Networking Forums

Networking Forums > Computer Networking > Windows Networking > Single User Standarding Entire Corporation - HELP

Reply
Thread Tools Display Modes

Single User Standarding Entire Corporation - HELP

 
 
Matthew Prieto
Guest
Posts: n/a

 
      01-25-2004, 06:08 AM
Here is what I'm facing. I'll take any suggestions. (It is almost like a
test questions...but with no wrong answer.)

My company (20 users, 1 Domain, Internet Presence) has just been acquired by
another company that doesn't specialize in Computers. They have 5 office
Nationwide all with an Internet Precense (Total users of their company about
50). We are keeping our name and they are keeping theirs so essentially we
have 2 companies running as one.

The CEO visited our site and dedicated me to standarize their entire
operation, from Servers to Applications on all sites. (VERY exiciting) I
have no support from my staff in this manner (not because they don't want to
help but because they don't know enough to help. Most would love to help,
but I would have to teach them what an OU is and how to delegate)

For sure these things are going to occur.
- Each office will have direct Internet access from their site. (So I
figured I would use the Internet to replication all information)
- All Server will be at least Windows 2000 Server and all workstation
Windows 2000 Professional
- I'm going to need to access all servers nationwide from one location
- There will be segmented sites at each location so replication will only
occure after hours.

I understand all the areas of what to do, but becase I am working by myself
I want some feedback on different or better ways to do things.

I'm looking for suggestions on how to structure the Domain (1 Tree or 2) I
was thinking 2 trees under one forest.

1) Where to place the GC? I was thinking 2. One at root of Tree 1and the
other at the root of Tree 2. But placing a DC at each site for
authenication of the users.

2) How to replication AD over the Internet. I was thinking VPN through a
Firewall. I have never had to do this, so how would I setup DNS to forward
replication traffic through the VPN and not through the Public Internet?

Any suggestions or comments or things that I might not have mentioned, are
greatly appreciated. I'm going into this project with just my knowledge and
no support staff so I'm hoping that you can help me.


 
Reply With Quote
 
 
 
 
Ulf B. Simon-Weidner
Guest
Posts: n/a

 
      01-25-2004, 12:32 PM
Hello Matthew,

first of all - please do not crosspost to so many groups. If you send it to the
most approbiate groups it will be read, and set follow-ups to where you want
the discussion. I'll set the follow-up to windows.server.active_directory
because of the DC/GC and DNS-issues.

Now let me answer inline:

Matthew Prieto says...
>
> I'm looking for suggestions on how to structure the Domain (1 Tree or 2) I
> was thinking 2 trees under one forest.
>

As far as I understood you want to keep both domain names, therefore you need
two trees.

> 1) Where to place the GC? I was thinking 2. One at root of Tree 1and the
> other at the root of Tree 2. But placing a DC at each site for
> authenication of the users.
>

Always keep in mind that if you are running native mode you need access to a GC
during logon. In Windows Server 2003 you can use the new universal group
caching feature as well if they are not traveling frequently (chaching per
default keeps the UG-Memberships for the users who already logged on to the
site in this site - if people are traveling frequently and haven't logged on
previously their membership info is not cached).

Depending on the size of both companies there's no valid reason in not making
all servers or most of them a global catalog server, usually size doesn't
matter, and if you are able to use WS2k3 then replication is not a issue as
well. Using W2k you'll have to keep in mind that a change of the schema will
force a full sync of the GC, so extend the schema before deployment.

> 2) How to replication AD over the Internet. I was thinking VPN through a
> Firewall. I have never had to do this, so how would I setup DNS to forward
> replication traffic through the VPN and not through the Public Internet?
>

You need to make sure that DNS is able to resolve all machines in both
companies. Depending on the number of hosts and the OS used you have different
options:
1. W2k+: keep a secondary zone of company1.com in company2.com and vice versa
2. W2k3: use conditional forwarding for the other companys dns
3. W2k3: keep a stub zone of company1.com in company2.com and vice versa
4. W2k3: replicate the AD-Integrated dns-zones of both companies in the
forestdnszones

In each szenario the forwarder of the local DNS-Server is pointing to the DNS-
Server of the local ISP. Which option you use depends on the numbers of DNS-
Entries you'll need. 1 needs some work (configuring the secondaries on every
DNS) and extends the size of the DNS-DB, 2 will use the VPN for every DNS-
Resolution for the other company, 3 is a good solution if you don't want all
records in the other company, 4 will increase the DB-Size. Depending on the
size I'd prefer 4,1,3,2 (first most prefered but biggest size).

For the VPN all companies I know are using Hardware VPN-Routers, but you'll
also be able to configure that using RRAS or ISA.

HTH

Gruesse - Sincerely,

Ulf B. Simon-Weidner
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Single/Multi User Broadband? Barry Higginbottom Broadband 17 02-16-2004 12:13 PM
Router for single-computer user Peter Broadband 2 01-26-2004 08:17 PM
proxy for a single user fabio vassalli Linux Networking 0 01-13-2004 08:32 AM
BT Single User?? Col Broadband 4 12-29-2003 10:22 PM
BT business 500 single user.. run NAT rat Broadband 5 11-21-2003 12:50 PM



1 2 3 4 5 6 7 8 9 10 11