ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    AD best practices

    IT Discussion
    11
    49
    4.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender @wirestyle22
      last edited by

      @wirestyle22 said in AD best practices:

      @jfath said in AD best practices:

      I do plan to use a second physical machine with another Win Server VM as the secondary DC. I understand AD well enough to know why it's important to have two if you're going to have one.

      I'd be much more concerned with hardware failing than I would be the VM

      So much so in a SMB (50 users) that you'd spend money on a second server with maintenance, etc, etc?

      wirestyle22W 1 Reply Last reply Reply Quote 0
      • wirestyle22W
        wirestyle22 @Dashrender
        last edited by

        @dashrender said in AD best practices:

        @wirestyle22 said in AD best practices:

        @jfath said in AD best practices:

        I do plan to use a second physical machine with another Win Server VM as the secondary DC. I understand AD well enough to know why it's important to have two if you're going to have one.

        I'd be much more concerned with hardware failing than I would be the VM

        So much so in a SMB (50 users) that you'd spend money on a second server with maintenance, etc, etc?

        I mean the reasoning behind having two DC's is for redundancy but if it's only provides that to the VM and not the hardware it isn't that useful. Might as well remove the issues that can occur with replication at that point and just take server backups.

        1 Reply Last reply Reply Quote 0
        • M
          marcinozga
          last edited by

          I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

          wirestyle22W 1 Reply Last reply Reply Quote 0
          • wirestyle22W
            wirestyle22 @marcinozga
            last edited by wirestyle22

            @marcinozga said in AD best practices:

            I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

            When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

            M 1 Reply Last reply Reply Quote 0
            • M
              marcinozga @wirestyle22
              last edited by

              @wirestyle22 said in AD best practices:

              @marcinozga said in AD best practices:

              I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

              When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

              I guess you missed the part when I said restoring DC from backups didn't do any good.

              wirestyle22W JaredBuschJ 2 Replies Last reply Reply Quote 0
              • wirestyle22W
                wirestyle22 @marcinozga
                last edited by wirestyle22

                @marcinozga said in AD best practices:

                @wirestyle22 said in AD best practices:

                @marcinozga said in AD best practices:

                I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

                When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

                I guess you missed the part when I said restoring DC from backups didn't do any good.

                That is not the scenario I'm talking about. You had a second DC. That complicates the backup/recovery process.

                JaredBuschJ 1 Reply Last reply Reply Quote 0
                • JaredBuschJ
                  JaredBusch @wirestyle22
                  last edited by

                  @wirestyle22 said in AD best practices:

                  @marcinozga said in AD best practices:

                  @wirestyle22 said in AD best practices:

                  @marcinozga said in AD best practices:

                  I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

                  When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

                  I guess you missed the part when I said restoring DC from backups didn't do any good.

                  That is not the scenario I'm talking about. You had a second DC. That complicates the backup process.

                  No it does not.

                  wirestyle22W 1 Reply Last reply Reply Quote 1
                  • wirestyle22W
                    wirestyle22 @JaredBusch
                    last edited by wirestyle22

                    @jaredbusch said in AD best practices:

                    @wirestyle22 said in AD best practices:

                    @marcinozga said in AD best practices:

                    @wirestyle22 said in AD best practices:

                    @marcinozga said in AD best practices:

                    I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

                    When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

                    I guess you missed the part when I said restoring DC from backups didn't do any good.

                    That is not the scenario I'm talking about. You had a second DC. That complicates the backup process.

                    No it does not.

                    A live database being replicated doesn't create time disparities that could potentially not resolve correctly?

                    M coliverC 2 Replies Last reply Reply Quote 0
                    • JaredBuschJ
                      JaredBusch @marcinozga
                      last edited by

                      @marcinozga said in AD best practices:

                      @wirestyle22 said in AD best practices:

                      @marcinozga said in AD best practices:

                      I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

                      When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

                      I guess you missed the part when I said restoring DC from backups didn't do any good.

                      Your problem here was failure to test backups. there is no reason to have this occur had you tested your backups.

                      1 Reply Last reply Reply Quote 1
                      • M
                        marcinozga @wirestyle22
                        last edited by

                        @wirestyle22 said in AD best practices:

                        @jaredbusch said in AD best practices:

                        @wirestyle22 said in AD best practices:

                        @marcinozga said in AD best practices:

                        @wirestyle22 said in AD best practices:

                        @marcinozga said in AD best practices:

                        I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

                        When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

                        I guess you missed the part when I said restoring DC from backups didn't do any good.

                        That is not the scenario I'm talking about. You had a second DC. That complicates the backup process.

                        No it does not.

                        A live database being replicated doesn't create time disparities that could potentially not resolve correctly?

                        That's not the scenario I described. Windows didn't even boot to that point to worry about AD database consistency.

                        wirestyle22W coliverC 2 Replies Last reply Reply Quote 0
                        • wirestyle22W
                          wirestyle22 @marcinozga
                          last edited by wirestyle22

                          @marcinozga said in AD best practices:

                          @wirestyle22 said in AD best practices:

                          @jaredbusch said in AD best practices:

                          @wirestyle22 said in AD best practices:

                          @marcinozga said in AD best practices:

                          @wirestyle22 said in AD best practices:

                          @marcinozga said in AD best practices:

                          I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

                          When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

                          I guess you missed the part when I said restoring DC from backups didn't do any good.

                          That is not the scenario I'm talking about. You had a second DC. That complicates the backup process.

                          No it does not.

                          A live database being replicated doesn't create time disparities that could potentially not resolve correctly?

                          That's not the scenario I described. Windows didn't even boot to that point to worry about AD database consistency.

                          I said that having a second dc can complicate the backup/recovery process (which I really meant to say recovery). Jared said no. I then replied to Jared saying no, not to your post.

                          JaredBuschJ 1 Reply Last reply Reply Quote 0
                          • coliverC
                            coliver @Dashrender
                            last edited by coliver

                            @dashrender said in AD best practices:

                            @wirestyle22 said in AD best practices:

                            @dashrender said in AD best practices:

                            @marcinozga said in AD best practices:

                            If your clients pull IP from Windows DHCP, they can register DNS records in Windows DNS servers automatically. If you move DHCP to another non-windows server or device, you will lose that ability. If it ain't broke, don't fix it.

                            I was pretty sure this wasn't entirely accurate.

                            https://lani78.com/2012/07/23/make-your-dhcp-server-dynamically-update-your-dns-records-on-ubuntu-12-04-precise-pangolin/

                            Linux based DHCP can update DNS - just maybe not Windows DNS, not sure.

                            You can setup Samba AD. I'd imagine you can do DNS as well

                            We're specifically talking about DHCP dynamically updating DNS as DHCP hands out IPs.

                            Why is this important? I get why it could be a good thing but not sure if it's a must have feature for a non-profit/SMB.

                            1 Reply Last reply Reply Quote 0
                            • JaredBuschJ
                              JaredBusch @wirestyle22
                              last edited by

                              @wirestyle22 said in AD best practices:

                              @marcinozga said in AD best practices:

                              @wirestyle22 said in AD best practices:

                              @jaredbusch said in AD best practices:

                              @wirestyle22 said in AD best practices:

                              @marcinozga said in AD best practices:

                              @wirestyle22 said in AD best practices:

                              @marcinozga said in AD best practices:

                              I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

                              When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

                              I guess you missed the part when I said restoring DC from backups didn't do any good.

                              That is not the scenario I'm talking about. You had a second DC. That complicates the backup process.

                              No it does not.

                              A live database being replicated doesn't create time disparities that could potentially not resolve correctly?

                              That's not the scenario I described. Windows didn't even boot to that point to worry about AD database consistency.

                              I said that having a second dc can complicate the backup/recovery process (which I really meant to say recovery). Jared said no. I then replied to Jared saying no, not to your post.

                              Not it does not. Because you simply do not recover one of them in a failure scenario. then there is no inconsistency to deal with.

                              1 Reply Last reply Reply Quote 1
                              • coliverC
                                coliver @marcinozga
                                last edited by

                                @marcinozga said in AD best practices:

                                @wirestyle22 said in AD best practices:

                                @jaredbusch said in AD best practices:

                                @wirestyle22 said in AD best practices:

                                @marcinozga said in AD best practices:

                                @wirestyle22 said in AD best practices:

                                @marcinozga said in AD best practices:

                                I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

                                When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

                                I guess you missed the part when I said restoring DC from backups didn't do any good.

                                That is not the scenario I'm talking about. You had a second DC. That complicates the backup process.

                                No it does not.

                                A live database being replicated doesn't create time disparities that could potentially not resolve correctly?

                                That's not the scenario I described. Windows didn't even boot to that point to worry about AD database consistency.

                                AD should be backed up by itself not as part of the OS. There are tools (and even powershell scripts) that can make this extremely easy.

                                JaredBuschJ 1 Reply Last reply Reply Quote 0
                                • coliverC
                                  coliver @wirestyle22
                                  last edited by coliver

                                  @wirestyle22 said in AD best practices:

                                  @jaredbusch said in AD best practices:

                                  @wirestyle22 said in AD best practices:

                                  @marcinozga said in AD best practices:

                                  @wirestyle22 said in AD best practices:

                                  @marcinozga said in AD best practices:

                                  I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

                                  When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

                                  I guess you missed the part when I said restoring DC from backups didn't do any good.

                                  That is not the scenario I'm talking about. You had a second DC. That complicates the backup process.

                                  No it does not.

                                  A live database being replicated doesn't create time disparities that could potentially not resolve correctly?

                                  You don't recover AD like you think you recover it. When recovering in a cluster like this bring up an entirely new AD server and promote it to DC. It will pull all of the data from the other domain controller. Remove the other one from AD (forcibly if necessary) and you're good.

                                  1 Reply Last reply Reply Quote 2
                                  • JaredBuschJ
                                    JaredBusch @coliver
                                    last edited by

                                    @coliver said in AD best practices:

                                    @marcinozga said in AD best practices:

                                    @wirestyle22 said in AD best practices:

                                    @jaredbusch said in AD best practices:

                                    @wirestyle22 said in AD best practices:

                                    @marcinozga said in AD best practices:

                                    @wirestyle22 said in AD best practices:

                                    @marcinozga said in AD best practices:

                                    I had a situation once where having 2 DCs on one host saved my ass. For unknown reason DC died, when booting it stopped at black screen without any messages, I couldn't enter safe mode either. Restoring VM from backups yielded the same result, booting to black screen, even going back as far as 2 months. Having 2nd DC allowed me to seize FSMO roles, delete failing DC, and promote another one. So having 2 even on one host, is not unreasonable.

                                    When having a single DC you could just recover via backups. I think the assumption here is that you will have downtime, but that is only if your DNS server is your DC, which it doesn't have to be. Users wouldn't notice anything if they could resolve hostnames. They login with their cached credentials and everything seems normal. The backup takes a few hours (DC's aren't big).

                                    I guess you missed the part when I said restoring DC from backups didn't do any good.

                                    That is not the scenario I'm talking about. You had a second DC. That complicates the backup process.

                                    No it does not.

                                    A live database being replicated doesn't create time disparities that could potentially not resolve correctly?

                                    That's not the scenario I described. Windows didn't even boot to that point to worry about AD database consistency.

                                    AD should be backed up by itself not as part of the OS. There are tools (and even powershell scripts) that can make this extremely easy.

                                    In a total fialure scenario, you just recover the entire server. Done.
                                    In a single server scenario, you agian, jsut recover the entire server done.

                                    No reason to deal with any other tool for AD.

                                    1 Reply Last reply Reply Quote 3
                                    • jfathJ
                                      jfath @Dashrender
                                      last edited by

                                      @dashrender said in AD best practices:

                                      Well, this would be a reason for the non-profit to fire their paid consultants. The non-profit isn't looking for the best solution, instead they are keeping some consultants in cash for no reason.
                                      I'm pretty sure @scottalanmiller would call this corruption.

                                      Fear, not corruption. They are weaning themselves from old consulting firm, but worry that I (as an unpaid volunteer) will not always be available. They want to be left with a network that can be maintained by available resources.

                                      My second DC will be at a second location connected by the 50 mb internet location. Both sites will have local authentication and the link is plenty to handle replication given the relatively small number of users.

                                      The new servers are Dell T30s at $329 each. A 2 core Server 2016 pack costs $8 (16 required) and a CAL is $3. Fairly cost effective and they stay in their comfort zone.

                                      I appreciate all of the feedback, especially regarding splitting DHCP and FS. I'm still unsure as to whether it's bad practice to run the FS on the same instance of Windows server as DC/DNS. I have a vague memory of reading that somewhere, but that's the way the former consultants set up the current server.

                                      The MS license allows two VMs, so I can split the roles if it's needed and best to stay all MS, or offload FS and DHCP to linux. My take on the feedback so far (given that I'm definitely going with two physical servers running MS Server) is that offloading FS and DHCP roles is possible, but may create additional headaches and lose some degree of functionality.

                                      DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
                                      • DashrenderD
                                        Dashrender @jfath
                                        last edited by

                                        @jfath said in AD best practices:

                                        @dashrender said in AD best practices:

                                        Well, this would be a reason for the non-profit to fire their paid consultants. The non-profit isn't looking for the best solution, instead they are keeping some consultants in cash for no reason.
                                        I'm pretty sure @scottalanmiller would call this corruption.

                                        Fear, not corruption. They are weaning themselves from old consulting firm, but worry that I (as an unpaid volunteer) will not always be available. They want to be left with a network that can be maintained by available resources.

                                        My second DC will be at a second location connected by the 50 mb internet location. Both sites will have local authentication and the link is plenty to handle replication given the relatively small number of users.

                                        The new servers are Dell T30s at $329 each. A 2 core Server 2016 pack costs $8 (16 required) and a CAL is $3. Fairly cost effective and they stay in their comfort zone.

                                        I appreciate all of the feedback, especially regarding splitting DHCP and FS. I'm still unsure as to whether it's bad practice to run the FS on the same instance of Windows server as DC/DNS. I have a vague memory of reading that somewhere, but that's the way the former consultants set up the current server.

                                        The MS license allows two VMs, so I can split the roles if it's needed and best to stay all MS, or offload FS and DHCP to linux. My take on the feedback so far (given that I'm definitely going with two physical servers running MS Server) is that offloading FS and DHCP roles is possible, but may create additional headaches and lose some degree of functionality.

                                        Where do I get Dell servers for $329?
                                        OK these are basically desktop PCs being called servers. No redundant powersupplies, what's the RAID option? is it real RAID or fakeRAID?

                                        What are you replicating to the remote location? Just the AD authentication stuff?

                                        jfathJ 1 Reply Last reply Reply Quote 0
                                        • jfathJ
                                          jfath @Dashrender
                                          last edited by

                                          @dashrender Yep, T30 are the low end Dell servers. ECC and single Xeon E3-1225, but no redundant PS. I'll throw in an LSI HW raid controller before deployment. And the $329 price was a one day sale. Just AD replication between sites.

                                          DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @jfath
                                            last edited by

                                            @jfath said in AD best practices:

                                            @dashrender Yep, T30 are the low end Dell servers. ECC and single Xeon E3-1225, but no redundant PS. I'll throw in an LSI HW raid controller before deployment. And the $329 price was a one day sale. Just AD replication between sites.

                                            Even if the remote side is free to host on, it doesn't seem worth the $329 spent, plus the RAID card and I'm assuming drives are still needed.

                                            Make good backups, test the backups and go. One DC, One server should be all that's needed.

                                            jfathJ 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 2 / 3
                                            • First post
                                              Last post