Jump to content

Recommended Posts

Posted

Hi,

 

Just setting up a new 2008 R2 DC and would like to setup a WSUS server.

 

Don't want to install the WSUS role on the DC but don't have another server until summer to install it on.

 

Is it safe to run virtualbox on a DC?

 

Many thanks.

 

Dan

Posted
I'm running Virtual Box on our second domain controller and all is well, it just runs a standard Windows 7 OS with Spiceworks installed for my help desk, make sure when setting up a VM though don't use NAT instead use Bridged, NAT will cause endless amount of issues with your DNS etc...
Posted

Probably not the best idea.

 

Why not setup the new server as a virtual host either running ESXi free or Hyper-V and then have both the DC and the WSUS server virtualised.

Posted
Probably not the best idea.

 

Why not setup the new server as a virtual host either running ESXi free or Hyper-V and then have both the DC and the WSUS server virtualised.

 

Why is it not the best idea? I only ask because I do it and never had any issues? Normally as long as you keep the network bridged and give it it's own IP and MAC Address there isn't a problem or am I missing something?

Posted
I never wear a helmet when I ride my bike, I have never had an issue with it, I don't see what all the fuss is about people saying it's not a good idea to wear helmets, I have never bothered with a helmet for the last three bikes I owned, my grandad never used a bike helmet and he lived until 289... I'm going to ignore everyone else's experiences and never wear a helmet because I have done it and so far everything is hunky dory, in fact I'm so pleased at my lack of non bike helmet wearing incidents I am going to start telling everyone else's it's fine not to wear helmets to.
Posted
I never wear a helmet when I ride my bike, I have never had an issue with it, I don't see what all the fuss is about people saying it's not a good idea to wear helmets, I have never bothered with a helmet for the last three bikes I owned, my grandad never used a bike helmet and he lived until 289... I'm going to ignore everyone else's experiences and never wear a helmet because I have done it and so far everything is hunky dory, in fact I'm so pleased at my lack of non bike helmet wearing incidents I am going to start telling everyone else's it's fine not to wear helmets to.

 

Well I tell you what instead of being a clever :censored: why don't you tell me what is wrong with using Virtual Box on a DC with a bridged connection. If I'm wrong I'd rather be told I am and why this is, so other people including myself can benefit from the new information provided rather than having 12 year olds comment in a stupid and sarcastic fashion such as yourself.

Posted
Why is it not the best idea? I only ask because I do it and never had any issues? Normally as long as you keep the network bridged and give it it's own IP and MAC Address there isn't a problem or am I missing something?

 

I believe the general recommendation from Microsoft is to leave a DC as just that - don't put any additional services on it.

From a day-to-day point of view, I suppose it shouldn't cause any issues, but given that there's the opportunity to do this in a "cleaner" fashion then that would be my recommendation.

Posted
I believe the general recommendation from Microsoft is to leave a DC as just that - don't put any additional services on it.

From a day-to-day point of view, I suppose it shouldn't cause any issues, but given that there's the opportunity to do this in a "cleaner" fashion then that would be my recommendation.

 

Ok thankyou, that makes more sense. Fortunately I haven't had any issues to date yet, I have to do this as I don't have enough servers to be able to run all the services I need. It'd be a quick and temporary fix for him I suppose but I can see why you wouldn't want to do it long term.

When we move to Windows 8/9 I will run our DC as a Virtual Host instead me thinks :)

Posted (edited)

Guys, please keep things civil - we're all working towards the same goals here.

@abillybob I'm sure it wasn't meant in the insulting tone you've taken it in, and @Jasbo Your point is valid, but explaining the possible issues is probably a better move.

 

Back on topic:

 

Your DC is the lifeblood of your domain, usually dealing with authentication, DNS, replication, addressing all at once. and also with more technologies getting AD aware and integrated it's becoming ever more vital.

 

For a long time, the best practice wisdom has to keep DCs as only DCs wherever possible. Previously I've run DCs with secondary tasks/roles and not had any issues, but after some pretty terrible replication issues raising their head recently we're moving totally in the other direction and only running DC roles on them.

 

TL : DR version is - it would probably be fine, but virtualbox attaches directly into the network stack, and your DC is useless without it. The chance for disaster increases in networks with multiple DCs, as any interruption to the synch processes is awful.

 

In this position myself now, I would suggest doing as @pantscat said, and making the physical server a host for multiple VMs.

Make sense?

Edited by Domino
Posted

I tried it, and wasn't very popular when it froze the one-and-only server in the school.

 

I would have thought you were better off just running the WSUS server on your DC rather than run it in a VBox VM on your DC (if I'm reading your question correctly). Being Primary-based, only my schools with newer installations have any virtualization, so everything is run off the DC: WSUS, WDS, VAMT/KMS...

Posted

@Domino

Fair point

@abillybob

 

I have disabled my humour functionality, wasn't dissing..

 

In essence what these guys above have said.

 

Why go against commonly know best practice?

 

Why take the risk?

 

Because your a tech genius or because you don't know better ?

 

There's shelves full of books and websites full of Info about managing Domain controllers, best practice, mitigating risk, planning capacity etc.

 

If I had a job looking after a companies Infrastructure I would consider it my job to go read some of them, then I wouldn't be thinking about doing this In The first place.

 

Hosting a hypervisor app on your dc to host another server is just not a great idea in my book doesn't matter if I can do it or not, I would just consider it a risk I don't need to take down to poor planning, all for what, waiting a bit longer to do it properly?

 

If I had to I would put wsus on a old box as a vm, have it scaled down and move it to the new server on arrival.

Posted (edited)
@Domino

Why go against commonly know best practice?

 

Why take the risk?

 

Because your a tech genius or because you don't know better ?

 

I didn't know it was a risk and neither did the OP so it's not commonly known that was why he was asking and I said I've never had a problem. I may not be a Tech Genius but I do my job well enough and actually have some manners in the way that I talk to others.

 

I don't understand how you could justify your last comment in any other way than taking the :censored: out of myself or the OP, grow up and learn not to be so sarcastic and derogative towards others.

 

Edit: "wasn't dissing"

Edited by abillybob
Posted (edited)

@abillybob you're now being insulting in return. @Jasbo has already said he "wasn't dissing" - and I think you're taking a hypothetical as a personal attack

 

As I said before, keep it civil please. I don't want to lock OPs thread when it's also prompted a useful discussion.

Edited by Domino
Posted (edited)
@abillybob you're now being insulting in return. @Jasbo has already said he "wasn't dissing" - and I think you're taking a hypothetical as a personal attack

 

As I said before, keep it civil please. I don't want to lock OPs thread when it's also prompted a useful discussion.

 

Makes it all ok now right?

 

Fight! Fight! Fight!

 

 

Only Joking! hehe!

@Domino: Your perfectly right.......................you two guys sort it or else we send the boy's round ok! hehe!

 

Pfft @bossman, do you even lift bruh!? ;)

Edited by abillybob
Posted

Cheers guys.

Might just wait until summer then and get esxi on the other server that will be wiped.

 

Have got this server just for the DC. Didn't want any virtual machines but was thinking of temporarily running a wsus server on it.

Will be patient.

Posted

As someone who is currently suffering the after effects of a previous system build which has loaded 4 dc's up with file server, dhcp, dns, print IIS and all sorts of other roles, depending on the size of your site, KISS.

 

Keep It Simple Stupid.

 

Let the DC, DC, make some other servers do the rest of it.

 

Split out the roles as much as practicably possible. We have put server OSs on spare workstations in the past to split off a service that was tying up a DC too much, it's not the best idea, - ESXI and virtualisation is the best idea, but it relieved the DC so it could actually serve up some auth rather than not!

Posted

"I don't understand how you could justify your last comment in any other way than taking the :censored: out of myself or the OP, grow up and learn not to be so sarcastic and derogative towards others."

 

Luckily I do understand, it's called having a joke.

 

I often find making a joke/analogy helps make a point, I don't think you could argue that you didn't get the point.

 

I don't consider it sarcastic but apologies if it came across that way.

 

Perhaps it IS sarcastic, dam perhaps this is why I don't have any friends?

 

No disrespect meant to the OP.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...