Network System Management Creating an Active Directory Domain
Objectives Identify the procedures involved in the promotion of a stand-alone Windows Server to an active directory services (ADS) domain controller (DC) Planning Environment Preliminary steps Best practices Classroom Page 2
Planning Is this the first domain controller? What is the existing network environment? Is this an Intranet, Extranet, or part of your DMZ? Intranet = Internet based technologies used within your LAN. Ex: A web server only available within your offices Extranet = Private, restricted web page only available to your business partners DMZ = demilitarized zone (see next slide) Page 3
DMZ = demilitarized zone Planning Standard Configuration all inbound ports on firewall are closed protecting the LAN Page 4
DMZ = demilitarized zone Planning Ports on firewall open to DMZ systems: Web server port 80, etc. Page 5
Planning DMZ = demilitarized zone Best practice: outside firewall with open ports to DMZ systems, inside firewall with closed ports Page 6
Preliminary Steps Install the operating system Install the necessary service packs and updates - Not required in the classroom Install and connect all hardware devices and peripherals Page 7
Preliminary Steps (cont.) Connect to your network and configure the TCP/IP protocol Dynamic or Static IP? - In the classroom: disable IP v6 as it is not part of our network configuration Page 8
Active Directory Concepts What is an AD DS Domain Logically structured organization of objects - Network environment - Share common directory services database Has unique name Organized in levels Administered as a unit with common rules and procedures Provides administrative benefits Page 9
Active Directory Concepts (cont.) AD Domain Trees and Forests Page 10
Active Directory Concepts (cont.) AD Domain Trees and Forests Tree - Hierarchical collection of domains - Share contiguous DNS namespace Forest - Collection of trees - Do not share contiguous DNS naming structure Page 11
Active Directory Concepts (cont.) AD Domain Trees and Forests Reasons for creating complex trees and forests: - Geographic separation - Different password policies. - Large number of objects - Replication performance Forest root domain First domain defined when you promote your first Windows server to a domain controller (DC) - This is what we are doing in the classroom Page 12
Adding a Role Add a Role Page 13
Adding a Role Before You Begin Page 14
Adding a Role Select Server Roles Page 15
Adding a Role Active Directory Domain Services Role Page 16
Things to Note Adding a Role Page 17
Adding a Role Confirm Installation Selections Page 18
Adding a Role Installation Progress Page 19
Adding a Role Installation Results Click on Close this wizard and launch the Active Directory Services Installation Wizard (dcpromo.exe) Page 20
DCPROMO ADDS Installation Wizard Which mode should we run? Page 21
DCPROMO Advance Mode Installation Page 22
DCPROMO Operating System Compatibility Legacy systems Page 23
DCPROMO Choose a Deployment Configuration In the classroom, create a new domain in a new forest the root domain Page 24
DCPROMO Name the Forest Root Domain What is an Internet FQDN? Page 25
DCPROMO Prior to 2007 Microsoft said: We recommend using the extension.local for the full DNS name for your internal domain. Because.local is not registered for use on the Internet, your internal domain and your public Internet domain (such as.com or.net) remain separate. This is more secure and avoids name resolution issues. Quoted from the Microsoft Windows Small Business Server 2003, R2, server promotion wizard. Page 26
DCPROMO As of 2007 Microsoft recommends: Use your company s Internet FQDN and add a level to it. Ex: internal.widgetworks.com Page 27
DCPROMO Checking the Network for name conflicts Page 28
DCPROMO NetBIOS domain name Name that is used by legacy clients What you see in network neighborhood Limited to 15 characters Accept the default Page 29
DCPROMO Set Forest Functional level In the classroom accept the default Page 30
DCPROMO Set Domain Functional level In the classroom accept the default Page 31
DCPROMO Additional Domain Controller Options DNS is tightly integrated into Active Directory What is the parent zone? Page 32
DCPROMO Location for Database, Log Files, and Sysvol The location where the directory services database files are stored For performance and reliability And backup In the classroom accept the default Page 33
DCPROMO Restore mode password Used when demoting or when restoring ADS Best practice different from administrator In the classroom know what it is Required when Demoting a DC Page 34
DCPROMO Summary Next Page 35
DCPROMO Configuring active directory domain services Patience Page 36
DCPROMO Complete Page 37
DCPROMO Test your server configuration after rebooting Especially your DNS server configuration DNS is tightly integrated into ADS IPCONFIG /ALL As a result of the DCPROMO wizard installing DNS Your DNS IP should be 127.0.0.1 - Which indicates the loopback IP, or localhost Page 38
DCPROMO Test your server configuration after rebooting Page 39