MM&M UG UK

 

The home of the Microsoft Messaging and Mobility

User Group in the UK.

Welcome to MM&M UG UK Sign in | Join | Help
in
Home Blogs Forums Photos Articles Links CESN Downloads Aggregated RSS

A network with only one Domain Controller!

Last post 03-19-2007, 8:37 by nathanwinters. 2 replies.
Sort Posts: Previous Next
  •  03-16-2007, 7:00 1004

    A network with only one Domain Controller!

    Hi,

    I have a client with a network which has the following domains:

    rootdomain.local

    child.rootdomain.local

    differenttree.local

    differentforest.local

     

    Now the most users are in differenttree.local and this domain is distributed with multiple DCs

    The Child.rootdomain.local domain is also distributed and has multiple DCs.

    However, the rootdomain.local has only a SINGLE DC!! So does the differentforest.local domain.

    The differentforest.local domain is about to have Exchange installed as is the rest of the forest.

    Personally, I am very concerned about the lack of multiple DCs in the Forest root and differnetforest domains.

    Specifically, I would be interested to hear your thoughts on this matter including in particular what would happen if the one forest root DC was lost.

    My client insists that they would simply restore the machine from backup and that all would be fine.

    So ideas please....

     

    Thanks

    Nathan

     


    Nathan Winters - MVP Exchange Server
    MCSE & MCSA 2000 & 2003 + Messaging, MCITP Exchange 2007, MCP, VMWare VCP v2 & v3.

    Welcome to the Microsoft Messaging and Mobility User Group: http://www.mmmug.co.uk
  •  03-16-2007, 16:46 1005 in reply to 1004

    Re: A network with only one Domain Controller!

    He may be correct, but I would agree with you that you need a minimum of 2 DC's for redundancy...

    God forbid he has a problem with the DC, and the backup....

    If you lose the forest root DC you can seize the FSMO roles, and as long as you either do a metedata cleanup or never restore  the forest root DC this isn't so much of a problem.

    While the forest root DC is still available, I would transfer the FSMO roles onto different DC's within the forest, so that when or if the server that hosts a FSMO dies only one of the roles is affected.

    I've seen a situation a few times, never been able to correctly identify the cause, where when the FRDC is offline, nobody can log in...

    I would like to see a test where he turns of the FRDC, and proves that it won't affect the other domains, and then I'd leave him to it.

    People, Process, Technology. As long as the IT team know and understand when and how to restore from a backup tape, if this is their DRP plan, then in some respects it's as good as any.

    As regards restoration, the SP level, HAL, (number of CPU's, IDE SATA, SAS or SCI etc) need to be the same or the syste state restore won't work. So the servers in question should be pretty standard.

    I would prefer to see a DRP test if it were my customer, so that we know in the event of a failure exactly what to do and exactly how long it will take to rebuild


    "The isolated knowledge obtained by a group of specialists in a narrow field has in itself no value whatsoever" : Erwin Schrodinger
  •  03-19-2007, 8:37 1008 in reply to 1005

    Re: A network with only one Domain Controller!

    Hi Declan,

    Thanks for the thoughts, that certainly helped in my discussions!

    Cheers

    Nathan


    Nathan Winters - MVP Exchange Server
    MCSE & MCSA 2000 & 2003 + Messaging, MCITP Exchange 2007, MCP, VMWare VCP v2 & v3.

    Welcome to the Microsoft Messaging and Mobility User Group: http://www.mmmug.co.uk
View as RSS news feed in XML
Powered by Community Server, by Telligent Systems