Jump to content

Recommended Posts

Posted

I'm planning to move our backup server from $current_remote_location to $other_remote_location_that's_better_suited.

 

As part of that (and a larger planned 2008R2 upgrade) I'm pondering the benefit of adding a lightweight rodc to the mix. I'm aware I'd have to pre-cache passwords and any locked out accounts would stay that way until it spoke to a writeable dc. But it would mean faster appropriate access to anything I can make available from backup.

 

Anyone done/planned this? Is it worth it? It would mostly be a time cost (re-used hardware).

Posted

tbh I would have to ponder that too, there are very few scenarios I can see them be a benefit, high latency offices for example possibly but its not like fibre/lan has any latency and if your dcs have plenty of ram they are all very quick anyway.

I just dont know if you would get a benefit from it unless you remote links are slow.

Posted

@Roberto

RODC as opposed to a writeable one because of the location. It's secure enough for a repo of encrypted backups (Backups are encrypted before being moved to the remote backup server and you can't decrypt them by just possessing the backup server or logins to backup server), but not (IMO) a DC where stuff can be changed.

 

@ZeroHour

The benefit is the DR element. Main school building has burned down / inaccessible / flooded / invaded by fibre-eating hamsters. If I have a remote DC holding a record of everyone's username/passwords/permissions, I can restore a fileserver to a VM, make DHCP available and everyone can magically start logging in on their laptops in said remote building.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...