Networking Forums

Networking Forums > Computer Networking > Windows Networking > DHCP on domain controller or member server

Reply
Thread Tools Display Modes

DHCP on domain controller or member server

 
 
Oskarsson Mikael
Guest
Posts: n/a

 
      08-08-2004, 04:55 PM
We have a W2K-domain with 3 DC (singel-domain) , DNS is AD-integrated and in
secure mode.
We are going to install DHCP on 2 of the 3 DC:s.
For 2 years ago (in W2K-book) a read something about not installing DHCP on
DC:s, something about ownership of records and about the group DNSProxy.
This summer a read a book about DHCP with Windows 2003 and is says that I
should not install DHCP on DC:s.

Can anybody gives me more info or any tips.

Regards Mikael



 
Reply With Quote
 
 
 
 
Miha Pihler
Guest
Posts: n/a

 
      08-08-2004, 05:46 PM
Hi Mikael,

One of rare services that I allow to be installed on DCs is DHCP (along with
DNS, ...) and till now I didn't have any problems. It is also configuration
supported by Microsoft.

The only thing to watch out for when setting up DHCP is after you install
first DHCP on first DC allow enough time for data to be replicated through
the AD before you install next DHCP.

Corrupted Security Groups Are Created When You Install DHCP or WINS on
Multiple Domain Controllers
http://support.microsoft.com/default...uct=winsvr2003

Again, this is just my experience. I hope it helps,

Mike

"Oskarsson Mikael" <mo-(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> We have a W2K-domain with 3 DC (singel-domain) , DNS is AD-integrated and

in
> secure mode.
> We are going to install DHCP on 2 of the 3 DC:s.
> For 2 years ago (in W2K-book) a read something about not installing DHCP

on
> DC:s, something about ownership of records and about the group DNSProxy.
> This summer a read a book about DHCP with Windows 2003 and is says that I
> should not install DHCP on DC:s.
>
> Can anybody gives me more info or any tips.
>
> Regards Mikael
>
>
>



 
Reply With Quote
 
Robert Moir
Guest
Posts: n/a

 
      08-08-2004, 09:43 PM
Oskarsson Mikael wrote:
> We have a W2K-domain with 3 DC (singel-domain) , DNS is AD-integrated
> and in secure mode.
> We are going to install DHCP on 2 of the 3 DC:s.
> For 2 years ago (in W2K-book) a read something about not installing
> DHCP on DC:s, something about ownership of records and about the
> group DNSProxy. This summer a read a book about DHCP with Windows
> 2003 and is says that I should not install DHCP on DC:s.
>
> Can anybody gives me more info or any tips.


To follow on from Miha's points, I too use DHCP running on DCs without a
problem.

Quite often, a book will talk about a possibility of a problem, or a
theoretical lapse in security from a certain scenario. Now the book can be
perfectly accurate in what it says, but it may be that many "real life"
networks are not worried about the problem mentioned or don't need that
level of security (security is very important to me, and a big part of my
job, but I am not securing the secrets of the NSA, CIA, MI5 or the Bank of
England).

More likely, the cost of preventing something vs. the likelyhood of it
happening vs. trying to make your budget stretch to do all you want dictate
that you shrug your shoulders and ignore what books say sometimes. You have
to be pragmatic about these things.

Regards
Rob Moir [ms mvp]



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
add member server to domain SANMAN07 Windows Networking 4 12-31-2006 05:25 AM
Should our web server be a domain member? OscarVogel Windows Networking 17 04-14-2006 12:11 AM
Automatic certificate enrollment for local system failed after upgrading member server to domain controller Arch Willingham Windows Networking 4 08-28-2005 09:17 PM
WINS on a Server 2003 running as member server in NT 4.0 Domain? Nils Windows Networking 2 06-03-2005 02:33 PM
2003 Member server in a NT4 domain =?Utf-8?B?Y2FzZXliMQ==?= Windows Networking 3 03-08-2005 05:52 PM



1 2 3 4 5 6 7 8 9 10 11