您好,登錄后才能下訂單哦!
AD DS Design
Single forest single domain is preferred
Time is important (PDC)
Implement multiple/backup domain controllers
2,150,000,000 objects per domain
FQDN less than 64 characters
FSMO (Flexible single master operation)
Schema master | Forest level | To make change into Schema in forest (such as implement Exchange, Lync) |
Domain naming master | Forest level | To add/remove domain in forest |
PDC | Domain level |
|
RID Pool master | Domain level | Assign RIDs (500/time) to DC |
Infrastucture master | Domain level | Objects reference in different domains |
# To check the FSMO servers
netdom query fsmo
# To transfer / seize
netdom /?
Install Domain controllers in the first site
# Install AD DS on the first DC
Install-WindowsFeature AD-Domain-Services -IncludeAllSubFeature -IncludeManagementTools
# # Windows PowerShell script for AD DS Deployment # Import-Module ADDSDeployment Install-ADDSForest ` -CreateDnsDelegation:$false ` -DatabasePath "C:\Windows\NTDS" ` -DomainMode "Win2012R2" ` -DomainName "vccware.com" ` -DomainNetbiosName "VCCWARE" ` -ForestMode "Win2012R2" ` -InstallDns:$true ` -LogPath "C:\Windows\NTDS" ` -NoRebootOnCompletion:$false ` -SysvolPath "C:\Windows\SYSVOL" ` -SafeModeAdministratorPassword (ConvertTo-SecureString "123.com" -AsPlainText -Force) ` -Force:$true
w32tm /config /computer:BJDC01.vccware.com /manualpeerlist:time.windows.com /syncfromflags:manual /update
Change the DNS from 127.0.0.1 back in the network adaptor configuration
# Install AD DS on the second DC
Install-WindowsFeature AD-Domain-Services -IncludeAllSubFeature -IncludeManagementTools
# # Windows PowerShell script for AD DS Deployment # Import-Module ADDSDeployment Install-ADDSDomainController ` -NoGlobalCatalog:$false ` -CreateDnsDelegation:$false ` -CriticalReplicationOnly:$false ` -DatabasePath "C:\Windows\NTDS" ` -DomainName "vccware.com" ` -InstallDns:$true ` -LogPath "C:\Windows\NTDS" ` -NoRebootOnCompletion:$false ` -ReplicationSourceDC "BJAD01.vccware.com" ` -SiteName "Default-First-Site-Name" ` -SysvolPath "C:\Windows\SYSVOL" ` -SafeModeAdministratorPassword (ConvertTo-SecureString "123.com" -AsPlainText -Force) ` -Force:$true
免責聲明:本站發布的內容(圖片、視頻和文字)以原創、轉載和分享為主,文章觀點不代表本網站立場,如果涉及侵權請聯系站長郵箱:is@yisu.com進行舉報,并提供相關證據,一經查實,將立刻刪除涉嫌侵權內容。