Discussion:
location of policy
(too old to reply)
Tony WONG
2010-02-09 03:34:41 UTC
Permalink
i have 2 networks connecting together by leased line, each with a Windows
2003 server
domain controller running on same domain.

Network A - large network about 80 pcs
Network B (remote office) - small network about 20 pcs

i work in Network A, when i put up group policies

All policies are located in domain controller in Network B (remote office)

i wonder there is speed problem updating workstation group policy,

in fact when i update policy, the update speed seems not a local network
speed.

i think policy should be saved in both controllers and workstation should
look for policy in nearest controller, but most of the times, workstations
go to remote office for policy. i do not find domain controller in network
A is very busy.

Grateful for any ideas.

Thanks.

tony
Florian Frommherz [MVP]
2010-02-09 06:59:50 UTC
Permalink
Howdie!
Post by Tony WONG
All policies are located in domain controller in Network B (remote office)
i wonder there is speed problem updating workstation group policy,
In fact Group Policy is replicated among the domain controllers as all
portions (GPC and GPT) are located on replicated places, that are Active
Directory and SYSVOL. So, when changing or creating a GP, replication
carries those changes out to all DCs of the domain.
Post by Tony WONG
in fact when i update policy, the update speed seems not a local network
speed.
What update speed? When clients apply the policies?
Post by Tony WONG
i think policy should be saved in both controllers and workstation should
look for policy in nearest controller, but most of the times, workstations
go to remote office for policy. i do not find domain controller in network
A is very busy.
Those policies indeed should be located on both domain controllers. I'd
go check on that and probably verify that both DCs have valid domain and
GPO data (and that replication is working). From that point, it is all
AD configuration. If clients go query a remote DC for authentication and
Group Policy (how did you learn that?) you should have a look into your
AD Sites&Services configuration. The underlying config is used to when
DCs advertise themselves in DNS in sites ... and that DNS information is
used by clients to find the nearest DC.

Cheers,
Florian

Loading...