3, Headquarters environment preparation3.1Create the first oneDC
Click to start à Run, enter DCPROMO started to install ad Services before Windows Server R2 , using DCPROMO to install ad, to windows Server, it is necessary to install the ad service by adding a role, and then configure the ad service after installation
650) this.width=650; "title=" 01.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/72/ Wkiom1v8323bcdiwaademzbmad8850.jpg "alt=" Wkiom1v8323bcdiwaademzbmad8850.jpg "/>
tick "Use Advanced mode installation ", for similar use of corp.contoso.com as the domain name, we also want the NETBIOS name Contoso , the case, This requires a tick to modify the NETBIOS name, or if we want to install the AD service using IFM in the branch office, there is also a tick, an RODC, etc.
650) this.width=650; "title=" 02.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M00/6E/6E/ Wkiol1v84rjjorvpaah7bzhswl4628.jpg "alt=" Wkiol1v84rjjorvpaah7bzhswl4628.jpg "/>
Default Next
650) this.width=650; "title=" 03.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M00/6E/72/ Wkiom1v8326avcgzaaj3fp4gyhs451.jpg "alt=" Wkiom1v8326avcgzaaj3fp4gyhs451.jpg "/>
tick " create new domain in New Forest "and click Next
650) this.width=650; "title=" 04.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/6E/ Wkiol1v84rnc1jwraafi7cahihy854.jpg "alt=" Wkiol1v84rnc1jwraafi7cahihy854.jpg "/>
Enter the forest root domain FQDN, this test uses robin.com, click Next
650) this.width=650; "title=" 05.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/72/ Wkiom1v8326q3ibvaaeom25mttq707.jpg "alt=" Wkiom1v8326q3ibvaaeom25mttq707.jpg "/>
Domain NetBIOS name is ROBIN, click " next "
650) this.width=650; "title=" 06.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/6E/ Wkiol1v84rmanpnkaafugjxmpcw550.jpg "alt=" Wkiol1v84rmanpnkaafugjxmpcw550.jpg "/>
Choose here Windows Server R2 forest functional level, for the domain forest level where Exchange is installed there is not much to say, click Next
650) this.width=650; "title=" 07.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/72/ Wkiom1v832-jmkz4aahjeeejfjg759.jpg "alt=" Wkiom1v832-jmkz4aahjeeejfjg759.jpg "/>
tick "DNS server ", here we have the idea thatthe GC default is a gray tick state, the following also explains that the first domain control must be a GC, discussed later in the GC
650) this.width=650; "title=" 08.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M00/6E/6E/ Wkiol1v84rqyjbayaagaytaxltu603.jpg "alt=" Wkiol1v84rqyjbayaagaytaxltu603.jpg "/>
Click " Yes "
650) this.width=650; "title=" 09.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M00/6E/72/ Wkiom1v834ld7rzvaad1jspnxac126.jpg "alt=" Wkiom1v834ld7rzvaad1jspnxac126.jpg "/>
Select the database folder, the log file folder, and SYSVOL folder path, default, click Next
650) this.width=650; "title=" 10.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/6E/ Wkiol1v84s2glrglaahle4cxgau434.jpg "alt=" Wkiol1v84s2glrglaahle4cxgau434.jpg "/>
Enter restore password settings and click Next
650) this.width=650; "title=" 11.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/72/ Wkiom1v834lrlk6caagv7k8cjdo880.jpg "alt=" Wkiom1v834lrlk6caagv7k8cjdo880.jpg "/>
Confirm that there is no problem, click Next
650) this.width=650; "title=" 12.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/6E/ Wkiol1v84s3rmkgqaahujxskj1e686.jpg "alt=" Wkiol1v84s3rmkgqaahujxskj1e686.jpg "/>
check here to restart after completion, wait, first the AD was installed successfully
650) this.width=650; "title=" 13.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/6E/ Wkiol1v84s2rqqlnaadyvylv1oo201.jpg "alt=" Wkiol1v84s2rqqlnaadyvylv1oo201.jpg "/>
OK, install successfully, use Administrator to login AD
650) this.width=650; "title=" 14.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/72/wKiom1V834LCM_ 89aaeemmwpdna392.jpg "alt=" Wkiom1v834lcm_89aaeemmwpdna392.jpg "/>
in production, it is recommended not to use Super Admin Administrator, where I create a new Domain Admins SYSADMIN account
650) this.width=650; "title=" 15.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/72/ Wkiom1v834obamnraaexswc1lag545.jpg "alt=" Wkiom1v834obamnraaexswc1lag545.jpg "/>
put The SYSADMIN joins the following groups:Domain Admins, Enterprise Admins, Schema Admins
650) this.width=650; "title=" 16.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M00/6E/6E/ Wkiol1v84s6b8ewwaahx8rpwfai217.jpg "alt=" Wkiol1v84s6b8ewwaahx8rpwfai217.jpg "/>
here, the first one Ad is done, the following deployment of Guangzhou headquarters of the second AD server.
650) this.width=650; "Width=" 720 "height=" 541 "title=" 17.png "style=" width:720px;height:541px; "src="/HTTP/ S3.51cto.com/wyfs02/m00/6e/72/wkiom1v835fjyp3raamsn6sbq0q536.jpg "border=" 0 "vspace=" 0 "hspace=" 0 "alt=" Wkiom1v835fjyp3raamsn6sbq0q536.jpg "/>
3.2Create a second setDC
With regard to domain control, I use a more standard approach here, first joined to the domain, and then promoted to the domain control
650) this.width=650; "title=" 18.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/6E/ Wkiol1v84ulyajphaad0n6uskjg221.jpg "alt=" Wkiol1v84ulyajphaad0n6uskjg221.jpg "/>
Add domain
650) this.width=650; "Width=" 720 "height=" 541 "title=" 19.png "style=" width:720px;height:541px; "src="/HTTP/ S3.51cto.com/wyfs02/m01/6e/72/wkiom1v835erahdgaamvhuorhva751.jpg "border=" 0 "vspace=" 0 "hspace=" 0 "alt=" Wkiom1v835erahdgaamvhuorhva751.jpg "/>
Domain joined
650) this.width=650; "title=" 20.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/6E/ Wkiol1v84ulbunffaadkhyjrk0o012.jpg "alt=" Wkiol1v84ulbunffaadkhyjrk0o012.jpg "/>
The following starts the promotion to domain control, and in the Run box enter DCPROMO
650) this.width=650; "title=" 21.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/72/ Wkiom1v835izhiyfaainy3imtgq099.jpg "alt=" Wkiom1v835izhiyfaainy3imtgq099.jpg "/>
Similarly, check " use Advanced mode installation " here
650) this.width=650; "title=" 22.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M00/6E/6E/ Wkiol1v84ulbiunhaakmyqiol4s894.jpg "alt=" Wkiol1v84ulbiunhaakmyqiol4s894.jpg "/>
Default Next
650) this.width=650; "title=" 23.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M00/6E/72/ Wkiom1v835icfrdsaafhbl8p18y714.jpg "alt=" Wkiom1v835icfrdsaafhbl8p18y714.jpg "/>
tick " existing forest "à" add domain controller to existing domain ", click " next ", the concept of domain forest is discussed at last
650) this.width=650; "title=" 24.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/6E/ Wkiol1v84uodd8swaagf7pj10tq055.jpg "alt=" Wkiol1v84uodd8swaagf7pj10tq055.jpg "/>
Default Next
650) this.width=650; "title=" 25.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/72/ Wkiom1v837kdwjj3aad-jshjokq425.jpg "alt=" Wkiom1v837kdwjj3aad-jshjokq425.jpg "/>
Default Next
650) this.width=650; "title=" 26.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/6E/ Wkiol1v84v3gjvh0aaeudaeqbjk452.jpg "alt=" Wkiol1v84v3gjvh0aaeudaeqbjk452.jpg "/>
Check here DNS Server and global catalog, click " next "
650) this.width=650; "title=" 27.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/72/ Wkiom1v837lhksj3aafyps9astw113.jpg "alt=" Wkiom1v837lhksj3aafyps9astw113.jpg "/>
Click " Yes "
650) this.width=650; "title=" 28.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M00/6E/6E/ Wkiol1v84v3c7ry7aad2cabyzuy399.jpg "alt=" Wkiol1v84v3c7ry7aad2cabyzuy399.jpg "/>
tick " replicate data from an existing domain controller over the network "because in the same LAN as the additional domain controller, there is no need to use media to replicate the data for AD installation, and subsequently in the Shanghai branch, we use the establishment of AD in Shanghai Branch organization by IFM Method
650) this.width=650; "title=" 29.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M00/6E/72/ Wkiom1v837oyxjkzaaira7lszu0533.jpg "alt=" Wkiom1v837oyxjkzaaira7lszu0533.jpg "/>
There is currently only one domain controller, the default next, in the environment with more than one domain controller, you can choose a good network environment or good performance of the server to replicate
650) this.width=650; "title=" 30.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/6E/ Wkiol1v84v7z5aikaahe4r5nnam367.jpg "alt=" Wkiol1v84v7z5aikaahe4r5nnam367.jpg "/>
Default Next
650) this.width=650; "title=" 31.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/6E/ Wkiol1v84v6hq1h6aahwuaj2noq189.jpg "alt=" Wkiol1v84v6hq1h6aahwuaj2noq189.jpg "/>
Enter directory restore password
650) this.width=650; "title=" 32.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M01/6E/72/ Wkiom1v837oq4ot7aag0npknyxg884.jpg "alt=" Wkiom1v837oq4ot7aag0npknyxg884.jpg "/>
Click Next
650) this.width=650; "title=" 33.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/6E/ Wkiol1v84v6duvgyaagyfonhrf0038.jpg "alt=" Wkiol1v84v6duvgyaagyfonhrf0038.jpg "/>
Similarly, tick " reboot after completion "
650) this.width=650; "title=" 35.png "style=" Float:none; "src=" http://s3.51cto.com/wyfs02/M02/6E/72/ Wkiom1v837sbmt-baadi2jkwj34263.jpg "alt=" Wkiom1v837sbmt-baadi2jkwj34263.jpg "/>
to this, the Guangzhou headquarters of the two The AD server is ready to complete.
This article from "Robin's Home" blog, declined reprint!
02Exchange Server 2010 Cross-Site Deployment-HQ AD Preparation