gshaw Posted May 28, 2014 Posted May 28, 2014 I bet this one will stir up some opinions We're putting in a brand new AD infrastructure that'll sit across 5 sites and service ~3000 workstations (as well as Office 365 etc.) We're at the design stage at the moment so out come the standard ideas: 2 DCs minimum at the primary site minimum 1 DC for each branch site (connected via leased line) ADFS to be set up for SSO to Office 365 + DMZ ADFS proxy x2 Now here's the question, everything else we run is on VMWare (with replicated SANs) but a part of me says that keeping a physical DC is a sensible idea just in case of a very worst case scenario. Looking elsewhere on t'Internet for opinions leans more to the all virtual model. Your thoughts?
6Foot2 Posted May 28, 2014 Posted May 28, 2014 Our servers were virtualised last year by our LEA. They created one physical and one virtual DC [We are a single site school]
Jasbo Posted May 28, 2014 Posted May 28, 2014 I had two virtual dcs on a 3 node cluster / San, after a firmware incident that caused issues to my San resulting in randomly disconnecting vms I now have a 3rd physical dc. I know that since 2012 it's not necessarily required, but I do lots of things that are not necessarily required, my argument is why not. Does it add that much overhead in costs/management? Now my worst case San/hypervisor cluster f scenario for users is them logging on, getting a few popup errors to okay and having access to cloud email / storage from their account while we panic behind the scenes, previously the worse case cluster f scenario was 1200 people twiddling their thumbs for a day while I fixed the problem.
Oaktech Posted May 28, 2014 Posted May 28, 2014 I've always bee told that best practice is to have at least 1 physical DC...
gshaw Posted May 28, 2014 Author Posted May 28, 2014 Sounds like my kind of thinking, for the sake of one server gives a lot more peace of mind 1
Sam_Brown Posted May 29, 2014 Posted May 29, 2014 Seconded on having one Physical Server for disaster recovery scenarios. Also if you use a server as an NTP server it's best that's physical as well as the clock drift is worse on VMs and isn't as accurate.
Fazza Posted May 29, 2014 Posted May 29, 2014 We've got at least one physical DC on each site along with at least one virtual.
Sam_Brown Posted May 29, 2014 Posted May 29, 2014 Do people recommend keeping the fsmo roles on the physical or the virtual? I'm assuming the physical...
tmcd35 Posted May 29, 2014 Posted May 29, 2014 I have physical with Hyper-V because of the host servers reliance on AD. You don't have that problem with VMWare. I'd have them all virtual personally. The only thing to remember with virtual DC's is not to snapshot or backup the VDMX. Backup the domain controllers system state as normal, just like a physical DC.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now