Jump to content

Recommended Posts

Posted

Afternoon,

 

I'm trying to collect some research together to feedback to the LEA (they are busy guys) - so I wonder if anyone can help.

 

We currently authenticate on our network over the LEA broadband network to 4 2012r2 domain controllers which are held centrally at the LEA. It works of course and does the job.

 

Back when it was all 2003r2 schools had an on-site DC which they could authenticate against. Yet it didn't really work. Schools were authenticating against it but occasionally they would send the request back to the centre DCs. This was causing issues. If there was a broadband outage he in-school DCs had to be restarted to that they re-opened their connections.

 

So - we had a massive outage yesterday. Every school in the LEA suffered. The Logicalis link went so nobody could authenticate against the centre DCs. This now raises the question once again of on-site DCs. If we had one in place then authentication could have carried on and the only issue would have been web browsing/email.

 

Does anyone know of a way to use an on-site DC for authentication as the primary contact, but then set some rules to only use the centre DCs should the on-site one be unavailable for some reason. The on-site one would also need to store the GPOs but also replicate centre GPOs etc etc. So they would mirror the LEA DCs but not be the primary authenticators.

 

Is this making sense to anyone?

 

Gareth

Posted

This should really be handled by the subnet in Sites and Services. I wouldn't expect the AD traffic to be going outside of the site if the subnet that device was on is correctly linked to the site with the onsite DC.

 

Sounds like you might have a good case for RODC's to be installed at sites. Making them server core would mean a very small footprint.

  • Thanks 1
Posted
This should really be handled by the subnet in Sites and Services. I wouldn't expect the AD traffic to be going outside of the site if the subnet that device was on is correctly linked to the site with the onsite DC.

 

Sounds like you might have a good case for RODC's to be installed at sites. Making them server core would mean a very small footprint.

 

Okay - that makes sense, so what happens when the desktop machines cannot authenticate against the onsite? We would need them to fall back to the LEA central DCs

 

Gareth

Posted

That should be handled by default. If the local DC is not available that would be the same as a site not having a local DC....It should then go to any other available DC (this won't necessarily be the central ones, but possibly one on another site entirely).

 

You can play around with weighting, but I would not really want to go down that route.

 

I would also make sure the Knowledge Consistency Checker is turned on (if for some reason it had previous been turned off)

  • Thanks 1
Posted
Isn't that just for file caching, not for authentication an DC type stuff.

 

Personally I think a RODC is appropriate, if AD Sites and Services is set up correctly then if the local DC is not contactable it will failover to the remote DCs.

 

Branch office include RODCs

  • Thanks 2
Posted (edited)
Branch office include RODCs

Ugh getting my terminology confused (had BranchCache in my head). But just to be clear, when you say a 'Branch Office install' we aren't talking a separate 'thing' here, essentially we are talking the same thing, a RODC. Right?

Edited by sparkeh
  • Thanks 2
Posted
Ugh getting my terminology confused (had BranchCache in my head). But just to be clear, when you say a 'Branch Office install' we aren't talking a separate 'thing' here, essentially we are talking the same thing, a RODC. Right?

 

Essentially yes.

 

A full implementation of Branch Office gives a whole load of resiliency benefits. Branch Cache and RODC are part of that.

 

If you have a moment, have squizz through that technet article. It's pretty interesting!

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...