDC/2DC on Virtual Server

I guess if EVERYTHING in your environment is on that 1 box then you have much 
more to worry about than authentication. That said one can have other NAS 
devices that require authentication and just because you can bring a VM DC back 
up doesn't mean it didn't suffer some form of corruption or loss of data. It 
all boils down to what your DR plan is, I don't mind spinning the meter to know 
I have a consistent copy of AD. YMMV
John W. Cook
Systems Administrator
Partnership For Strong Families
 Sent to you from my Blackberry in the Cloud

----- Original Message -----
From: Sam Cayze <[email protected]>
To: NT System Admin Issues <[email protected]>
Sent: Mon Mar 30 18:35:44 2009
Subject: RE: Pros/Cons of putting PDC/2DC on Virtual Server

+1 on the confusion...

-----Original Message-----
From: Brian Desmond [mailto:[email protected]]
Sent: Monday, March 30, 2009 5:33 PM
To: NT System Admin Issues
Subject: RE: Pros/Cons of putting PDC/2DC on Virtual Server

Why would booting VMs be dependent on this?

Thanks,
Brian Desmond
[email protected]

c - 312.731.3132

Active Directory, 4th Ed - http://www.briandesmond.com/ad4/ Microsoft MVP - 
https://mvp.support.microsoft.com/profile/Brian


-----Original Message-----
From: [email protected] [mailto:[email protected]]
Sent: Monday, March 30, 2009 5:06 PM
To: NT System Admin Issues
Subject: RE: Pros/Cons of putting PDC/2DC on Virtual Server

Try bringing up your virtual environment with no authentication or name 
resolution if your Domain Controller VM goes down and no physical DC.

Mike

Original Message:
-----------------
From: Bill Songstad (WCUL) [email protected]
Date: Mon, 30 Mar 2009 14:35:33 -0700
To: [email protected]
Subject: RE: Pros/Cons of putting PDC/2DC on Virtual Server


m going to throw my opinion in to see if I can get my thinking torn apart am 
unsure of the value of the physical boxes.  I am in the process of planning the 
ebad p as the original poster is dealing with.  I have three servers built on 
cheap hardware.  Sometimes controllers fail or disks fail or get full and 
moving up to new hardware is a pain.  But if I put all three on a s�� server 
with hotswap everything, I get a level of reliability, scalability, and 
recoverability that I could not previously afford.



I am not seeing the why of not putting all the DCs on a VM.  If my VM goes 
down, all the servers are down, yes, but all the servers are good and I can 
restore them to dissimilar hardware in a jiffy.  If I keep a physical DC off 
the VM, all my other servers are still down so nobody is working still.
I guess what Im asking is what is the value of having a physical DC if
nobody can get to file-and-print or sql or exchange?   What is the purpose
of the extra physical box?  Is there a problem with having all of AD down at 
one time? (I mean other than not allowing access to other resources; of which I 
have none)



I suppose if I really should keep a physical server, I certainly wt have 
anything critical on it.  I justt like the idea of keeping an extra $1000 box 
with a $650 license on it just to keep the domain on two machines.



Bring on the ridicule ifm making a mistake.  I opened my mouth to learn 
something h  I just havet seen a good reason to have a physical DC if all your 
other servers are on a single VM.



Bill





From: Benjamin Zachary - Lists [mailto:[email protected]]
Sent: Thursday, March 26, 2009 3:58 PM
To: NT System Admin Issues
Subject: RE: Pros/Cons of putting PDC/2DC on Virtual Server




I do/have all dcs ed in vm environments. I do understand feel g scenario. 
However, I place as much trust in the esx delivery as I do the physical box, if 
not more so since the vm is portable.
Thats my .02.

This structure is based around a san with or w/o vmotion (depending on budget). 
You can put a san together for next to nothing, that is fairly robust 
(drbd/openfiler/iet). With Esxi, and no vmotion. If a physical esx goes down 
you simply start them on the other machine. Its not pretty but it works, and a 
small/med shop that can be down for 15 minutes while someone does that can be 
worth saving the 5k.

If you are talking about putting all your eggs in one basket thats acceptable 
in small/med environments. I know you mention this is a large environment so 
then I wonder how big could it be with just 1 exchange and 2 dcs ?

Everything regarding restoring s with DC data is well documented and there 
should be no surprises for those who need to do that.

On the physical box, if the server crashes you have it even worse, because you 
cant juresto the image. You have to go rebuild the server, join the domain and 
then promote it again, or restore from backup. That actually sounds like more 
work, then restoring the vm, rolling back the ticket.

In your particular case, it sounds like the advantages vmware gives you , 
space, consumption, failover have all been swept aside to save dollars.
Therefore, I would say you should rethink the current solution.








~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ 
<http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~


--------------------------------------------------------------------
mail2web.com What can On Demand Business Solutions do for you?
http://link.mail2web.com/Business/SharePoint



~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ 
<http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~


~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ 
<http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

CONFIDENTIALITY STATEMENT: The information transmitted, or contained or 
attached to or with this Notice is intended only for the person or entity to 
which it is addressed and may contain Protected Health Information (PHI), 
confidential and/or privileged material. Any review, transmission, 
dissemination, or other use of, and taking any action in reliance upon this 
information by persons or entities other than the intended recipient without 
the express written consent of the sender are prohibited. This information may 
be protected by the Health Insurance Portability and Accountability Act of 1996 
(HIPAA), and other Federal and Florida laws. Improper or unauthorized use or 
disclosure of this information could result in civil and/or criminal penalties.
 Consider the environment. Please don't print this e-mail unless you really 
need to.

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to