What's the best approach


in forest lot of domains , sites, when dcs domain cannot "talk" other dcs but dcs master domain (first domain of forest), what's best approach regarding replications :

- use of kcc and smtp instead of rpc ?

- disable kcc , set replications manually ?

to more specific : (dc in domain 1) can replicate b, b can replicate c (dc in domain 2) c cannot replicate because of security in place. b = dc of master domain in fores (domain 0). kcc tends create replication links c or c a. , yes, site links replications between dc of same domain. 1 dc replicates dc domain 0.

besides basl marcin , florian pointed out, want stop dc's covering other sites if unreachable clients.  need prevent these dc's registering service records on other sites.  have article assist this.

http://www.pbbergs.com/windows/articles.htm

select prevent dc's registering service records

 

--
paul bergson
mvp - directory services
mcitp: enterprise administrator
mcts, mct, mcse, mcsa, security+, bs csci
2008, vista, 2003, 2000 (early achiever), nt4
microsoft's thrive pro of month - june 2009
http://www.pbbergs.com    twitter @pbbergs

please no e-mails, questions should posted in newsgroup this
posting provided "as is" no warranties, , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...