PC Review


Reply
Thread Tools Rate Thread

Active Directory Test Environment

 
 
=?Utf-8?B?SGFycHJlZXQgU2lkaHU=?=
Guest
Posts: n/a
 
      30th Mar 2005
Hi,

I am trying to build a test environment that mimics the production
environment, I have tried a couple of scenarios to do this but neither has
worked too well. Goal is to replicate the entire schema and the AD data in
the test environment. Here is what I have tried:

1. Tried to do a bare metal recovery of the DC holding all 5 FSMO roles in
the authoritative domain using Tivoli on to a test box by following the
outlined procedures from IBM and that did not work at all.

2. Created a child domain under the forest but then the problem is that it
is not a TRULEY isolated test environment.

3. Created an isolated environment and used a product called SimpleSync
which worked great and brought in all the data but it was a trial version and
the real version costs several thousand dollars.

What I was wondering was if ldifde or csvde are able to dump the entire
directory data ALONG with the schema then i could import that in my test
environment and may be even make the procedure into a script so the test is a
day behind the production data. Can someone please recommend a simple or
RIGHT way of achieving this task. The test network is to have NO visibility
to the production network but the production network does have access on the
test network. A have put in a small firewall to separate the two with inbound
rules from certain IPs over certain ports.

Any help or direction would be greatly appreciated.

Thanks
 
Reply With Quote
 
 
 
 
Ryan Hanisco
Guest
Posts: n/a
 
      31st Mar 2005
Try this:

1. Create a member server in the domain.
2. Promote it to a Domain Controller in your domain
3. Move it to your isolated test environment -- and never allow it back
4. Seize all FSMO roles with NTDSUTIL
5. Remove all DC remnants with NTDSUTIL Metadata Cleanup

You should be in business. Take care with DNS too... You'll be ok if its AD
integrated, but if its not, make it a secondary, and promote it to primary
once it is segregated.

DO NOT be tempted to "update" it later to get new changes to the environment
by allowing these to be on the same network.
--
Ryan Hanisco
MCSE, MCDBA
FlagShip Integration Services
Chicago, IL

"Harpreet Sidhu" <(E-Mail Removed)> wrote in message
news:5250885C-8D4B-4ED7-95EF-(E-Mail Removed)...
> Hi,
>
> I am trying to build a test environment that mimics the production
> environment, I have tried a couple of scenarios to do this but neither has
> worked too well. Goal is to replicate the entire schema and the AD data in
> the test environment. Here is what I have tried:
>
> 1. Tried to do a bare metal recovery of the DC holding all 5 FSMO roles in
> the authoritative domain using Tivoli on to a test box by following the
> outlined procedures from IBM and that did not work at all.
>
> 2. Created a child domain under the forest but then the problem is that it
> is not a TRULEY isolated test environment.
>
> 3. Created an isolated environment and used a product called SimpleSync
> which worked great and brought in all the data but it was a trial version
> and
> the real version costs several thousand dollars.
>
> What I was wondering was if ldifde or csvde are able to dump the entire
> directory data ALONG with the schema then i could import that in my test
> environment and may be even make the procedure into a script so the test
> is a
> day behind the production data. Can someone please recommend a simple or
> RIGHT way of achieving this task. The test network is to have NO
> visibility
> to the production network but the production network does have access on
> the
> test network. A have put in a small firewall to separate the two with
> inbound
> rules from certain IPs over certain ports.
>
> Any help or direction would be greatly appreciated.
>
> Thanks



 
Reply With Quote
 
=?Utf-8?B?SGFycHJlZXQgU2lkaHU=?=
Guest
Posts: n/a
 
      31st Mar 2005
That is definetly an idea worth trying, the only hitch is that I would not be
able to keep the two envrionments in "sync" as I had wanted to for obvious
reasons. Maybe after I set it up this way I could do active directory
restores maybe once a month to try to keep the data somewhat fresh.

Our dns is Ad-integrated so that should be ok, I am also going to try using
NT-backup/restore as suggested in
http://support.microsoft.com/Default.aspx?kbid=249694

I doubt this will work but will let everyone know either way. Thanks for the
idea on introducing a member server and promoting it I will try that out as
well and share the results.

Thanks,
Harpreet

"Ryan Hanisco" wrote:

> Try this:
>
> 1. Create a member server in the domain.
> 2. Promote it to a Domain Controller in your domain
> 3. Move it to your isolated test environment -- and never allow it back
> 4. Seize all FSMO roles with NTDSUTIL
> 5. Remove all DC remnants with NTDSUTIL Metadata Cleanup
>
> You should be in business. Take care with DNS too... You'll be ok if its AD
> integrated, but if its not, make it a secondary, and promote it to primary
> once it is segregated.
>
> DO NOT be tempted to "update" it later to get new changes to the environment
> by allowing these to be on the same network.
> --
> Ryan Hanisco
> MCSE, MCDBA
> FlagShip Integration Services
> Chicago, IL
>
> "Harpreet Sidhu" <(E-Mail Removed)> wrote in message
> news:5250885C-8D4B-4ED7-95EF-(E-Mail Removed)...
> > Hi,
> >
> > I am trying to build a test environment that mimics the production
> > environment, I have tried a couple of scenarios to do this but neither has
> > worked too well. Goal is to replicate the entire schema and the AD data in
> > the test environment. Here is what I have tried:
> >
> > 1. Tried to do a bare metal recovery of the DC holding all 5 FSMO roles in
> > the authoritative domain using Tivoli on to a test box by following the
> > outlined procedures from IBM and that did not work at all.
> >
> > 2. Created a child domain under the forest but then the problem is that it
> > is not a TRULEY isolated test environment.
> >
> > 3. Created an isolated environment and used a product called SimpleSync
> > which worked great and brought in all the data but it was a trial version
> > and
> > the real version costs several thousand dollars.
> >
> > What I was wondering was if ldifde or csvde are able to dump the entire
> > directory data ALONG with the schema then i could import that in my test
> > environment and may be even make the procedure into a script so the test
> > is a
> > day behind the production data. Can someone please recommend a simple or
> > RIGHT way of achieving this task. The test network is to have NO
> > visibility
> > to the production network but the production network does have access on
> > the
> > test network. A have put in a small firewall to separate the two with
> > inbound
> > rules from certain IPs over certain ports.
> >
> > Any help or direction would be greatly appreciated.
> >
> > Thanks

>
>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Using Active Directory in XP OS Environment for Access Security OldGrinch Microsoft Access Security 2 9th Sep 2009 04:59 AM
Documenting Active Directory Environment. frank s Microsoft Windows 2000 Active Directory 2 25th May 2006 04:04 PM
Do applemac`s work in an Active Directory environment? Ivor Windows XP Hardware 2 16th Jun 2004 09:18 PM
Active Directory on W2k server within Nt4 environment Ken Microsoft Windows 2000 Active Directory 3 17th Aug 2003 06:31 AM
Re: Printing in a Active directory environment Bruce Sanderson Microsoft Windows 2000 Printing 0 3rd Jul 2003 08:35 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 09:20 PM.