Introduction. Versions Used Windows Server 2003



Similar documents
Installing and Setting up Microsoft DNS Server

How To Install And Configure Windows Server 2003 On A Student Computer

How do I install Active Directory on my Windows Server 2003 server?

How to. Install Active Directory. Server 2003

Course: WIN310. Student Lab Setup Guide. Summer Microsoft Windows Server 2003 Network Infrastructure (70-291)

Installation of MicroSoft Active Directory

Joining. Domain. Windows XP Pro

How to install Small Business Server 2003 in an existing Active

Chapter 3: Building Your Active Directory Structure Objectives

Installing the Microsoft Network Driver Interface

Network Scanner fi-6000ns

Setting Up a Backup Domain Controller

AD RMS Step-by-Step Guide

In the Active Directory Domain Services Window, click Active Directory Domain Services.

How to Join QNAP NAS to Microsoft Active Directory (AD)

CLEO NED Active Directory Integration. Version 1.2.0

NAS 206 Using NAS with Windows Active Directory

Contents Introduction... 3 Introduction to Active Directory Services... 4 Installing and Configuring Active Directory Services...

istorage Server: High-Availability iscsi SAN for Windows Server 2008 & Hyper-V Clustering

0651 Installing PointCentral 8.0 For the First Time

Trial environment setup. Exchange Server Archiver - 3.0

Active Directory integration with CloudByte ElastiStor

The Windows Server 2003 Environment. Introduction. Computer Roles. Introduction to Administering Accounts and Resources. Lab 2

Windows Domain Network Configuration Guide

Active Directory Restoration

Appendix B Lab Setup Guide

Step-by-Step Guide to Setup Instant Messaging (IM) Workspace Datasheet

How to Install the Active Directory Domain Services (AD DS) Role in Windows Server 2008 R2 and Promote a Server to a Domain Controller

istorage Server: High Availability iscsi SAN for Windows Server 2012 Cluster

Other documents in this series are available at: servernotes.wazmac.com

Installing Active Directory

Installing Windows Rights Management Services with Service Pack 2 Step-by- Step Guide

Faculty Details. : Assistant Professor ( OG. ),Assistant Professor (OG) Course Details. : B. Tech. Batch : : Information Technology

Click Studios. Passwordstate. Installation Instructions

Network System Management. Creating an Active Directory Domain

Kaseya 2. User Guide. Version R8. English

Step-by-Step Guide for Setting Up IPv6 in a Test Lab

Windows 7 Hula POS Server Installation Guide

Active Directory Domain Migration Checklist ADUM Active Directory Migrator

Configure Windows 95 after a Domain name change Configure TCP/IP correctly using DHCP Eliminate Network Traffic by Disabling Sharing

Using Logon Agent for Transparent User Identification

SETTING UP ACTIVE DIRECTORY (AD) ON WINDOWS 2008 FOR EROOM

Dialing up with Windows 95

Quick Start Guide. Sendio System Protection Appliance. Sendio 5.0

Windows Vista: Connecting to the wireless network at Hood College

NNAS-D5 Quick Installation Guide

Wazza s QuickStart 1. Leopard Server - Install & Configure DNS

Active Directory Authentication Integration

Searching for accepting?

Lotus Notes 6.x Client Installation Guide for Windows. Information Technology Services. CSULB

Deploying Remote Desktop IP Virtualization Step-by-Step Guide

SonicOS Enhanced 3.2 LDAP Integration with Microsoft Active Directory and Novell edirectory Support

Use 802.1x EAP-TLS or PEAP-MS-CHAP v2 with Microsoft Windows Server 2003 to Make a Secure Network

SharePoint Server for Business Intelligence

Windows Server 2008 R2 Initial Configuration Tasks

Creating the Conceptual Design by Gathering and Analyzing Business and Technical Requirements

Chapter 2 Preparing Your Network

StarWind iscsi SAN Software: Using StarWind with MS Cluster on Windows Server 2003

Step By Step Guide: Demonstrate DirectAccess in a Test Lab

Cloud Services ADM. Agent Deployment Guide

Deploying Windows Streaming Media Servers NLB Cluster and metasan

Quick Start Guide. Version R91. English

How the Active Directory Installation Wizard Works

Implementing Domain Name Service (DNS)

RoomWizard Synchronization Software Manual Installation Instructions

Active Directory Management. Agent Deployment Guide

FaxCore Ev5 -To-Fax Setup Guide

TopEase Single Sign On Windows AD

ILTA HAND 6B. Upgrading and Deploying. Windows Server In the Legal Environment

Contents. Platform Compatibility. Directory Connector SonicWALL Directory Services Connector 3.1.7

AD RMS Windows Server 2008 to Windows Server 2008 R2 Migration and Upgrade Guide... 2 About this guide... 2

Configuring the CyberData VoIP 4-Port Zone Controller with Audio Out

Presenter s name here Date of presentation (optional) Windows Security and Domains for Experion

CONFIGURING ACTIVE DIRECTORY IN LIFELINE

VRC 7900/8900 Avalanche Enabler User s Manual

PC User s Guide PC User s Guide Muratec America, Inc.

LDAP Implementation AP561x KVM Switches. All content in this presentation is protected 2008 American Power Conversion Corporation

STATISTICA VERSION 9 STATISTICA ENTERPRISE INSTALLATION INSTRUCTIONS FOR USE WITH TERMINAL SERVER

Iomega Home Media Network Hard Drive

Clustering VirtualCenter 2.5 Using Microsoft Cluster Services

Dell Compellent Storage Center

Creating a Domain Tree

SafeWord Domain Login Agent Step-by-Step Guide

R4: Configuring Windows Server 2008 Active Directory

Setting up Active Directory Domain Services

STATISTICA VERSION 12 STATISTICA ENTERPRISE SMALL BUSINESS INSTALLATION INSTRUCTIONS

Step-by-Step Guide for Creating and Testing Connection Manager Profiles in a Test Lab

WatchGuard Mobile User VPN Guide

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

Step-by-Step Secure Wireless for Home / Small Office and Small Organizations

Outlook Profile Setup Guide Exchange 2010 Quick Start and Detailed Instructions

AcqKnowledge or better for Windows OS (version compatibility varies each release)

Configuring Global Protect SSL VPN with a user-defined port

Using Cisco UC320W with Windows Small Business Server

Core Active Directory Administration

9. Which is the command used to remove active directory from a domain controller? Answer: Dcpromo /forceremoval

Integrating idrac7 With Microsoft Active Directory

Transcription:

Training Installing Active Directory Introduction As SonicWALL s products and firmware keeps getting more features that are based on integration with Active Directory, e.g., Active Directory Connector for CSM appliance, LDAP integration for UTM Appliances and SSL-VPN and Email Security, more people will install Active Directory on their local server or server in a test environment. This training document is a guideline on how to setup Microsoft Active Directory. Versions Used Windows Server 2003 Setup Used i. Server Name = martini ii. Credentials: User = Administrator, Password = password iii. IP Address: 10.1.1.101 iv. AD Setup: AD Domain Name = echofloor.com v. AD Setup: NetBIOS Domain Name= echofloor Prerequisites Before being able to Install Active Directory, a Domain Name System (DNS) server is required. Therefore, some knowledge of DNS is required. An integration of DNS and WINS (Windows Internet Naming Service) is not required but is best practice. Therefore knowledge of WINS is also a prerequisite. As this training involves changing TCP/IP Settings, knowledge of TCP/IP is the next requirement. In this Tech Note Microsoft terms will be used without explanation. Microsoft Active Directory is dependent on a fully functional DNS server. This training will include a basic guide for how to install and setup Microsoft Windows 2003 DNS server to support Microsoft Active Directory.

Training CATEGORY Title Installing Active Directory Task List Install Windows 2003; Prepare Windows 2003 Server; Prepare TCP/IP Settings; Install WINS and DNS; Setup DNS; Install Active Directory; Setup Active Directory. Install Windows 2003 This training assumes Windows 2003 Server is installed and that all drivers have been installed. Make sure that either a copy of the I386 Directory from the Windows Server installation CD on the local hard drive remains, or the Windows Server installation CD is in the CD Drive. A Domain Controller must have a fixed IP so make sure that the server does not get an IP from a DHCP server. The server must be able to reach the Internet but DNS settings are not required as the server will be its own DNS server.

Prepare Windows 2003 The first step for installing Active Directory is to set the computer name and Primary DNS Suffix. The computer name and Primary DNS Suffix must be set from System Properties. From System Properties go to the Computer Name tab. On this tab the full computer name and the workgroup can be seen. Workgroup name is not important, as this will not be used; Computer name, membership and Primary DNS Suffix can be changed by clicking the Change button; The More button brings up the DNS Suffix and NetBIOS Computer Name dialog; In the Primary DNS Suffix of this computer field the Domain Name to be used by your DNS Server must be filled in. e.g. echofloor.com; After applying these settings the server needs to be restarted. Note: Without a restart the Server will not get the new server name and / or DNS Suffix. This will result in the failure of the DNS server that has to be installed later in this training.

Prepare TCP/IP Settings Once the proper name and DNS Suffix are setup, some adjustments have to be made to the TCP/IP settings. For this go to the properties of the Primary Local Area Connection in Network Connections. Select Internet Protocol (TCP/IP) and click the Properties button; Make sure that the server has a static IP address and a Default Gateway. For Preferred DNS Server fill in the server s IP address; Click the Advanced button to go to the advanced settings; On the WINS tab click the Add button to fill in the server s IP address; Make sure that the Enable NetBIOS over TCP/IP is selected. These settings will point all DNS and WINS requests from your server to its own DNS and WINS server. Without these settings you server will not be able to register itself in its own DNS and WINS tables.

Install WINS and DNS DNS (Domain Name System) and WINS (Windows Internet Name Service) Server can be installed in a single go. DNS and WINS are installable windows components and need to be installed via Add/Remove Programs from Control Panel. From Windows Components select Networking Services; Click Details to select the Networking Services you want to install; Select Domain Name System (DNS) and Windows Internet Name Service (WINS). Installing Windows Components, the I386 Directory from the Original Windows Server 2003 is needed. If the CD is not in the CD Drive, a popup will allow you to select the location of the I386 directory. Once installation is complete, two additional Services and two additional Administrative Tools can be found on the server.

Setup DNS In contrary to WINS, which does not need additional configuration, DNS setup consists of multiple steps. This training only covers setting up Microsoft DNS server to prepare for Microsoft Active Directory. More Advanced Microsoft DNS Server configuration will be handled in a separate training. Microsoft DNS Server is configured via DNS Manager. DNS Manager can be launched via the DNS shortcut within Administrative Tools. The first step to setup Microsoft DNS server is to setup a Forward Lookup Zone. This can be done by selecting and right clicking Forward Lookup Zones and choosing the New Zone option. This will launch the New Zone Wizard

The first step is to select the Zone Type. Select Primary Zone; For Zone Name, fill in the Domain Name needed for the Domain, in this case echfloor.com; For Zone File, leave the option on Create a new file and leave the filename as it is; On the Dynamic Update option, choose to Allow both nonsecure and secure option.

Completing the New Zone Wizard will create the Forward Lookup Zone. Once the Forward Lookup Zone is created, the next step is to create a Reverse Lookup Zone. The steps to create a Reverse Lookup Zone are very similar to creating a Forward Lookup Zone. The first step is to select the Zone Type. Select Primary Zone;

For Reverse Lookup Zone Name, fill in the Network ID needed for the Domain. The network ID consists of the IP Subnet ID - in this case 10.1.1; For Zone File, leave the option on Create a new file and leave the filename as it is; On the Dynamic Update option, choose to Allow both nonsecure and secure option. Completing the New Zone Wizard will create the Reverse Lookup Zone. As an option WINS and DNS can be integrated. Not allowing Dynamic Updates on Forward Lookup Zone will stop Active Directory Installation.

Integrating DNS and WINS Integrating DNS and WINS server is not required, but can help with name resolving and is advised when using Microsoft Active Directory. WINS Integration can be enabled on the Properties Dialog of a specific Zone. On the Properties of the Forward Lookup Zone go to WINS tab; Enable Use WINS forward lookup; Enter the IP Address of your WINS Server; in this case the server IP is 10.1.1.101. On the Properties of the Reverse Lookup Zone go to WINS-R tab; Enable Use WINS-R lookup; Fill in the Domain name; in this case echofloor.com.

Install Active Directory Now that the preparations for Active Directory have been setup, the server can be setup as an Active Directory Domain Controller. This step is also called Promoting a server to Domain Controller. To promote a server to Domain Controller run DCPromo, from Start, Run. This will launch the Active Directory Installation Wizard; After reading the warning about Operating System Compatibility, setup can be started; From the first screen choose Domain controller for a new domain; On the next screen choose Domain in a new forest;

On the New Domain Name dialog fill in the Full DNS Name for new domain. This is the same Domain Name used in setting up the Forward Lookup Zone in DNS Server. In this case echofloor.com; On the NetBIOS Domain Name choose a Domain Name as used in earlier versions of windows. This is the Domain Name that will be seen in the Logon Screen for Windows clients and in the Logon Screen for Email Security when using Domain Login. In this case ECHOFLOOR; Leave the settings on Database and Log Folders and Shared System Volume dialogs as default. By default these will be placed in the windows directory. The SYSVOL will on completion also be accessible as a network share and is used to synchronize data between domain controllers;

The last step in the wizard is to set Permissions level. When pre-windows 2000 Servers exist within the network the Permissions compatible with pre-windows 2000 option needs to be chosen. This option lowers part of Windows Server security level. In this case choose this option. After all the above options have been completed, a DNS Registration Diagnostics test will run. If these Diagnostics fail, Active Directory can not be installed. The most probable cause for this is the DNS Server has not been setup properly. Possible causes: Primary DNS Suffix has not been configured; Preferred DNS Server IP has not been configured to the server s own IP address; DNS Service is not started; Forward Lookup Zone does not allow Dynamic Updates. The last step in the wizard to complete is choosing the password for the Domain Administrator Account.

After choosing a Domain Administrator password Active Directory will be installed. After the wizard is complete, the server needs to be restarted. Note: without restarting Active Directory will not be active Note: A Domain Controller Startup takes much longer than a normal server Once Active Directory has been successfully installed, a few direct changes can be found on the system: Active Directory will add five new Administrative Tools: -Active Directory Users and Computers; -Active Directory Sites and Services; -Active Directory Domains and Trusts; -Domain Security Policy; -Domain Controller Security Policy. Active Directory will add Active Directory Domain information in to the DNS Forward Lookup Zone. If these are missing, your Active Directory Installation will have failed.

The final steps for Active Directory Setup are to integrate Windows DNS Server and Active Directory. This is done by changing the properties of the Forward Lookup Zone and Reverse Lookup Zone; From the Forward Lookup Zone Properties click the Change button to change the Zone Type; Enable the Store the zone in Active Directory; Repeat this process for the Reverse Lookup Zone.

Setup Active Directory Once Active Directory is installed Active Directory can be further setup to be used. This chapter will cover a few basic tasks: -Setup Sites and Services; -Modify Domain Security Policy for ease of use; -Setup an Organizational Unit (OU); -Add a user. Setup Sites and Services Although modifying Sites and Services is not a requirement, it is an Administrative Task that will help to identify where each server is located. This is especially useful in a multi-site environment. With Sites and Services Inter-Site links are defined and Inter-Site Replication is defined. Settings changed in Sites and Services will be reflected in DNS Server and in Exchange Server. Sites and Services can be setup from the Active Directory Sites and Services Manager tool. The First task is to rename Default-First-Site-Name to an appropriate Site Name; in this case EchoFloor- TestLab; This change is immediately reflected in DNS Server.

The second task is to add the local Subnet, by right clicking Subnets and choosing New Subnet; In the New Object - Subnet dialog fill in the appropriate IP Address and Subnet Mask and select the Site this Subnet belongs to. In this case fill in 10.1.1.0 and 255.255.255.0 and choose EchoFloor-Testlab as site. Modify Domain Security Policy By default Windows Server 2003 uses a very strict Password Policy. By default passwords must meet a certain complexity requirement. This includes the requirement to have three out of the following four characteristics: -Must contain small case letters; -Must contain upper case letters; -Must contain numbers; -Must contain non-alpha numeric characters like @#$%. This behavior can be changed by modifying the Domain Security Policy. Domain Security Policies can be modified with the Domain Security Policy manager. Disable Password must meet complexity requirements.

Setup an Organization Unit (OU) Although using Organization Units is not a requirement, it helps Administrators organize Active Directory users and is a requirement for Delegation of Control. In this training we will use Organizational Units to administratively separate the testlab users and groups from the Active Directory built-in users and groups. OU s can be created with the Active Directory Users and Computers manager. Right click the domain. In this case right click echofloor.com; From the New Drop down choose Organizational Unit; Fill in the new OU name. In this case EchoFloor.

Add a User Now that Active Directory is installed and setup, users can be created. Users are managed with the Active Directory Users and Computers management tool. Users can be created in any of the available containers available. Select the container or OU where you want the user to be created In this case select EchoFloor; Right click on either the container or in the right pane and select New>User; In the New Object User dialog fill in the User s attributes: o First name; o Initials; o Last name; o Full name; o User logon name this is also called the User Principal; o User logon pre-windows 2000 this is the user login used when logging on to Domain Computers, SonicWALL Appliances and Email Security. Create a password and set password options. Note: User logon name is NOT an email address When users are created, you can create groups in a similar manner, and add users to groups. After the Active Directory is filled with users and groups, the Active Directory is ready to be used. This concludes this training.