Everyone that is using a domain based DFS namespace with more than one target most certainly is using FRS to replicate the data between the replica's. R2 provides a new state-based replication mechanism called 'DFS Replication'. REMARK: from this point the DFS folder is available through the DFS namespace and replication is working. However when looking from the DFS Namespaces node by selecting the DFS folder and then the Replication TAB it will show: "Replication status: not configured". And when looking from the DFS Replication node by selecting the replication group and then the replicated folders TAB it will show: "Publication status: not published". The main reason for this is because an attribute is not populated (we will take care of that later!)
A summarization of its very cool features and characteristics:
(1) Configure each existing DFS folder using FRS replication within A SEPARATE DFS-R replication group with one replicated folder
(2) Configure each existing DFS folder using FRS replication within A SEPARATE OR EXISTING DFS-R replication group. This way one replication group can contain one or more DFS folders as replicated folders that share the same replication topology, replication schema and bandwidth usage.
Before starting with the migration from FRS to DFS-R, I do recommend that one first reads the following document as it contains information on how to setup/design DFS Namespaces and DFS Replication:
REMARK: sharing and publishing the folder into the desired DFS namespace will not work because the DFS folder already exists in the DFS namespace
If you use this information, please be so kind to post any comments you have!
And of course: TRY IT FIRST IN A TEST ENVIRONMENT AND SEE IF THE RESULTS ARE SATISFYING!!!
Migrating from FRS to DFS-R
Labels: Fix, Thunderbird, Videos, Windows Server
Tracking LDAP Searches with Windows Server 2008 Reliability and Performance Monitor
Windows Server 2008 ships with the Reliability and Performance Monitor (RPM) snap-in. On DCs, RPM incorporates an Active Directory Diagnostics feature that includes the abilility to track LDAP searches against a DC. The amount of information captured can be very useful when troubleshooting LDAP issues.
This article provides a step by step guide on how to use RPM to track LDAP searches.
Label | Example | Explanation |
Client | 192.168.83.1814 | Client IP address and source port number |
Instance | NTDS | Always NTDS for AD DS. May be different for AD LDS. |
Scope | Deep | LDAP search scope. Will be one of base, one-level or deep (subtree). |
Object Name | DC=ad,DC=fisheagle,DC=net | Search base, i.e. the Distinguished Name of the object from which the base will start. |
Filter Name | (&(objectClass=user)(sn=n*)) | The LDAP search filter used. |
Index | idx_sn:6:N; | The internal index used for the search. In this example, the index for surname (sn) was used. |
Status | 0 | The result of the search. A value indicates that the search completed successfully. |
Visited | 6 | The number of objects visited by the search. |
Found | 6 | The number of objects found by the search. |
Requests/Sec | 0 | The number of requests made per second. Typically, this is 0. |
Response Time (ms) | 1 | The number of milliseconds the search took to complete. |
CPU % | 0 | The percentage of CPU the search used. |
Labels: Fix, Thunderbird, Videos, Windows Server
Mapping of MMC display names to snap-in file names (*.msc)
This mapping can be useful for those who like to launch snap-ins from the command line or from Start -> Run.
Labels: Fix, Thunderbird, Videos, Windows Server
Multiple Domain Forests: Still a Valid Design Model?
Labels: Fix, Thunderbird, Videos, Windows Server
Considerations when using a domain-based service account with AD LDS
When creating an AD LDS instance you are prompted to specify an account to use as the service account. At this point you can specify either the Network Service account or another account. Unless you have a particular need, you should choose the built-in Network Service account. If you opt for a domain-based service account you have to jump through a whole lot of hoops to get things working. Also, you typically end up giving your domain-based service account more permissions than are strictly necessary (as described later in this article). The Network Service account on the other hand provides an easy set up option and is a good choice from a security perspective given that the account has limited access to the local computer.
1. Create a user account in AD.
Source: ADAM [instance1] General
Date: 6/04/2009 11:22:08 a.m.
Event ID: 1168
Task Category: Internal Processing
Level: Error
Keywords: Classic
User: ANONYMOUS LOGON
Computer: ADLDS1.widget.com
Description:
Internal error: An Active Directory Lightweight Directory Services error has occurred.
Additional Data
Error value (decimal):
-1073741790
Error value (hex):
c0000022
Internal ID:
3000715
Labels: Fix, Thunderbird, Videos, Windows Server