Block Based replication of Domain Controllers to DR site


i have bring business critical application @ dr site using same hostname , ip address in production site. purpose, plan use block replication software replicate data production servers san @ dr site. dr invocation or testing, planning take snapshot san, create virtual disks , attach them newly created vm's @ dr site.

this application depends on active directory , hence need have domain controller @ dr site. if create new domain controller dr site, in separate ip subnet, have in separate ad site , application servers not able use domain controllers, domain controllers in ad site (which production site). if put domain controller in same ip subnet application servers, same ip subnet has user workstations , hence user authentication requests production site start coming dr site across wan.

in scenario, proposing replicate domain controllers production site dr site, application servers. not sure if block replication of production dc's dr site , when required testing/invocation, can create new vm , attaching virtual hard disks replicated data, bring these vm's domain controllers in dr site or have negative effects ? supported solution ? response highly appreciated. in advance.

you don't want run type of duplicated software clone dc, bad idea.  end lingering objects and/or directory service corruption. 

if want dc's exist in same subnet in quandry.  can start modify srv records dc won't authenticate clients (but have manually change @ dr time).

i have blog talks lag site replication blocks clients ever attempting authenticate dc, should able use same logic.
http://blogs.dirteam.com/blogs/paulbergson/archive/2013/05/14/how-to-build-an-ad-replication-delay-lag-site.aspx

you want create group policy prevents dc in dr site registering records advertise authenticating dc.  if need use dr site, need remove gpo , either reboot dc or run gpupdate , restart netlogon on dc register records clients can use dc.


paul bergson
mvp - directory services
mcitp: enterprise administrator
mcts, mct, mcse, mcsa, security, bs csci
2012, 2008, vista, 2003, 2000 (early achiever), nt4
twitter @pbbergs http://blogs.dirteam.com/blogs/paulbergson
please no e-mails, questions should posted in newsgroup.
posting provided no warranties, , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2