170 likes | 184 Views
2.1. Plan Active Directory. TestOut Server Pro 2016: Identity. Active Directory Sites. Section Skill Overview. Create Active Directory sites. Configure Active Directory sites. Manage Active Directory sites and subnets. TestOut Server Pro 2016: Identity. Key Terms. Site Subnet Site Links.
E N D
2.1 Plan Active Directory TestOut Server Pro 2016: Identity Active Directory Sites
Section Skill Overview • Create Active Directory sites. Configure Active Directory sites. Manage Active Directory sites and subnets. TestOut Server Pro 2016: Identity
Key Terms • Site Subnet Site Links TestOut Server Pro 2016: Identity
Key Definitions • Site: A physical grouping of well-connected IP subnets that are typically connected with high-speed links. In most cases, an Active Directory site will map to a single LAN. Sites can represent a large physical location, such as a country or city, or a small collection of subnets located in a building. Subnet: A subnet represents a grouping of computers based on their IP address or physical network segment. Each subnet possesses its own unique network address space. Site Links: Site links represent the logical paths that the Knowledge Consistency Checker (KCC) uses to establish the intersite connectivity for Active Directory replication. TestOut Server Pro 2016: Identity
Active Directory Sites • Sites control domain services replication. • Sites ensure users are directed to local resources. • Sites mirror the physical environment. TestOut Server Pro 2016: Identity
Site Design • Create separate sites for each WAN link except where no local site-aware applications exist. • Domain Controllers • Distributed File System (DFS) replicas • Third-party site-aware applications • Provide ample bandwidth within a site. TestOut Server Pro 2016: Identity
Site Concepts • Computers are assigned to sites based on their IP address. • Each computer is directed to resources in its own site. • Clients in sites with no domain controller are referred to the nearest site. • Site proximity is determined by Site Link cost. • Try Next Closest Site must be enabled. • Right-click on GPO and edit. • Select DC Locator DNS Records. TestOut Server Pro 2016: Identity
Site Concepts • Disable DCs from registering generic (non-site-specific) domain controllers.locator records in DNS • Limit domain controller authentication in two ways: • Set AutoSiteCoverage to 0 in the DC registry. • Disable using Group Policy. • Implement only when absolutely necessary. TestOut Server Pro 2016: Identity
Configuring Sites • Create site • Rename Default-First-Site-Name. • Create additional sites as needed. TestOut Server Pro 2016: Identity
Configuring Sites • Create site. • Rename Default-First-Site-Name. • Create additional sites as needed. • Create the subnet and associate it with the site. TestOut Server Pro 2016: Identity
Configuring Sites • Create site • Rename Default-First-Site-Name. • Create additional sites as needed. • Create subnet and associate to site. • Create site link objects. TestOut Server Pro 2016: Identity
Configuring Sites • Create site • Rename Default-First-Site-Name. • Create additional sites as needed. • Create subnet and associate to site. • Create site link objects. • Adjust site link object cost, schedule, and frequency. TestOut Server Pro 2016: Identity
Site Facts TestOut Server Pro 2016: Identity
Site Facts TestOut Server Pro 2016: Identity
In-Class Practice Do the following labs: • 2.1.4 Configure Sites 2.1.5 Manage Sites and Subnets TestOut Server Pro 2016: Identity
Class Discussion • How does a site differ from a domain? What is the purpose of a site link? What does the term "well-connected" mean when referring to networks? How are sites used in Active Directory? How do IP addresses and subnets relate to sites? How are dynamic site assignments made? TestOut Server Pro 2016: Identity