Jump to content

Recommended Posts

Posted

Hi

 

Im taking over some primaries, doing new domains etc with new server hardware as they are massively behind (one doesn't even have a domain)

 

I am going down the route of having the physical server just being a PDC and HyperV Host. I do windows server backups of the bare metal states, and so back up the AD that way.

 

However, I am wondering if it is worth virtualising a DC - in the hope that if the physical server was to fail, my VEEAM backups of all VMs, including the BDC VM could be restored to an alternative server with ease and, because the BDC would exist, the entire network could then be brought back up quickly and easily on a plain server OS with no links to the domain?

Posted
Yep. I would not join the HyperV host to the domain either - keep it as a standalone (I am not a fan of tying in HyperV or Vmware hosts by joining the domain when virtual machines that are actually running on them are the domain controllers). It's added complexity for no good reason as far as I can see.
Posted
I can understand that logic, but was always told that its best to keep a physical DC, has this changed with 2012? As my main school is a 2008r2 failover cluster, with both the physical hosts being DCs
  • 4 weeks later...
Posted
I can understand that logic, but was always told that its best to keep a physical DC, has this changed with 2012? As my main school is a 2008r2 failover cluster, with both the physical hosts being DCs

I heard the same thing too! But recently I had some hardware failed on secondary DC, so decided to virtualise it. All went smoothly and it's been running for a bit now without any problems whatsoever, I can even say it's a bit quicker (definitely the management part)! However not sure I'm ready to risk it and go fully virtual yet.

Posted

Haven't had a physical DC here for years. The old wives tales of not virtualising DCs was created by unfortunate people years ago who 1) didn’t realise that you shouldn’t take or restore snapshots on DCs as it can change the time on the virtual machine, thus disconnecting the DC from Active Dir and 2) Didn't realise that if they joined their physical Hosts into the AD they could get into a situation where they may not be able to log in to their hosts if a virtual DC running on that host goes down 3) didn’t realise that if they enabled VMs to automatically sync with the physical host, and the physical host gets out of time for whatever reason they could lose their domain controllers due to time errors as per 1).

 

Keep your physical hosts as standalone machines, don't auto sync the time on the host and VM, and don't use snapshots with wild abandon and you will be able to keep your virtual DCs running like me, for years.

Posted
Keep your physical hosts as standalone machines

 

Sorry to butt in. I look after a small primary and we have one physical 2008r2 DC and another 2008r2 server running the hyper-v role with a second DC as a VM. The physical server that has the hyper-v role is also a member of the domain. I have noticed on this post that that is not a good idea but not a 100% sure why. I can see an issue with the main DC going down and not being able to log in to the second physical DC using a domain account but can you not use a local account?

  • 3 years later...
Posted (edited)

dont forget that as soon as you use the hyper-v host for anything other than hosting VMs then you might need additional licensing depending on how many VMs you have running. setting the physical host as a DC definitely counts as adding another role.

 

As for your hosts as standalones, it is a good idea to keep them as simple and stupid as possible. Their job is to keep VMs running, not worrying about other things. Backup software is a possible exception (the management of backup software should live elsewhere). Sure if your hosts cant contact the DC then they COULD log in locally. But what are you gaining by having them on the domain in the first place?

Edited by KK20
Posted
dont forget that as soon as you use the hyper-v host for anything other than hosting VMs then you might need additional licensing depending on how many VMs you have running. setting the physical host as a DC definitely counts as adding another role.

 

As for your hosts as standalones, it is a good idea to keep them as simple and stupid as possible. Their job is to keep VMs running, not worrying about other things. Backup software is a possible exception (the management of backup software should live elsewhere). Sure if your hosts cant contact the DC then they COULD log in locally. But what are you gaining by having them on the domain in the first place?

 

4 year old thread! Congrats! :D

  • Thanks 1
Posted (edited)

i swear to god it was at the top of the list! No idea how that happened. (shame on me. the shame).

 

edit: i know what must have happened. This will have been a link at the bottom of another thread. apologies. I'm going to hide in the server room all afternoon to avoid being an idiot.

Edited by KK20
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...