최고의 답변자
Directing Multiple Vlans to a single Active Directory

질문
-
Hello, i realize there are several post about vlans and active directory but i havent found one that really focuses on what im looking to find.
Currently we have one subnet that our building is on, but we are being told vlan each department out, our current setup handles DHCP through our firewall, and our users are are connecting to our server running server 2003. Each department is configured with security policies on several network drives, including personal "home drives".
Our goal is to create several vlans that can still point back to our Active Directory Server, without having to set individual servers on each vlan.
I will be happy to provide additional information to help clarify any missing information. I appreciate any help in advance.
Eric
2010년 8월 11일 수요일 오전 3:30
답변
-
VLANs are just subnets.Subnets have no bearing on Active Directory. If the LAN is designed corrrectly and the subnets communicate over the LAN's Routing Scheme correctly than that is all that matters. None of that has any bearing on the use of Active Directory.Active Directory just requires you communicate with the correct DNS,...which has nothing to do with subnets.
--
Phillip WindellThe views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
"EMClink" <=?utf-8?B?RU1DbGluaw==?=> wrote in message news:351a77a9-42b1-4781-8b6e-abd8ba91d0bf...So if i create a VLAN strictly for, lets say, our servers and route the traffic to that vlan, itll still maintain our running setup? so to speak :)
thanks for your quick response.
- 답변으로 표시됨 Miles Li 2010년 9월 2일 목요일 오전 9:58
2010년 8월 11일 수요일 오후 2:08 -
Hello,
as long as you configure the routing correct for the other subnets and use the existing DNS as preferred on the NIC it should work also with VLANs. I suggest to configure all used subnets also in AD sites and services.
As it sounds that you are using a single DC, i suggest to install a second one also as DNS/GC for failover and redundancy.
Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.- 답변으로 표시됨 Miles Li 2010년 9월 2일 목요일 오전 9:58
2010년 8월 11일 수요일 오전 7:04 -
You certainly do not need an AD domain controller on each VLAN. As long as computers on each can access the subnet where your DCs are located - and the subnets corresponding to these VLANs are associated with the AD site that this DC is associated with, AD should work as expected. In addition, you should make sure that you allow DHCP traffic to pass between VLANs ...
hth
Marcin- 답변으로 표시됨 Miles Li 2010년 9월 2일 목요일 오전 9:58
2010년 8월 11일 수요일 오후 1:26 -
Hi,
Thank you for your post here.
Yes, Active Directory will work happy across VLANs as long as you have the proper routing between VLAN subnets. If you have domain clients in separate VLANs, you would like to know how to provide DHCP IP address lease with domain specific options for all VLAN clients. You may count on the DHCP relay with multiple DHCP scope for the client.
- 답변으로 표시됨 Miles Li 2010년 9월 2일 목요일 오전 9:58
2010년 8월 12일 목요일 오전 3:01
모든 응답
-
Hello,
as long as you configure the routing correct for the other subnets and use the existing DNS as preferred on the NIC it should work also with VLANs. I suggest to configure all used subnets also in AD sites and services.
As it sounds that you are using a single DC, i suggest to install a second one also as DNS/GC for failover and redundancy.
Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.- 답변으로 표시됨 Miles Li 2010년 9월 2일 목요일 오전 9:58
2010년 8월 11일 수요일 오전 7:04 -
You certainly do not need an AD domain controller on each VLAN. As long as computers on each can access the subnet where your DCs are located - and the subnets corresponding to these VLANs are associated with the AD site that this DC is associated with, AD should work as expected. In addition, you should make sure that you allow DHCP traffic to pass between VLANs ...
hth
Marcin- 답변으로 표시됨 Miles Li 2010년 9월 2일 목요일 오전 9:58
2010년 8월 11일 수요일 오후 1:26 -
VLANs are just subnets.Subnets have no bearing on Active Directory. If the LAN is designed corrrectly and the subnets communicate over the LAN's Routing Scheme correctly than that is all that matters. None of that has any bearing on the use of Active Directory.Active Directory just requires you communicate with the correct DNS,...which has nothing to do with subnets.
--
Phillip WindellThe views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
"EMClink" <=?utf-8?B?RU1DbGluaw==?=> wrote in message news:351a77a9-42b1-4781-8b6e-abd8ba91d0bf...So if i create a VLAN strictly for, lets say, our servers and route the traffic to that vlan, itll still maintain our running setup? so to speak :)
thanks for your quick response.
- 답변으로 표시됨 Miles Li 2010년 9월 2일 목요일 오전 9:58
2010년 8월 11일 수요일 오후 2:08 -
Hi,
Thank you for your post here.
Yes, Active Directory will work happy across VLANs as long as you have the proper routing between VLAN subnets. If you have domain clients in separate VLANs, you would like to know how to provide DHCP IP address lease with domain specific options for all VLAN clients. You may count on the DHCP relay with multiple DHCP scope for the client.
- 답변으로 표시됨 Miles Li 2010년 9월 2일 목요일 오전 9:58
2010년 8월 12일 목요일 오전 3:01 -
Hi Philip, Can you help me understand this concept.
If I have a default vlan 1 192.168.1.1 255.255.255.0
and I want to add vlan 2 for accounting 192.168.2.1 255.255.255.0
My switch automatically separates the 2 subsets so vlan 2 no longer has access to the domain controller which is sitting on vlan 1. As illustrated in the drawing below.
How could vlan 2 access the domain controller which is on vlan 1 in this scenario?
2019년 10월 1일 화요일 오후 11:01