Networking Forums

Networking Forums > Computer Networking > Windows Networking > Recommendations for best practice for designing geographically disparateAD

Reply
Thread Tools Display Modes

Recommendations for best practice for designing geographically disparateAD

 
 
Robert Gordon
Guest
Posts: n/a

 
      11-03-2007, 05:21 AM
I have one office (50 people) in North America, under a single AD
domain. I am also about to open a second office (30 users) across the
Pacific and the offices will be connected via a LAN-LAN VPN connection.
These offices will each have plenty of Internet bandwidth on both ends
(5 MB+) which are both close to my provider's global backbone.

There will definitely be some potential requirements for being able to
set granular access from each side. I will need to create a DC/DNS/DHCP
and Exchange environment for the remote office, so there can be business
continuity should the VPN connection go down. Obviously the remote
office will be using separate IP subnets from the main North America office.

In this set up, would creating a separate site, under the same AD domain
be the most logical design?
 
Reply With Quote
 
 
 
 
Anthony
Guest
Posts: n/a

 
      11-03-2007, 07:00 AM
Yes. You need a separate Site in AD Sites and Services so that people
connect to their nearest DC. You don't need a separate domain or forest
unless you have incompatible security requirements at the two sites,
Hope that helps,
Anthony, http://www.airdesk.co.uk



"Robert Gordon" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>I have one office (50 people) in North America, under a single AD domain.
>I am also about to open a second office (30 users) across the Pacific and
>the offices will be connected via a LAN-LAN VPN connection. These offices
>will each have plenty of Internet bandwidth on both ends (5 MB+) which are
>both close to my provider's global backbone.
>
> There will definitely be some potential requirements for being able to set
> granular access from each side. I will need to create a DC/DNS/DHCP and
> Exchange environment for the remote office, so there can be business
> continuity should the VPN connection go down. Obviously the remote office
> will be using separate IP subnets from the main North America office.
>
> In this set up, would creating a separate site, under the same AD domain
> be the most logical design?



 
Reply With Quote
 
Ryan Hanisco
Guest
Posts: n/a

 
      11-03-2007, 08:32 AM
Robert,

You shouldn't have any technical problems with the design that you are
proposing. If the country is China or one of the others that has a very
different view of intellectual property than we do, however, I would suggest
that you sequester them into a separate forest and rely on forest trusts
making sure that all documentation and IP is stored off site, preferably in
an encrypted CMS.

Certainly talk to your general counsel and whatever liaison company or
consultants you are using for the security impacts. I understand that this
is a management pain and I am usually an advocate for a single domain or at
least single forest where possible, but if there are any IP concerns, you
must look as a separate forest.

Hope this helps.
--
Ryan Hanisco
MCSE, MCTS: SQL 2005, Project+
http://www.techsterity.com
Chicago, IL

Remember: Marking helpful answers helps everyone find the info they need
quickly.


"Robert Gordon" wrote:

> I have one office (50 people) in North America, under a single AD
> domain. I am also about to open a second office (30 users) across the
> Pacific and the offices will be connected via a LAN-LAN VPN connection.
> These offices will each have plenty of Internet bandwidth on both ends
> (5 MB+) which are both close to my provider's global backbone.
>
> There will definitely be some potential requirements for being able to
> set granular access from each side. I will need to create a DC/DNS/DHCP
> and Exchange environment for the remote office, so there can be business
> continuity should the VPN connection go down. Obviously the remote
> office will be using separate IP subnets from the main North America office.
>
> In this set up, would creating a separate site, under the same AD domain
> be the most logical design?
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Designing a Network nummer31 Home Networking 1 05-25-2011 01:24 PM
Geographically locating incoming emails anupshinde@gmail.com Network Routers 0 09-08-2006 12:25 PM
Designing a TCP/IP server for ARM Abdul Razaq Linux Networking 0 03-24-2006 03:28 AM
Help designing wireless network Thomas Hedden Linux Networking 7 01-09-2006 05:15 PM
End point VPN routers on geographically separate Win2K3 DC controlled networks ch Windows Networking 2 04-23-2004 09:40 PM



1 2 3 4 5 6 7 8 9 10 11