Re: Authenticating to wrong DC

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 11/15/04


Date: Mon, 15 Nov 2004 17:27:24 GMT

The best way to control which dc's a computer/user authenticates to is to
create sites in Active Directory Sites and Services based on subnets and
then by default authentication will first be attempted with domain
controllers in the site/subnet. I believe that a client/computer uses icmp
to find the closest domain controller by response time. You might check the
dns configuration of your clients and add the local domain controller to the
top of the list in the dns preferred servers in tcp/ip to see if that helps
at all. Running the support tool netdiag on a domain computer can show you
the dclist to make sure the domain computer knows where all the domain
controllers are just in case there is a problem with _srv records/dns or
such. You may also want to post in the win2000 or server active_directory
newsgroup. --- Steve

"RichardB" <RichardB@discussions.microsoft.com> wrote in message
news:D2331E27-2EA5-4B42-BF1E-2B14C438AD62@microsoft.com...
> Hello
>
> I have a seperate Domain Controller 600 miles away which most of our Users
> are authenticating to. How do you set it to use the GC here? I thought
> that by default that AD would look at the local Domain controller first.
>
>
> Thanks in advance
> RichardB



Relevant Pages

  • Re: Demote 1st DC Error
    ... "Don Wilwol" wrote in message ... > When a domain controller is demoted, the operational attribute> "GiveAwayAllFsmoRoles" is written, which triggers the domain controller to> locate other domain controllers to offload any roles it currently owns. ... Locate a server to which there is RPC connectivity. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Swing migration Q?: problem joining new DC to temp domain
    ... verify that it points ONLY to itself as it's DNS server. ... Run dcdiag and netdiag on the temp server/domain controller to make sure it ... replication, Group Policy refresh, or domain controller errors. ...
    (microsoft.public.windows.server.sbs)
  • Re: Domain user is seen as domain administrator?
    ... computer where you observe the account has been mapped. ... setting permissions for some folders (in domain controller) for the user ... And yes this user is in Domain Admins group. ... workstation and one exact domain controller. ...
    (microsoft.public.security)
  • RE: Securing a Local Network
    ... In your case windows would the best way to go. ... Linux can function as a domain controller, but as much as I love linux, ... Subject: Securing a Local Network ...
    (Security-Basics)
  • RE: Domain Controller Hardware Failure, remove from AD
    ... to know how to remove a crashed and decommissioned domain controller from ... we use the Active Directory Installation Wizard for ... demoting a domain controller to a member server. ... Settings object that exists as a child of the server object in Active ...
    (microsoft.public.windows.server.active_directory)