Connectivity

Healthy replication between domain controllers is a must for the Active Directory infrastructure. FSMO role holders are designated to do specific tasks in the infrastructure. Other domain controllers, devices, and resources should have a reliable communication channel with FSMO role holders in order to get these specific tasks done for them when required.

In Active Directory infrastructures, there can be regional offices and remote sites that are connected using WAN links. Most of the time, these WAN links have limited bandwidth. These remote sites can have domain controllers hosted too. If replication traffic between sites is not handled in an optimized way, it can turn out to be a bottleneck. Rebeladmin Corp. is a managed services provider and it has two offices. The HQ is located in Toronto and the operation center is based in Seattle, USA. It is connected via a 512 KB WAN link. In the Toronto office, there are 20 users and in the Seattle office, there are 500 users. It runs on a single domain Active Directory infrastructure. As I mentioned earlier, among all these FSMO roles, the PDC is the most highly used FSMO role. Devices and users keep communicating with PDC more frequently than other FSMO role holders. In this scenario, if we place the PDC in the Toronto office, 500 users and associated devices and the other workloads will need to go through the WAN link in order to communicate with the PDC. But if we place it in the Seattle site, then the traffic that will pass through the WAN link to connect to the PDC will be lower. In a regional office scenario, make sure you always place the PDC near the site that hosts the most number of users, devices, and resources.

Network topology use for inter-site connectivity also makes an impact on the FSMO role placement:

In the preceding example, Active Directory setup has three Active Directory sites with a single domain infrastructure. Site Canada connects to Site USA and Site USA connects to Site Europe. But Site Canada does not have a direct connection with Site Europe. Now if the FSMO roles are placed in Site Canada, Site Europe will have issues communicating with it. Site Europe will not be able to perform any FSMO-related tasks. According to the network topology, the best option will be to place the FSMO roles in Site USA as both sites have a direct connection to it.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.190.156.212