newpersn Posted December 8, 2014 Posted December 8, 2014 Do anyone here with VLANs have a domain controller on each VLAN?
Gardinho Posted December 8, 2014 Posted December 8, 2014 (edited) Why would you do that? You really shouldn't need to. As far as I'm aware you would see no benefit. If your routing is configured correctly on your core switch and you have a couple of DCs replicating correctly you should have all the fault tolerance and high availability you need (depending on the size of your network). Edited December 8, 2014 by Gardinho
newpersn Posted December 8, 2014 Author Posted December 8, 2014 Why would you do that? You really shouldn't need to. As far as I'm aware you would see no benefit. If your routing is configured correctly on your core switch and you have a couple of DCs replicating correctly you should have all the fault tolerance and high availability you need (depending on the size of your network). Just wanted to know. Few years ago we had someone come in and move us away 10.7 range. The company who done it for us, installed a virtual DC on eacher VLAN (Each server doing DNS,DHCP and AD)
Gardinho Posted December 8, 2014 Posted December 8, 2014 Would love to know why they'd do that. I didn't think you'd need to. I may well be wrong though. Have you ditched all the 10.7 addresses? Was it for local address expansion? 1
newpersn Posted December 8, 2014 Author Posted December 8, 2014 Would love to know why they'd do that. I didn't think you'd need to. I may well be wrong though. Have you ditched all the 10.7 addresses? Was it for local address expansion? More security than anything. I'll find the topic about swgfl and there firewall. We have the 10.7 coming in. Meets a Cisco NAT. (Need to check this). All routing is done though this (exchange, rpd and proxy's) I thought it was overkill. But heyho
Gardinho Posted December 8, 2014 Posted December 8, 2014 Were SWGFL involved with this work? Definite overkill! Do you use them for your internet services?
newpersn Posted December 9, 2014 Author Posted December 9, 2014 Were SWGFL involved with this work? Definite overkill! Do you use them for your internet services? Nope. We just use them for our Internet services.
sonofsanta Posted December 9, 2014 Posted December 9, 2014 Heavens no! What a waste of resources and effort :/
localzuk Posted December 9, 2014 Posted December 9, 2014 Seems like a ridiculous idea to me. I can understand the NATing, it does add a division between your network and the SWGfL, but the DCs thing just seems plain odd.
synaesthesia Posted December 9, 2014 Posted December 9, 2014 Wow, never heard that before. Sounds like the work of someone who doesn't actually understand networking, or they've only just finished reading chapter 1 of "Networking for Dummies". 1
psydii Posted December 9, 2014 Posted December 9, 2014 Or someone who wanted to play around with the features of AD Sites and Services, perhaps ahead of bidding for work on a genuine multi site project. Done properly it should cause no harm, provided the next admin in also understands the site and services elements of AD design and management. /optimist 1
synaesthesia Posted December 9, 2014 Posted December 9, 2014 School's ICT systems are not playgrounds though!
mrbios Posted December 9, 2014 Posted December 9, 2014 7 years ago, when i was still quite new to all this we had someone come in and do the exact same thing. This was before virtualisation became a big thing i think, but we ended up having a physical low powered DC in each building (so not every vlan as such, but every physical building) which resulted in us having 5 or 6 physical DCs spread throughout the site. Very similar to what you've got from the sounds of it. Basically as time went on i noticed it being more and more of a waste of space, no idea why it was done like that. Now we just have two DCs and a replication to azure AD, no need for all those others, it was very excessive and overly complicated and a waste of resources. I'm sure the company that did it had their reasons, maybe based off information the manager gave them perhaps, as i still know the people who work there and they aren't by any means stupid. (I'm sure there must be a legitimate reason if two different companies did the same/similar thing for two different schools. I wonder if it was common for that type of setup when you were doing vlans but had no server virtualisation to work with perhaps.) Definitely a position i'd recommend moving away from now though. simplify your setup, free up resources etc. EDIT: Hold on a minute, location gloucestershire, i wonder if it was the same company! One in stonehouse business park per chance? starts with a j?
newpersn Posted December 9, 2014 Author Posted December 9, 2014 7 years ago, when i was still quite new to all this we had someone come in and do the exact same thing. This was before virtualisation became a big thing i think, but we ended up having a physical low powered DC in each building (so not every vlan as such, but every physical building) which resulted in us having 5 or 6 physical DCs spread throughout the site. Very similar to what you've got from the sounds of it. Basically as time went on i noticed it being more and more of a waste of space, no idea why it was done like that. Now we just have two DCs and a replication to azure AD, no need for all those others, it was very excessive and overly complicated and a waste of resources. I'm sure the company that did it had their reasons, maybe based off information the manager gave them perhaps, as i still know the people who work there and they aren't by any means stupid. (I'm sure there must be a legitimate reason if two different companies did the same/similar thing for two different schools. I wonder if it was common for that type of setup when you were doing vlans but had no server virtualisation to work with perhaps.) Definitely a position i'd recommend moving away from now though. simplify your setup, free up resources etc. EDIT: Hold on a minute, location gloucestershire, i wonder if it was the same company! One in stonehouse business park per chance? starts with a j? I wouldn't want to give it away.... I'm just the technician. I think we will be looking at making it better. (all these are on VMWare)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now