• No results found

Network System Management. Creating an Active Directory Domain

N/A
N/A
Protected

Academic year: 2021

Share "Network System Management. Creating an Active Directory Domain"

Copied!
39
0
0

Loading.... (view fulltext now)

Full text

(1)

Network System Management

Creating an

(2)

Objectives

Identify the procedures involved in the promotion of a

“stand-alone” Windows Server to an active directory

services (ADS) domain controller (DC)

Planning

Environment

Preliminary steps

Best practices

(3)

Planning

Is this the first domain controller?

What is the existing network environment?

Is this an Intranet, Extranet, or part of your DMZ?

Intranet = Internet based technologies used within

your LAN. Ex: A web server only available within your

offices

Extranet = Private, restricted web page only available

to your business partners

(4)

Planning

DMZ = demilitarized zone

(5)

DMZ = demilitarized zone

Planning

(6)

DMZ = demilitarized zone

Planning

(7)

Preliminary Steps

Install the operating system

Install the necessary service packs and updates

-

Not required in the classroom

Install and connect all hardware devices and

(8)

Preliminary Steps (cont.)

Connect to your network and configure the TCP/IP

protocol

Dynamic or Static IP?

(9)

Active Directory Concepts

What is an AD DS Domain

Logically structured organization of objects

-

Network environment

-

Share common directory services database

Has unique name

Organized in levels

Administered as a unit with common rules and

procedures

(10)

Active Directory Concepts (cont.)

(11)

Active Directory Concepts (cont.)

AD Domain Trees and Forests

Tree

-

Hierarchical collection of domains

-

Share contiguous DNS namespace

Forest

-

Collection of trees

(12)

Active Directory Concepts (cont.)

AD Domain Trees and Forests

Reasons for creating complex trees and forests:

-

Geographic separation

-

Different password policies.

-

Large number of objects

-

Replication performance

Forest root domain

First domain defined when you promote your first

Windows server to a domain controller (DC)

(13)

Adding a Role

(14)

Adding a Role

(15)

Adding a Role

(16)

Adding a Role

(17)

Adding a Role

(18)

Adding a Role

(19)

Adding a Role

(20)

Adding a Role

Installation Results

Click on “Close this wizard and launch the Active

(21)

DCPROMO

ADDS Installation Wizard

(22)

DCPROMO

(23)

DCPROMO

Operating System Compatibility

(24)

DCPROMO

Choose a Deployment Configuration

In the classroom, create a new domain in a new forest

(25)

DCPROMO

Name the Forest Root Domain

(26)

DCPROMO

Prior to 2007 Microsoft said:

“We recommend using the extension

.local for the full DNS name for your

internal domain. Because .local is not

registered for use on the Internet,

your internal domain and your public

Internet domain (such as .com or .net)

remain separate. This is more secure

and avoids name resolution issues.”

(27)

DCPROMO

As of 2007 Microsoft recommends:

Use your company’s Internet FQDN

and add a level to it.

(28)

DCPROMO

(29)

DCPROMO

NetBIOS domain name

Name that is

used by legacy

clients

What you see in

network

neighborhood

Limited to 15 characters

(30)

DCPROMO

Set Forest Functional level

In the classroom…

(31)

DCPROMO

Set Domain Functional level

In the classroom…

(32)

DCPROMO

Additional Domain Controller Options

DNS is tightly integrated into Active Directory

(33)

DCPROMO

Location for Database, Log Files, and Sysvol

The location where

the directory services

database files are

stored

For performance

and reliability…

And backup

In the classroom…

(34)

DCPROMO

Restore mode password

(35)

DCPROMO

Summary

(36)

DCPROMO

Configuring active directory domain services

(37)

DCPROMO

(38)

DCPROMO

Test your server configuration after rebooting

Especially your DNS server configuration

DNS is tightly integrated into ADS

IPCONFIG /ALL

As a result of the DCPROMO wizard installing DNS

Your DNS IP should be 127.0.0.1

(39)

DCPROMO

References

Related documents

This is what CZ stands for, and this is why CZ also offers healthcare services in addition to group health insurance that will assist you with ensuring the health of your

Designing an Active Directory Domain Infrastructure in Windows Server 2008.. Administering Active Directory Securely

While still a member of a domain, a domain controller is a Windows Server 2003 system explicitly configured to store a copy of the Active Directory database, and service

RIS must be installed on a Windows 2000/2003- based server that has access to Active Directory, for example, a domain controller or a server that is a member of a domain with access

Interestingly, when the N rate x plant density interaction was analyzed across different stress levels, the low density (44,460 plants/ha) responded to the same level of N (133

The College of Engineering also embraces the goals of fostering teaching, scholarship and outreach on an interdisciplinary basis. The certificate program will support

Additional Domain Controller Options page (Active Directory Domain Services Installation Wizard), 259 Additional Domain Controller Options. page (Active Directory Installation

Module 4: Designing Active Directory Domain Administrative Structures in Windows Server 2008This module explains how to design Active Directory domain administrative structures