Quick help on AD design

Hi there,

I have experience with LDAP/OD, and windows server, but finally setting up my first AD!  Looking for a little bit of help on design.  Here's the scoop.

-  three offices in three different cities in the US, all on 250mbit fibre, S2S over IPSec

- 50 or so people in each office

- will be using vmware to virtualize server 2k12 in a redundant environment with each controller on another esxi host.

- we use office 365, but don't care too much about tying it together

- we typically use a prefix on our suffix for each office to name client computers and servers in each office, our current DNS is setup like that.  (serverone.chi.domain.com, serverone.sea.domain.com, anotherserver.nyc.domain.com, etc.)

-  we plan on ditching bind dns and using windows dns of course.

- we also collaborate on projects cross office, so we need to make sure authentication will work across offices

I've found conflicting info on parent and child domains and wanted to get a little clarity.  I read that you should be careful about using a parent domain that matches the name of your website as it can cause some issues.  I've also seen someone recommend that you should setup each child domain as it's own dc in each office.  My thoughts are that we should have two dc's in each office for redundancy.  I want the setup to be as simple as possible, I know how bad things can get with broken directory services!

Any help on design would be MUCH appreciated.  thanks!


July 22nd, 2015 6:44pm

I personally would have one domain. More just makes things overly complicated. You still should have 2 DCs at each site, if at all possible, and make all DCs GCs.
Free Windows Admin Tool Kit Click here and download it now
July 22nd, 2015 9:12pm

Thanks for the response, Richard.

Yeah, I agree with the simplicity.  I was thinking about using "ad.company.com" as the domain.  

Is there any reason I can't name servers like this while using a different child domain for AD?

serverone.chi.company.com

serverone.nyc.company.com

Also, we have some intranet type sites that are like

intranet.company.com

database.company.com

How would I create these entries in DNS?  Would the entries *require* the servers FQDN to have the ad.company.com in the name? (like serverone.ad.company.com)

thanks again for any help!!

July 23rd, 2015 12:33am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics