MCSE-08-Implementing of an Active Directory Service-09-Theory

Embed Size (px)

Citation preview

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    1/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Implementing Sites To

    Manage

    Active Directory Replication

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    2/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    3/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Introduction to Active Directory Replication

    Replication is the process of updating information in

    Active Directory from one domain controller to other

    domain controller on a network.

    The replication process synchronizes the movement

    of updated information between the domains.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    4/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Replication of Linked Multivalued Attributes

    Replication of linked multivalued attributes depends on the forest

    functional level.

    Forest Functional Level What Happens?

    < Windows Server 2003 Change triggers replication of the entire

    membership list

    = Windows Server 2003 Replication occurs by individual value

    instead of the whole attribtue

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    5/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Directory Partitons

    SCHEMA

    CONFIGURATION

    DOMAIN

    APPLICATION

    Active Directory Database

    FOREST

    DOMAIN

    CONFIGURABLEREPLICATION

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    6/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Directory Partitons

    Schema Partition

    Only one Schema partion exists per forest.

    This partition is stored on all domain controllers in a

    forest.

    It contains definitions of all objects and attributes that

    you can create in the directory.

    Schema information is replicated to all domain

    controllers in the forest.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    7/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Directory Partitons

    Configuration Partition

    Only one configurtion partition per forest.

    Stored on all domain controllers in a forest.

    The configuration partition contains information

    about the forest-wide Active Directory structure.

    Configuration information is replicated to all domaincontrollers in a forest.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    8/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Directory Partitons

    Domain Partition

    Many domain partitions can exit per forest.

    Domain partition are stored on each domain

    controller in a given domain.

    It contains information about all domain-specific

    objects that were created in that domain, including

    users, groups, computers and OU.

    All objects in this partition is stored in Global Catalog

    with only a subset of their attribute.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    9/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Directory Partitons

    Application Partition

    It stores inforamtion about applications in Active

    Directory.

    Unlike a domain partition, this partiton cannot store

    security principal objects, such as user accouts.

    The data in an application is not stored in the gobal

    catalog.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    10/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Replication Topology

    Replication Topology is the route by which

    replication data travels throughout a network.

    Replication occurs between two domain controller.

    To create this topology, Active Directory must

    determine which domain controllers replicate data

    with other domain controllers.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    11/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Global Catalog

    A global catalog server is a domain controller that

    stores two forest-wide partitions.

    It has read/write copy of the partiton from its own

    domain and a partial replica of all domain partition in

    the forest.

    These partial replicas contain a read-only subset of

    the information in each domain partition.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    12/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Global Catalog and Replication of Partition

    When a new domain is added to forest, the

    Configuration partiton stores information about new

    domain.

    Active directory replicates the configuration partion

    to all domain controllers.

    Each global catalog server becomes a partial replica

    of the new domain controller that obtaing replica

    information.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    13/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Sites

    In Active Directory, Sites helps to define the physical

    structure of a network.

    Sites are used to control replication traffic, logon

    traffic, and client computer requests to the gobal

    catalog server.

    It consits of server objects, which contain connection

    objects that enable replication.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    14/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Site Link

    Enables replication traffic between sites.

    Represents the physical connection between sites.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    15/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Default Site Link

    When first domain is created, Active Directory

    creates a default site link named Defaultipsitelink.

    It includes the first site and is located in the IP

    container in Active directory.

    Site link can be renamed.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    16/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    17/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    18/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Site Link Transport Protocols

    A transport protocol is a common language that

    computers share in order to communcate during

    replication.

    Active Directory uses only one protrocol for

    replication within a site.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    19/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    20/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    21/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Site Link Transport Protocols

    Simple Mail Transfer Protocol (SMTP)

    SMTP supports replication of the schema,

    configuration, and global catalog between sites and

    domains.

    This protocol cannot be used for replication of the

    domain partition.

    Configure a certificate authority to sign the SMTPmessages and ensure the authenticity of directory

    updates.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    22/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    23/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    24/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    25/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Creating a Site

    Here right click Site andselect New Site

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    26/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    27/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    28/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    29/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    30/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Creating a Subnet Object

    Right click Subnets

    select new subnet

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    31/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    32/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Creating a Subnet Object

    Subnet will display here

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    33/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Moving a Domain Controller To A Different

    Site

    Select the

    option

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    34/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Moving a Domain Controller To A Different

    Site

    Right click theDomain Controller

    and select Move

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    35/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    36/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Moving a Domain Controller To A Different

    Site

    The DC is

    Moved here

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    37/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    38/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    39/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    40/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    41/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    42/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    43/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Delegating Control Of Sites

    Click Next

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    44/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    45/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    46/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    47/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    48/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Intersite Topology Generator

    Functions:

    It automatically selects one or more domain

    controllers to become bridgehead servers.

    If a bridgehead server becomes unavailable, it

    automatically selects another bridgehead server.

    It runs Knowledge Consistency Checker(KCC) to

    determine the replication topology and resultant

    connection objects to communicate with other sites.

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    49/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Creating a Preferred Bridgehead Server

    Click this

    option

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    50/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    51/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    52/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Creating a Preferred Bridgehead Server

    Click OK

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    53/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    54/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    55/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    56/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    57/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Forcing KCC to run

    Click OK

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    58/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Common Replication Problems

    SYMPTOM POSSIBLE CAUSES

    Replication does not finish or * Sites not connected by site links

    occur * No bridgehead server in the site

    Replication is slow * Inefficient site topology and schedule

    Client computers receive a * No domain controller online in client site

    slow response * Not enough domain controllers

    Replication greatly increases * Insufficient bandwidth

    network traffic * Incorrect site topology

    The KCC cannot complete the * Exception in the KCCtopology

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    59/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    60/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Configure Replication Monitor

    Type the command

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    61/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    62/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    63/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Configure Replication Monitor

    Right click the monitor

    server and select ADD

    MONITOR SERVER

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    64/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Configure Replication Monitor

    Mention the

    server name

    Click Next

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    65/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    66/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    67/70

    ADVANTAGE PRO Chennais Premier Networking Training Center

    Dcdiag Tool

    Analyze the state of a domain controller and reportany problems

    Perform a series of tests to verify different areas of

    the system

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    68/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    69/70

  • 8/6/2019 MCSE-08-Implementing of an Active Directory Service-09-Theory

    70/70

    Dcdiag Tool