Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

December 11, 2000 12:00 AM

Active Directory Sites

Windows IT Pro
InstantDoc ID #16332
Rating: (0)

Active Directory (AD) sites, which consist of well-connected networks defined by IP subnets that help define the physical structure of your AD, give you much better control over replication traffic and authentication traffic than the control you get with Windows NT 4.0 domains. Because AD relies on IP, all LAN segments should have a defined IP subnet. This makes creating your AD site structure straightforward; you simply group well-connected subnets to form a site.

Creating AD sites benefits you in several ways, the first of which is that creating these sites lets you control replication traffic over WAN links. This control is important in Windows 2000 because any Win2K domain controller (DC) can originate changes to AD. To ensure that a change you make on one DC propagates to all DCs, Win2K uses multimaster replication (instead of the single-master replication that NT 4.0 uses). You might think that multimaster replication would make it difficult to plan for AD replication’s effect on your WAN links, but you can overcome this obstacle using AD sites.

AD employs two types of replication: intra-site replication, which occurs between DCs that are members of the same site, and inter-site replication, which occurs between DCs at different sites. Intra-site replication requires high bandwidth because it’s based on change notification and because it initiates within 5 minutes of any change that occurs to a DC's local copy of the AD. With inter-site replication, bandwidth is limited because it occurs over WAN links. Inter-site replication is usually compressed to conserve bandwidth, and you can schedule it to occur during periods of low network utilization. In an NT 4.0 domain environment, you have to adjust registry parameters to gain such control.

Another important advantage of using sites in your AD design is that the AD site structure ensures that logon traffic doesn’t travel over WAN links to remote DCs. Because the system stores site information in the DNS zone file, a client can locate a DC at its local site when it needs one for authentication purposes. This feature is a great improvement over WINs queries under NT 4.0, which randomly return a list of DCs.

Finally, because Microsoft Dfs is site-aware, it will direct clients to shared folders at their own sites when available. As AD- and site-aware third-party applications emerge, they will be able to take advantage of this functionality as well.

AD sites are crucial for keeping unnecessary traffic out of your WAN links. In an upcoming column, I'll discuss other important issues you need to consider when designing sites, including Global Catalog (GC) server placement.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.