That really depends on the environment. Running a DC on a DNS server might be 
fine if it's a Windows box. But a lot of larger organisations will have DNS 
running on non-Windows boxes (especially for public DNS and also for DNS 
namespaces that have nothing to do with AD namespaces)

Also, if it's just to get VMWare ESX started, then I wouldn't make this box a 
DC necessarily. It's one more thing that needs to be secured, updated, patched, 
migrated, whatever. The bigger the environment, the more that costs.

Cheers
Ken

________________________________________
From: John Cook [[email protected]]
Sent: Wednesday, 1 April 2009 12:15 AM
To: NT System Admin Issues
Subject: RE: Pros/Cons of putting PDC/2DC on Virtual Server

I think his point was to have the FSMO away from the VMs (not that that is a 
big deal) BUT if you're already going to have a box running DNS why wouldn't 
you take the 10 - 20 extra minutes (depending on the size of your AD) to 
DCpromo it and have an online backup of AD as well? I've had redundancy 
hammered into me from day one (I doubt many of you buy servers with single NICs 
or power supplies) and this is just one easy, reliable, low cost (if done 
right) means of adding that protection to AD. I never said it was a bad idea to 
have your DCs in VMs IF they are on separate hosts, I just like the comfort 
level provided by a quiet little box locked away in a closet somewhere offsite 
keeping incredibly important things like AD backed up.

John W. Cook
Systems Administrator
Partnership For Strong Families
315 SE 2nd Ave
Gainesville, Fl 32601
Office (352) 393-2741 x320
Cell     (352) 215-6944
Fax     (352) 393-2746
MCSE, MCTS, MCP+I,CompTIA A+, N+

-----Original Message-----
From: Ken Schaefer [mailto:[email protected]]
Sent: Tuesday, March 31, 2009 12:48 AM
To: NT System Admin Issues
Subject: RE: Pros/Cons of putting PDC/2DC on Virtual Server

I'm not aware of FSMO roles having anything to do with DNS. So why do you need 
a physical DC (with or without FSMO roles)? Just keep a physical DNS server 
around...

Cheers
Ken

________________________________________
From: Kurt Buff [[email protected]]
Sent: Tuesday, 31 March 2009 10:08 AM
To: NT System Admin Issues
Subject: Re: Pros/Cons of putting PDC/2DC on Virtual Server

On Mon, Mar 30, 2009 at 15:30, Bill Songstad (WCUL)
<[email protected]> wrote:
> If my SAN had a major issue, neither my VMs or my physical DC would have
> anything to d���������������  All my clients could authenticate, but they 
> would����������������������t
> have anything to access.
>
>
>
> I really feel lik������������������������������������m missing an obvious 
> underlying concept here and that
> makes me nervous.

VMWare gets quite unhappy when it can't talk to a DNS server. In most
Windows environments, the DCs are also the DNS servers, therefore
virtualizing *all* of your DCs, or rather, virtualizing them all on
the *same* DC, puts that VMWare host at risk.

That's reason enough for me to keep one DC (probably the one with the
FSMO roles) on its own physical machine.

Kurt
~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

CONFIDENTIALITY STATEMENT: The information transmitted, or contained or 
attached to or with this Notice is intended only for the person or entity to 
which it is addressed and may contain Protected Health Information (PHI), 
confidential and/or privileged material. Any review, transmission, 
dissemination, or other use of, and taking any action in reliance upon this 
information by persons or entities other than the intended recipient without 
the express written consent of the sender are prohibited. This information may 
be protected by the Health Insurance Portability and Accountability Act of 1996 
(HIPAA), and other Federal and Florida laws. Improper or unauthorized use or 
disclosure of this information could result in civil and/or criminal penalties.
 Consider the environment. Please don't print this e-mail unless you really 
need to.

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~
~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to