|
| |||||||||
| Tags: active directory, password replication policy, rodc, setup |
![]() |
| | Thread Tools | Search this Thread |
|
#1
| |||
| |||
| RODC no prp
Does it make sense to setup a RODC in a remote office if there is no password replication policy in place? it seems like if there is no prp, then the RODC doesnt really do much accept pass authentication requests back to a RWDC |
|
#2
| |||
| |||
| Re: RODC no prp
It would depend on how many users at the remote office. If more than 10, I would say yes, go ahead. This will elimnate WAN authentication and logon traffic. Replication traffic for the RODC will be considerably less than authentication and logon traffic. |
|
#3
| |||
| |||
|
you still somewhat benefit from having a local domain controller (even though a writable replica needs to be involved in computer/user authentication) - e.g. due to ability to process Group Policies without resorting to WAN access or faster name resolution assuming that RODC is also configured as a DNS server... I would use also the password replication and make the DC also DNS server, so you can limit the WAN traffic at all. |
|
#4
| |||
| |||
|
I would consider stating which users at the branch office to retain the passwords and make sure none of those are admins. Yes there is much value in not keeping passwords on board the rodc. For starters if someone steels your dc (rwdc) it has all the secrets within it, an rodc doesn't. That is why it was built, to protect remote sites and/or (Details coming soon) dmz's. correct but troubles will hunt you as soon as the RWDC is not accessible for whatever reason |
|
#5
| |||
| |||
| Re: RODC no prp
We have an RODC site in 4 of our Barch offices. The issue is that in everyone of these sites users complain that there is considerable delay in logon. This is not an issue in branch offices which have a RWDC. We decided to configure PRP for all the branch office users but that has not helped. Has anyone else experiancing this or has experianced this with RODC's? Thanks. |
![]() |
|
| Thread Tools | Search this Thread |
| |
Similar Threads for: "RODC no prp" | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Rodc | aconti | Active Directory | 3 | 02-11-2009 06:53 PM |
| RODC | southpaw | Active Directory | 4 | 18-10-2009 08:38 PM |
| RODC DNS in DMZ | Jim | Active Directory | 2 | 15-10-2009 02:53 AM |
| Rodc ... | southpaw | Active Directory | 3 | 07-10-2009 10:28 PM |
| RODC | Kerry | Active Directory | 4 | 30-07-2009 01:05 PM |