Where do I start with replacing the whole MS AD stack
-
So first, you setup your DHCP up on your non Windows Server device.
Router, pfSense, WTF ever.
But you set it up so that the DNS it hands to the clients is the Windows server.
At that point, DHCP is migrated.
-
@DustinB3403 said in Where do I start with replacing the whole MS AD stack:
Why would you have no internal dns?
We used to only use public external DNS because we didn't have servers at all. When we first got our servers, I didnt really know what DNS was and we ran for while with no internal DNS, but there were lots of issues as you can imagine.
-
@JaredBusch said in Where do I start with replacing the whole MS AD stack:
So first, you setup your DHCP up on your non Windows Server device.
Router, pfSense, WTF ever.
But you set it up so that the DNS it hands to the clients is the Windows server.
At that point, DHCP is migrated.
no, I got that. But simply using windows DNS as a service requires the CAL. I need to run some other DNS server.
-
@Donahue said in Where do I start with replacing the whole MS AD stack:
@JaredBusch said in Where do I start with replacing the whole MS AD stack:
So first, you setup your DHCP up on your non Windows Server device.
Router, pfSense, WTF ever.
But you set it up so that the DNS it hands to the clients is the Windows server.
At that point, DHCP is migrated.
no, I got that. But simply using windows DNS as a service requires the CAL. I need to run some other DNS server.
Centos, Fedora, Ubuntu. .
-
@Donahue said in Where do I start with replacing the whole MS AD stack:
@JaredBusch said in Where do I start with replacing the whole MS AD stack:
So first, you setup your DHCP up on your non Windows Server device.
Router, pfSense, WTF ever.
But you set it up so that the DNS it hands to the clients is the Windows server.
At that point, DHCP is migrated.
no, I got that. But simply using windows DNS as a service requires the CAL. I need to run some other DNS server.
One thing at a time. Changing all the pieces at once is a good way to break your shit, again.
-
@DustinB3403 said in Where do I start with replacing the whole MS AD stack:
Why would you have no internal dns?
LANless? Other than being a cache, often no need for internal DNS.
-
Once your DHCP is all fixed, then you can move on to DNS.
Unless you have a need for a fully managed DNS system with a fuck ton of records, I recommend just using the system that is doing the DHCP. Router, pfSense, WTF ever.
Here is how I do it at a remote site for a client that has IPSEC between their sites.
This is the config in their ER4
10.1.1.4 is the Windows AD server.
So the router looks to that first. The options also tell it to know thatdomain
anddomain.local
are 10.1.1.4 -
@scottalanmiller said in Where do I start with replacing the whole MS AD stack:
@DustinB3403 said in Where do I start with replacing the whole MS AD stack:
Why would you have no internal dns?
LANless? Other than being a cache, often no need for internal DNS.
Unrelated to this discussion.
-
Like @JaredBusch keeps saying, start with DHCP because that's the easiest. When I was moving away from AD, DHCP was the first thing I started with. Just document any DHCP settings like reservation, network booting and so on.
-
Once you setup DNS, you can manually set your DNS On a test workstation to point to the new system and make sure everything works as expected.
Then you update your DHCP to hand out that IP as the DNS.
-
I am in the middle of changing all my DHCP stuff, which is what prompted this whole thing. I want to switch over to reservations for everything, but it got me thinking about CALs, and it all snowballed from there.
-
@Donahue said in Where do I start with replacing the whole MS AD stack:
I am in the middle of changing all my DHCP stuff, which is what prompted this whole thing. I want to switch over to reservations for everything, but it got me thinking about CALs, and it all snowballed from there.
Well first, you don't change anything.
Get it cleaned up and in a known good working state.
-
@JaredBusch said in Where do I start with replacing the whole MS AD stack:
You need to have your DNS use your AD server as it's forwarder, but everything else can look at your DNS.
How will this affect licensing? Do you only need one CAL for that DNS server, since it's the only thing actually talking to the server? Interesting work-around to MS licensing.
-
@JaredBusch said in Where do I start with replacing the whole MS AD stack:
Unless you have a need for a fully managed DNS system with a fuck ton of records, I recommend just using the system that is doing the DHCP. Router, pfSense, WTF ever.
I've got just our 50 or so workstations and then our servers as records. I don't need much.
-
@DustinB3403 said in Where do I start with replacing the whole MS AD stack:
Why would you have no internal dns?
If you don't have AD and don't have internal servers - why do you need internal DNS?
-
@Dashrender said in Where do I start with replacing the whole MS AD stack:
@JaredBusch said in Where do I start with replacing the whole MS AD stack:
You need to have your DNS use your AD server as it's forwarder, but everything else can look at your DNS.
How will this affect licensing? Do you only need one CAL for that DNS server, since it's the only thing actually talking to the server? Interesting work-around to MS licensing.
I believe that MS believes that ANY device that gets info that is passed along using DNS requires a CAL. It doesn't matter who hosts the DHCP, if it is still point to MS DNS.
-
@Dashrender said in Where do I start with replacing the whole MS AD stack:
@DustinB3403 said in Where do I start with replacing the whole MS AD stack:
Why would you have no internal dns?
If you don't have AD and don't have internal servers - why do you need internal DNS?
Nothing in the original post (until a very recent one) stated there were no on-prem servers. Hence the question.
-
@Donahue said in Where do I start with replacing the whole MS AD stack:
@Dashrender said in Where do I start with replacing the whole MS AD stack:
@JaredBusch said in Where do I start with replacing the whole MS AD stack:
You need to have your DNS use your AD server as it's forwarder, but everything else can look at your DNS.
How will this affect licensing? Do you only need one CAL for that DNS server, since it's the only thing actually talking to the server? Interesting work-around to MS licensing.
I believe that MS believes that ANY device that gets info that is passed along using DNS requires a CAL. It doesn't matter who hosts the DHCP, if it is still point to MS DNS.
You'd replace them one at a time and eventually not care about MS Licensing besides for the user workstations.
-
@JaredBusch said in Where do I start with replacing the whole MS AD stack:
@Donahue said in Where do I start with replacing the whole MS AD stack:
I am in the middle of changing all my DHCP stuff, which is what prompted this whole thing. I want to switch over to reservations for everything, but it got me thinking about CALs, and it all snowballed from there.
Well first, you don't change anything.
Get it cleaned up and in a known good working state.
I just redid our scopes yesterday, but I have not yet started migrating over our static IP's to be reservations. I can get everything setup in windows first, and then migrate it over as @black3dynamite said, but that seems like extra steps to me.
-
@Donahue said in Where do I start with replacing the whole MS AD stack:
@JaredBusch said in Where do I start with replacing the whole MS AD stack:
Unless you have a need for a fully managed DNS system with a fuck ton of records, I recommend just using the system that is doing the DHCP. Router, pfSense, WTF ever.
I've got just our 50 or so workstations and then our servers as records. I don't need much.
Why are you worried about CALs at all? You have at least 50 device CALs to cover those 50 devices - just don't allow other devices on that specific network. If you are allowing personal phones/laptops on WiFi - create a separate network for them, that gets DNS and DHCP from the router (most likely at least).