mattianuk Posted February 12, 2014 Posted February 12, 2014 Hi Im taking over some primaries, doing new domains etc with new server hardware as they are massively behind (one doesn't even have a domain) I am going down the route of having the physical server just being a PDC and HyperV Host. I do windows server backups of the bare metal states, and so back up the AD that way. However, I am wondering if it is worth virtualising a DC - in the hope that if the physical server was to fail, my VEEAM backups of all VMs, including the BDC VM could be restored to an alternative server with ease and, because the BDC would exist, the entire network could then be brought back up quickly and easily on a plain server OS with no links to the domain?
PotNoodleTech Posted February 12, 2014 Posted February 12, 2014 Yep. I would not join the HyperV host to the domain either - keep it as a standalone (I am not a fan of tying in HyperV or Vmware hosts by joining the domain when virtual machines that are actually running on them are the domain controllers). It's added complexity for no good reason as far as I can see.
djm968 Posted February 12, 2014 Posted February 12, 2014 @AButters beat me to it. This is exactly what I would do.
mattianuk Posted February 12, 2014 Author Posted February 12, 2014 I can understand that logic, but was always told that its best to keep a physical DC, has this changed with 2012? As my main school is a 2008r2 failover cluster, with both the physical hosts being DCs
happierlarry Posted March 12, 2014 Posted March 12, 2014 I can understand that logic, but was always told that its best to keep a physical DC, has this changed with 2012? As my main school is a 2008r2 failover cluster, with both the physical hosts being DCs I heard the same thing too! But recently I had some hardware failed on secondary DC, so decided to virtualise it. All went smoothly and it's been running for a bit now without any problems whatsoever, I can even say it's a bit quicker (definitely the management part)! However not sure I'm ready to risk it and go fully virtual yet.
PotNoodleTech Posted March 12, 2014 Posted March 12, 2014 Haven't had a physical DC here for years. The old wives tales of not virtualising DCs was created by unfortunate people years ago who 1) didn’t realise that you shouldn’t take or restore snapshots on DCs as it can change the time on the virtual machine, thus disconnecting the DC from Active Dir and 2) Didn't realise that if they joined their physical Hosts into the AD they could get into a situation where they may not be able to log in to their hosts if a virtual DC running on that host goes down 3) didn’t realise that if they enabled VMs to automatically sync with the physical host, and the physical host gets out of time for whatever reason they could lose their domain controllers due to time errors as per 1). Keep your physical hosts as standalone machines, don't auto sync the time on the host and VM, and don't use snapshots with wild abandon and you will be able to keep your virtual DCs running like me, for years.
edutech4schools Posted March 13, 2014 Posted March 13, 2014 Keep your physical hosts as standalone machines Sorry to butt in. I look after a small primary and we have one physical 2008r2 DC and another 2008r2 server running the hyper-v role with a second DC as a VM. The physical server that has the hyper-v role is also a member of the domain. I have noticed on this post that that is not a good idea but not a 100% sure why. I can see an issue with the main DC going down and not being able to log in to the second physical DC using a domain account but can you not use a local account?
KK20 Posted February 26, 2018 Posted February 26, 2018 (edited) dont forget that as soon as you use the hyper-v host for anything other than hosting VMs then you might need additional licensing depending on how many VMs you have running. setting the physical host as a DC definitely counts as adding another role. As for your hosts as standalones, it is a good idea to keep them as simple and stupid as possible. Their job is to keep VMs running, not worrying about other things. Backup software is a possible exception (the management of backup software should live elsewhere). Sure if your hosts cant contact the DC then they COULD log in locally. But what are you gaining by having them on the domain in the first place? Edited February 26, 2018 by KK20
PotNoodleTech Posted February 26, 2018 Posted February 26, 2018 dont forget that as soon as you use the hyper-v host for anything other than hosting VMs then you might need additional licensing depending on how many VMs you have running. setting the physical host as a DC definitely counts as adding another role. As for your hosts as standalones, it is a good idea to keep them as simple and stupid as possible. Their job is to keep VMs running, not worrying about other things. Backup software is a possible exception (the management of backup software should live elsewhere). Sure if your hosts cant contact the DC then they COULD log in locally. But what are you gaining by having them on the domain in the first place? 4 year old thread! Congrats! 1
KK20 Posted February 26, 2018 Posted February 26, 2018 (edited) i swear to god it was at the top of the list! No idea how that happened. (shame on me. the shame). edit: i know what must have happened. This will have been a link at the bottom of another thread. apologies. I'm going to hide in the server room all afternoon to avoid being an idiot. Edited February 26, 2018 by KK20 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now