Windows Server 2008 Domain setup advice

stroebs

Expert Member
Joined
Jan 15, 2009
Messages
2,109
Reaction score
41
Location
Cape Town
Hi forumites,

Recently our biggest client experienced a power outage in their office building which shut down both of their sites - JHB and CPT, because all of the file servers, domain controllers and the VoIP box are in CPT. I need to remedy this fairly urgently because without CPT, JHB cannot do anything. Their laptops don't have DHCP, they can't authenticate to the network, can't make phone calls, can't access files etc.

I would like to hear from someone who may have setup something similar to this and maybe get some advice on how to implement this in a live system.

Here's some background:

There are two sites - one in JHB and one in CPT. They are each connected to the internet via a 4Mbps Neotel line, with the CPT office currently running the main file server for both sites - ZASRV001. There's also ZASRV002 (JHB), ZASRV003 (CPT), ZAADS001 (CPT), ZAADS002 (CPT) and (ZAVOIP001). The sites are currently connected via a VPN, and all JHB users access services on CPT servers.

What I'm planning on doing:
- Adding ZASRV004 to the loop as the JHB main file server with DFS (is DFS a good idea?), for data redundancy.
- Adding ZAVOIP002 to the loop, somehow making sure that I am able to split Neotel channels between the two sites (Have yet to figure this one out).
- Adding ZAADS003 to the loop, as a backup domain controller for JHB if CPT goes down again.

My main question is that of DFS. Has anyone had any good experience with DFS? I've Google'd around and found tons of articles on DFS, but wanted to hear from someone who may have actually implemented it in a scenario similar to mine. I am terrified of losing client data while implementing DFS, as I need to get all of the data over to ZASRV004 while it's still in CPT, then fly it up to JHB, and hope it works fine.

One of the things I've also noticed about DFS is that there are different sites - ZASITE01. Both of these servers are currently on the same site. Would I be able to change that once the server is in CPT? Or would DFS detect a different IP range and automagically change it to ZASITE02?
 
First i'd like to ask a question, why did'nt you have dhcp and a dc in joburg in the first place?

Regarding DFS, I've used it, but not for huge amounts of data.
Remember, DC's use it to replicate sysvol etc.... so it does work nicely.
Are you planning to create a new AD site for joburg? Or make the new DC part of the capetown site?
 
If you have a slow physical link between the sites, and have your new DC joined to the same AD site, you might have traffic problems, cause the DC's will think they on a local lan together.
Always create AD sites based on physical sites.
 
It's a two year+ old setup, and I only joined the company a year ago, so maybe there's some questions to be asked about the setup. This also might be why I'm involved in fixing it.

The very first thing I noticed about DFS is the sysvol replication. There's a few things I see DFS can do such as schedules, bandwidth limiting etc. which will be fun to play around with to see what works.

I will make sure to differentiate the sites when the third domain controller is added.
 
I don't think your challenge is too big, more optimizing it.
And don't forget, you still need to backup the data, a deleted file will be removed from the dfs share on the other side.
Oh, one more thing, you will need to use another ip range in johannesburg if you using a new AD site, an ip range cannot belong to 2 Ad sites.
Good Luck.
 
I've worked with DFS and it can be really tricky to implement and support of you don't have experience on it. We always try and avoid DFS unless there is a specific business case for it.
 
@Hendrix:

Thanks for that. I see that DFS offers a deleted cache of variable size. That will definitely come in handy. I don't think there's an issue with file deletion, more that we need site redundancy. There is currently off-site backup in place as well as tape backup for real emergencies. We do currently have a separate IP range up in JHB, so no problem there.

I've been delaying the implementation of DFS for weeks now, hoping to complete it sometime this week.
 
Top
Sign up to the MyBroadband newsletter
X