If all the domain controllers reside in the VMWare environment

I was curious to know if there is someone who can give their opinion about the location of the domain controllers in the VMWare community.  I had 2 DCs before the introduction of VMWare and pulling on servers inside.  I created 2 new controllers domain in VMWare and then retrograde 2 those outside so that only there are only virtual domain controllers.  It seemed to work very well, but I had to turn off equipment running VMWare, and when it started, the storage device that the accessible ESX host has launched a mistake because he could not find a domain controller.

Most people remove all external domain controllers and go with only VMWare virtual DCs, or is it better to always keep an external domain controller upwards and running?  Any advice is welcome.

Thank you.

I always advise to keep the domain controller hosting your virtual environment PDC emulator FSMO role. Time is critical on most of the servers, but especially on the PDC that is the top of your Windows Time synch infrastructure.

We also keep a ms in each data center on a physical platform, this way if we already have a power down when we turn we can raise the physical DC first and very quickly.

I hope this helps.

Kind regards

Steve

Tags: VMware

Similar Questions

  • Extend the VMware environment

    I'm expanding our vmware environment.  I currently have HA\DRS clusters comprising DL360\380 G5 servers.  I bought three DL380 G6 servers.  I'm the thing about creating another cluster for the G6 servers using VMware EVC vs. Someone has mixed the G5 and G6 servers on the same cluster?  Or is it better to keep them separated?

    Thank you

    > Has anyone mixed G5 and G6 servers on the same cluster?  Or is it better to keep them separated?

    VCA depends on the processor not material, if processors are a match, it should be good... We mixed in some, it's only a problem if your servers are a different configuration, so G5 is 64 GB and G6 is 96 GB of RAM for example, then you could end up with an asymmetrical cluster.

    IMHO if the machines are identical (except the new architecture) I would put it in the same cluster. You can always build the new cluster, as expected, disconnect, then remove the host G5 of the old cluster and ADD the new cluster G6 (after turning on VCA).  If she don't get complaint, it should be good

    BTW, removing guests will NOT affect the virtual computer running (provided that you restart / power off of the host).

  • How to activate the shared folders in the VMware tools

    I'm running a Windows 2003 Server EE guest x 64 OS in a virtual machine hosted by ESXi 3.5 u4 build 199239. VMware tools have been updated to the latest version for this build ESX.  In the VMware Tools Properties GUI the shared folders tab says "shared folders are currently disabled on the host computer.  Please see VMware documentation to find out how to activate it. "I searched all the VMware Documentation and have not found the answer to this question.

    Also, when folders are enabled it is my understanding that an addition is made to the guest OS network providers.  What is the impact of the network provider of shared folders moving further towards the bottom of the list of purchase orders (network connections, advanced, advanced settings, purchase order).

    As far as I KNOW, this is not possible if it running ESX (i)

    KB http://kb.vmware.com/kb/1317 tire

    The shared folders functionality is not supported by the ESX Server or GSX server, but is enabled when you install VMware Tools with the complete option. The feature is not enabled when you install VMware Tools with the typical option in respect of these products.

  • Help with the Powershell script to collect logs from all domain controllers

    I am writing a script to retrieve the last 5 days of application, security and log files from all domain controllers. The script runs, but fire the logs from the local server only. The variable $Computer has all of my DC so it's the fine mark. I guess it's a problem with my line ForEach-Object, but is not error. See the below script.

    $log = 'application '.
    $date = get-date-format MM-DD-YYYY
    $now = get-date
    $subtractDays = new-object System.TimeSpan 5,0,0,0,0
    $then = $Now.Subtract ($subtractDays)
    $Computers = get-ADDomainController-filter *.
    ForEach-Object - InputObject $Computers - process {Get-EventLog - LogName $log - after $then - before $now - EntryType error | select EventID, MachineName, Message, Source, TimeGenerated |} ConvertTo-html | {Out-file $env:TEMP\Applicationlog.htm}
    Invoke-Expression $env:TEMP\Applicationlog.htm

    Thank you

    Rich

    Hello

    To help with the repost the question script to the script Center Forum

    http://social.technet.Microsoft.com/forums/scriptcenter/en-us/home

  • all domain controllers are running windows server 2000 with the company wants to set up a more secure network server OS the company will modernize the ADS?

    you are the network administrator for abc.com domain. All domain controllers are running windows server 2000 with the company wants to set up a more secure network server OS the company will modernize the ADS?

    Please repost your request in the appropriate in the Windows Server Forum.  Thank you!

  • Remove 1 of the 3 domain controllers in a Windows environment

    I have a Windows domain that has Windows 2003 and 2008 R2 servers to support workstations, SharePoint and exchange among other things. There are 3 domain controllers. The first domain controller created on window 2003 server. Later, more 2 domain controllers were added on Windows 2008 R2. During the promotion of each of the servers in DC, each of them were activated as DNS and Global catalog servers. In addition, both 2008 DHCP configuration on them were servers and one Server 2008 R2 is configured as primary and the second as the secondary. The 2003 is just a DC member. I made main hold all 5 FSMO roles and replication works as well on both servers.
    I now have to demote the first Windows Server 2003, and then it must be taken out of the area. But whenever I have to run DCPromo to demote the server he kept a message that no other DC cannot be contacted, and when I try to disable the NIC in Server 2003, replication will stop automatically on the two 2008 R2.

    Any help please.
    Thanks in advance.

    Hello

    Post your question in the TechNet Server Forums, as your question kindly is beyond the scope of these Forums.

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

    See you soon.

  • Problems with cross certification over a link to low bandwidth to the domain controllers in the same forest

    I need to explain to a user a simple explanation on why this is not an effective solution for filing committed in different places trying to share a single file. The file is an excel document and the original file would be shared at 4 different locations on 4 separate domain controllers. The link is weak across all domains at best and the file is accessible by several people at the same time. Server 2003

    Hello

    I suggest you send the same question in the Microsoft Technet Forum for assistance. We have a dedicated team to help you with such questions.
    http://social.technet.Microsoft.com/forums/en/category/windowsxpitpro

  • Win2008R2 domain controllers; Restart the domain controllers disconnects the client

    * Original title: DC reboot causes disconnection of the clinets

    We have 2 controllers Doamin of Win2008R2. When a domain controller restarts, all the APs on some clients (Telnet, MSTSC ex...) Win7 will cut soon. There is no error/kingdoms fighters on the client event log. WinXP will never suffer.

    What can I do? Thank you.

    This issue is beyond the scope of this site (for consumers) and to be sure, you get the best (and fastest) reply, we have to ask either on Technet (for IT Pro) or MSDN (for developers)
    *
  • Commissioning for lack of Exchange because of the latency in Multi Site domain controllers

    Hi all

    I use using the OIM 11 g R2 PS2 BP04 with AD-connector version (11.1.1.6.0 & AD 2010) and the Version of the Exchange Connector (11.1.1.6.0 & Exchange 2010) and its installed on RHEL 6.5. We have 20:00 domain controllers and each of them is in a different site. Here is the list of domain controllers:

    DC-host1,DC-HOST2,DC-site2-host1,DC-SITE3-host1,DC-SITE4-host1...etc

    We use automatic configuration AD access strategies and resources the user Exchange and configured as domain controllers in AD IT resource:

    DC-HOST1 - primary

    DC-HOST2 - secondary

    AD resource provisioning works fine however when IOM tries to configure exchange to the user, its failure due to the latency issue b & w AD different Site of the domain controller. For example, "PRODTESTUSER12" is implemented successfully in AD and when IOM tries to configure exchange for this user, exchange server search for any available domain controller search for the user. It randomly selects an AD domain controller, I say DC-SITE2-HOST1 to search for the user. Since this domain contorller is on another site and it is latency, its not able to find the user of this domain controller, this is why available exchange fails for this user. See the below error:

    Target class = oracle.iam.connectors.icfcommon.prov.ICProvisioningManager

    < 21 may 2015 23:10:06 CEST > < error > < ORACLE. IAM. CONNECTORS. ICFCOMMON. Prov. ICPROVISIONINGMANAGER > < BEA-000000 > < oracle.iam.connectors.icfcommon.prov.ICProvisioningManager: createObject: error while creating user

    java.lang.RuntimeException: the operation could not be performed because the object 'PRODTESTUSER12' could not be found on 'anc-dc2k8 - 01.wssc.ad.root'.

    We have not specified this domain either under AD controller or Exchange resources.

    n Connector logs, I can see below:

    22/05/2015-10:55:19 < INFORMATION >: class-> Org.IdentityConnectors.Exchange.RemoteRunspaceInstance-> InvokeScript method, Message-> enter the method


    22/05/2015-10:55:19 < VERBOSE >: class-> Org.IdentityConnectors.Exchange.RemoteRunspaceInstance,-> InvokeScript method, Message-> Script: Set-ADServerSettings - ViewEntireForest: $true; Get-User "PRODTESTUSER21" - ReadFromDomainController

    I think, because of this script, Exchange Server recovers first of any domain controller available to search for the user. Yes, is there a way to restrict or put domain controller's favorite?

    There is a hotfix available for this problem. Here are the details:

    Patch 19692488: APPLICATION of MERGER on top of 11.1.1.6.0 FOR the BUGS 18310438 19478076

    Bugs resolved by this fix

    UPDATED EXCHANGE CONNECTOR SMTP PRIMARY ADDRESS 16813315 PROBLEM

    17949931 DELAY IN EXCHANGE / COMMISSIONING

    19478076 WITH REGARD TO THE EXCHANGE OF SUPPLY FAILURES.

    Concerning

    Suren

  • Domain controllers Windows 2008 R2 with the forest functional level Windows 2003 taken over after the end of Windows 2003 support in July 2015

    Hello

    Anyone know if the Windows 2008 R2 with Windows 2003 forest functional level domain controllers will be always supported after Windows 2003 support ends in July 2015?

    Thank you

    This issue is beyond the scope of this site and must be placed on Technet or MSDN

    http://social.technet.Microsoft.com/forums/en-us/home

    http://social.msdn.Microsoft.com/forums/en-us/home

  • DNS query script - need a way to script to query the DNS settings of all the servers on a domain

    Hi - I was wondering if anyone new a script or a simple way to query the DNS settings of all the servers on a domain? Basically, I need to know the primary and secondary, all our servers DNS settings and that discharge into a file. Any help is very appreciated

    Thanks in advance

    Hello

    As you try to run the DNS settings on the domain, I suggest you to post the same question on the Microsoft TechNet Forums

    You can follow the link to your question:

    Windows Small Business Server: http://social.technet.microsoft.com/Forums/en/category/windowsserver/

    It will be useful.

  • I want to move or archive all logs of all the computers in my domain name in one place

    Original title: more details

    Thanks for the reply, but it did not entirely of my concern. I want a way to automatically archive all the event logs of all computers in the domain to a place or location so that everytime I want to view logs from any computer I have to go to the centralized location and view it instead of going on this computer
    Hope I made my concern more clearly now.
    Hope to hear from you soon
    The sub steps might help you better understand my point of view
    1. I want to move or archive all logs of all the computers in my domain name in one place
    2. I want to be able to access any newspaper of the events from any computer by simply contacting this central location
    Thank you

    Hello

    Given that the problem is related to the domain network, I suggest you post this question in the TechNet forum.
    http://social.technet.Microsoft.com/forums/en-us/categories/

  • Change the account a local administrator on the domain controllers

    Hello

    I have a mix of domain controllers Server 2003-2012 of the running server.

    I need to rename the local administrator account.

    Is there a tool I can use to determine what applications/services using the local administrator account, which is what would be compromised if I renamed the existing local administrator account before as I do?

    Any advice or suggestions would be appreciated.

    Thank you.

    KO

    (Moved from FFOS)

    Hello

    Post your question in the TechNet Server Forums, as your question kindly is beyond the scope of these Forums.

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

    See you soon.

  • A way to resolve the domain controller Adobe Acrobat Reader to open with the right hand "Interface" in the closed position - really annoying to have to close ALL THE TIME.

    A way to resolve the domain controller Adobe Acrobat Reader to open with the right hand "Interface" in the closed position - really annoying to have to close ALL THE TIME.

    Read this:

    https://forums.Adobe.com/thread/1817184?start=120&TSTART=0

  • Questions about the movement of 1 of 3 ESXi4.1-ESXi5 host domain controllers.

    Is this environment that I have 3 2008 R2 domain controllers.

    1 physical

    2 virtual

    I want to turn off a virtual domain controller and move first host (ESXi 4.1) on second host (ESXi 5).

    My concern is that if the NETWORK card in the guest OS is going to get dirty with or it will remain as it is.

    If I remember not the mac address will indeed change (unless I hard coded it in the configuration file), but that shouldn't be a problem.

    I don't know, what if a new NETWORK card will appear in OS making old useless NIC originally invited me to change the network settings.  Something I don't want to have to do.  I know I've seen a similar problem with a VM linux before, but don't remember seen happen in a virtual Windows machine.  Just want to be sure before that I have to try.

    Thanks in advance for your comments.


    Greg

    VM migration between hosts will make any changes to the NIC or MAC address. You must ensure that the required networking is presented with two hosts if you want to move between them seamlessly. If the network tag is not the same between the hosts, then you will need to change the settings of the virtual machine and use the drop down to select the appropriate network before turning on the new host. But this should be easy and quick and without surprise.

    See you soon,.

    Jon

Maybe you are looking for