locked
Any Suggestion for AD Sites and Subnets assoication of root domain and sub domain on phyiscal LAN segement RRS feed

  • 問題

  • Dear All,

    I've refered to following URL first
    http://technet.microsoft.com/en-us/magazine/dd797576.aspx
     
    Senarios:
    I have a flat LAN segement IP network is 192.168.0.0/22
    I have AD root domain call KZEROPLUS.INC and sub domain K2MINUS.INC both belongs to same AD forest
    The AD root domain and sub domain are depolyed on flat network 192.168.0.0/22
    The AD root domain have two Domain Controllers with DNS service hold the AD intergretaed zone KZEROPLUS.INC and stub zone for K2MINUS.INC.We name the Domain Controllers HQDC01.KZEROPLUS.INC, HQDC02.KZEROPLUS.INC
    The AD sub domain have one Domain Controller with DNS service hold AD intergrated zone K2MINUS.INC named SUBDC01.K2MINUS.INC
     
     
    HQDC01.KZEROPLUS.INC IP address 192.168.3.181 netmask 255.255.252.0
    HQDC02.KZEROPLUS.INC IP address 192.168.3.182 netmask 255.255.252.0
    SUBDC01.K2MINUS.INC IP address 192.168.3.196 netmask 255.255.252.0
     
    We have no plan to apply any VLANs with subneting on 192.168.0.0/22
    The AD root domain has 400 users, sub domain has 100 users
     
    Question:
    1. Should I place all Domain Controllers of all domains on one AD site?
    2. We will build another sub domain calls AWLTG.INTL on same AD Forest located on remote branch network 192.168.4.0/22, to prevent unnecessary AD replication trafffic; should I create 3 AD sites and each site associate with one particular domain?
    i.e AD SiteA - KZEROPLUS.INC, AD SiteB - K2MINUS.INC, AD SiteC - AWLTG.INTL
    3. What is the better AD site topology for user on KZEROPLUS.INC and K2MINUS.INC?
    4. Can I use the Catch-All Subnet apporach for KZEROPLUS.INC and K2MINUS.INC?
    5. How can I apply two sets of AD site policy for KZEROPLUS.INC and K2MINUS.INC?
     
    Any comment and suggestion is welcome
     
    Thanks!

    Kenny Lee
    2009年5月12日 上午 01:05

解答

  • 1. Yes. You should using a single Site for all domain controllers

    2. You should create another site 192.168.4.9/22 for the subdomain. If the domain in the same network and subnet, it should be fine to have a single Site

    3. Becase they are in the same network, I dont see there have any needs to have second site.

    4. Since your SUBDC and HQDC is on the VLAN 192.168.0.0/22. It already in a catch-all subnet as the domain using 192.168.3.196.

    5. You may not able to assign a site-wise policy to KZEROPLUS.INC and K2MINUS.INC. Since both of the domain are using 192.168.3.0/22 as the network address. If you need to do a site-wise address range, you have to define the DC in either network into another vlan, or just using another range of IP addresses

    2009年5月20日 下午 04:29