Day -3
1
Vijay Bhalerao BCS, MCM, CISA, DCL,MCTS, ISO 27001 LA univijay2001@yahoo.com
Windows Server 2008 Training Day -3 Vijay Bhalerao BCS, MCM, CISA, - - PowerPoint PPT Presentation
Windows Server 2008 Training Day -3 Vijay Bhalerao BCS, MCM, CISA, DCL,MCTS, ISO 27001 LA univijay2001@yahoo.com 1 Windows Server 2008- Day3 Domain Name Service (DNS), DNS zones and DHCP Various Server Roles and Features Operation
1
Vijay Bhalerao BCS, MCM, CISA, DCL,MCTS, ISO 27001 LA univijay2001@yahoo.com
2
Determine the AD DS features available in a domain or forest Restricts which Windows Server operating systems can be
Domain
Supported Domain Controller Operating system Forests Windows 2000 Native Windows Server 2008 Windows Server 2003 Windows 2000 Windows 2000 Windows Server 2003 Windows server 2008 Windows Server 2003 Windows Server 2003 Windows Server 2008 Windows Server 2008 Windows Server 2008
3
Active Directory domain names must use DNS names
The same name space A sub domain of the external
Wood.com Wood.com Pine.Wood.com
5
A domain controller needs to replicate changes
6
Locator initiates a call to Net Logon service
1
Net Logon uses the information and queries DNS
3
Net Logon tests connectivity to target servers
4
Locator collects information about the client
2
5
Net Logon returns the information to clients
6
7
Auranagbad Site Local DNS Server AUR-DC1 SAT-DC1 Satara Site
8
7.
9
Replicates DNS zone information using Active Directory replication
10
Domain Config Schema App1 App2 Domain Config Schema Domain Config Schema App1
11
Domain Config Schema DomainDNSZone ForestDNSZones CustomApp
12
Resource Records DNS Server Windows Server 2008 Windows Vista Windows XP
1 3 4 2 5 1 2 3 4 5
13
Windows DNS Client Domain Controller with Active Directory Integrated DNS Zone Local DNS Server
14
15
DHCP Server DHCP Client
Switch tch
16
DHCP SERVER
17
18
19
Role Description Schema Master
One per forest Performs all updates to the Active Directory schema
Domain Naming Master
One per forest Manages adding and removing all domains and
directory partitions RID Master
One per domain Allocates blocks of RIDs to each domain controller in
the domain PDC Emulator
One per domain Minimizes replication latency for password changes Synchronizes time on all domain controllers in the domain
Infrastructure Master
One per domain Updates object references in its domain that point to the
Schema Master Domain Naming master RID Master PDC Emulator Infrastructure Master Forest wide Domain Wide
User authentication includes a time stamp Replication between domain controllers is time stamped
Windows Time service (W32Time)
Domain controllers PDC Emulator Client computers
22
RODCs host read-only partitions of the Active Directory database, only accept replicated changes to Active Directory, and never initiate replication
Cannot be configured as an operation master or replication
Can be deployed on Windows 2008 core server for additional
If applications must run on a domain controller
RODC
Unidirectional replication
24
– RODC
Before installing an RODC:
Ensure that the domain and forest is at a Windows Server 2003
Ensure a writeable domain controller running Windows Server
Run ADPrep /rodcprep to enable the RODC to replicate DNS
Run ADPrep /domainprep in all domains if the RODC will be a
25
The password replication policy determines how the RODC performs
credential caching for authenticated user
By default, the RODC does not cache any user credentials or computer
credentials No credentials cached
Enable credential caching on an RODC for specified accounts Options for configuring password replication policies: Add users or groups to the Domain RODC Password Allowed group so
credentials are cached on all RODCs
26
A feature supported on Read-Only Domain Controllers
All application partitions containing DNS information are replicated to RODC
DNS information required for Active Directory name resolution is available for
clients in the same site as the RODC Changes are not allowed on the read-only DNS zone, which increases security
27
28
29
30