E
ESM
Hello all, I'm looking for some input on if the way I've structured by
multi-site AD setup is appropriate, or should be tweaked.
My physical network topology is a star with the Corporate office being in
the middle. Corporate office has 2 DC's on the same subnet that replicate
via RPC. The 5 FSMO roles are splut between these 2 DC's.
I have 61 other remote sites currently across the country. 2 of them are
connected via 3 meg and 10 meg metro-ethernet directly. 1 of them is
connected via a T1 point-to-point. These are private connections. All the
other sites are connected via IPSec VPN's over the internet. My Corporate
site has 10mbit internet with only 25% utilization, so plenty of bandwidth.
The remote sites have Cable or DSL connections, with 3 of them having T1's.
All of them have plenty of available upload/download bandwidth for
replication.
In each of those 61 remote sites, I have deployed a DC and made each of them
a GC as well. Primary function of these machines is printer/file sharing.
I've made them DC's because in the event of a VPN Failure, the local DC can
authenticate all requests as necessary and keep the remote site running.
Inter-site replication transports are set from 15 minutes to 90 minutes
depending on the size of the site.
As I add a new office, I add a new DC, and the number grows. This makes
replication across all DC's a very timely process, which is why I'm
wondering if I should revise my thinking. What say you?
multi-site AD setup is appropriate, or should be tweaked.
My physical network topology is a star with the Corporate office being in
the middle. Corporate office has 2 DC's on the same subnet that replicate
via RPC. The 5 FSMO roles are splut between these 2 DC's.
I have 61 other remote sites currently across the country. 2 of them are
connected via 3 meg and 10 meg metro-ethernet directly. 1 of them is
connected via a T1 point-to-point. These are private connections. All the
other sites are connected via IPSec VPN's over the internet. My Corporate
site has 10mbit internet with only 25% utilization, so plenty of bandwidth.
The remote sites have Cable or DSL connections, with 3 of them having T1's.
All of them have plenty of available upload/download bandwidth for
replication.
In each of those 61 remote sites, I have deployed a DC and made each of them
a GC as well. Primary function of these machines is printer/file sharing.
I've made them DC's because in the event of a VPN Failure, the local DC can
authenticate all requests as necessary and keep the remote site running.
Inter-site replication transports are set from 15 minutes to 90 minutes
depending on the size of the site.
As I add a new office, I add a new DC, and the number grows. This makes
replication across all DC's a very timely process, which is why I'm
wondering if I should revise my thinking. What say you?