Deploying member servers using DirectAccess

I'm putting together a relatively small Server 2012 R2 network, using Direct Access and an external member server running SharePoint.
The pictorial below best shows what the plans is:
To clarify, four servers at Head Office with 2x DC's, Exchange server and an Application server (not important). One server running SharePoint at the external branch office, with clients connecting remotely to both offices. There
also internal clients at both premises. These servers are to deliver mail and SharePoint access for
all clients both internal and external.
What I am trying to understand is how to best have the member server communicate with the DC's for GPO updates, remote management and SharePoint permission structures, which is governed by active directory users and groups. It appears that Server
2012 member servers cannot act as clients in the way that Windows 8 does with Direct Access. I guess I'm looking for the best advice on how to set this up. 
Many thanks in advance
MIS5000

Yes, that sounds like quite a fun project :)
You can definitely utilize your SBS as the Domain Controller, I have installed Server 2012 and Server 2012 R2 DirectAccess into environments that are SBS2003, and it works just fine. There are no schema requirements for DirectAccess itself, I actually have
it running in a Server 2003, Active Directory 2000 Mixed Mode environment just to show that it works.
Since DirectAccess does rely on domain connectivity and those GPOs to distribute settings, you will probably hit some bumps in the road when you cut over to your new DCs. However, it's quite quick and easy to setup DirectAccess in the first place, once you
have the server prepped accordingly, and so even in a worst-case scenario, if your current DirectAccess server isn't happy after the DC switch, you could just wipe off the Remote Access role, reinstall the role, and walk back through the configuration wizards
to setup the environment again.
If you're ever interested in learning a bit more about DA itself, there are a couple of books out on the subject (not trying to self-promote, but questions on the forums are the primary reason why I put together this book in the first place):
https://www.packtpub.com/virtualization-and-cloud/microsoft-directaccess-best-practices-and-troubleshooting
https://www.packtpub.com/networking-and-servers/windows-server-2012-unified-remote-access-planning-and-deployment

Similar Messages

  • Create Local Group on Member Servers

    Guys,
    I have put together below script (thanks to everyone for posting great scripts). I have copied some part of the script from the forum examples.
    This script will take Input, create Domain group and add that domain group to the number of member servers listed in the text file.
    So far so good, my this script works fine. 
    Question - I need to add functionality in the script to create new local group on member servers using same variable and Add the Domain group (created using same variable) in the newly created local group on member servers.
    I also want to have an output file for the failed hosts. 
    Appreciate your help.
    ==============================================
    # input
    $Name = Read-Host "Write Policy Name"
    #Create Domain User Group
    NEW-ADGroup -Name ${Name}_UserGroup –groupscope Global -path "ou=Test,DC=Lab,DC=Local" -Description "${Name} Domain users Group"
    #Read Servers from the Text File
    $Servers = Get-Content c:\temp\${Name}_Servers.txt
    #Initialize the Domain Group Object 
    $DomainGroup = [ADSI]"WinNT://Lab.local/${Name}_usergroup,group"
    #Add Domain group to the local Remote Desktop Group on member servers
    ForEach ($Server in $Servers) #Loop through each server 
        #Get Local Group object 
        $LocalGroup = [ADSI]"WinNT://$Server/Remote Desktop Users,group" 
        #Assign DomainGroup to LocalGroup 
        $LocalGroup.Add($DomainGroup.Path)
    ==============================

    You don't need scripts to manage local groups.
    Group Policy can do this for you.
    -- Bill Stewart [Bill_Stewart]

  • Just FYI, new blog post "Deploy BranchCache Content and Hosted Cache Servers Using Windows PowerShell"

    Just FYI, new blog post "Deploy BranchCache Content and Hosted Cache Servers Using Windows PowerShell" at
    http://aka.ms/le85n3
    Thanks -
    James McIllece

    Great to see new BranchCache content out there!
    We created a BranchCache info page to try to get all of the relevant info into one place for V1 and 2
    http://2pintsoftware.com/microsoftbranchcache
    thanks
    Phil
    Phil Wilcock http://2pintsoftware.com @2pintsoftware

  • [svn:bz-trunk] 17920: Fix for WebLogic: WebLogic does not provide File IO on the deployed artifacts hence using getResourceAsStream .

    Revision: 17920
    Revision: 17920
    Author:   [email protected]
    Date:     2010-09-29 05:56:06 -0700 (Wed, 29 Sep 2010)
    Log Message:
    Fix for WebLogic: WebLogic does not provide File IO on the deployed artifacts hence using getResourceAsStream.
    Modified Paths:
        blazeds/trunk/apps/samples/WEB-INF/src/flex/samples/marketdata/Portfolio.java

    check the server log;
    /app/oracle/product/fwm11g/user_projects/domains/fwm_domain/servers/AdminServer/logs/AdminServer.log
    you can launch the console and see if it is running; http://<server>:<port>/console

  • Moving member servers without DC

    Hi
    I have recently been asked to move some server's (running windows server 200 and windows server 2003 r2) to a new site as the old site is being decommisioned, the DC's will be decomm'd, as the legacy data will only be required for reference purposes and
    the business is closing down, as the company is being closed down. 
    The DC's run DNS, DHCP and ADDS.
    The servers that will be moved are purely application servers, I was wondering what would happen when the DC's are powered off? Will the member servers still function and communicate, also the time server is one of the DC's, how will this affect the retrieval
    of data from the member servers.
    Thanks
    Gin 

    The servers that will be moved are purely application servers, I was wondering what would happen
    when the DC's are powered off? 
    If I understand well, the DCs will be decommissioned and the domain will no longer exist. If this is the case then you will need to disjoin these servers from the domain to avoid false positive alerts in the logs and so that you can do the things in the
    correct way.
    About the impacts on your application servers, you need to know their dependencies and relation with AD. If you have an AD based application then it will no longer work. You need to check each of these applications and do the assessment of the impacts. A
    test environment would help and contacting the application developers / support would be helpful too.
    Will the member servers still function and communicate, also the time server is one of the DC's,
    how will this affect the retrieval of data from the member servers.
    About which data are you speaking? You need to check the requirements for your applications.
    As for the time sync, you need to think about hosting an internal NTP server that is in sync with external ones or simply make all your servers point to external NTP servers for time sync as you will no longer have DCs.
    The servers will hold data and the legacy application, without the DC's will the servers boot up
    and be able to talk to each other, also what happens with the time synchronisation when there's no DC available. 
    They will be able to boot and use the cached credentials for authentication. For the time sync, it will no longer work as your DCs will be no longer available.
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • I have an iPhone 4 and an iPod 4th gen linked to the same email address and apple ID. I am trying to set up a new email address for the iPod so a family member can use it but it doesn't want to recognize the new email account. Where am I going wrong?

    I have an iPhone 4 and a 4th gen iPod linked to the same email address and apple ID. I am trying to change the email address on the iPod so a family member can use it but when I do it says it doesn't recognize the email address. Where am I going wrong ? I just want them to be able to iMessage and email without having to use my email address.

    The procedure is Settings>Messages>Send & Receive at>You can be reached by iMessages at>Add another email address. The email address has to be a valid working email address, obviously. Apple should verify the email address and you have to go to the inbox of that email account, read the verification email from Apple and follow the inductions in the email in order to complete the verification. Then you go back to the settings, uncheck your email address and check the new email address to be used as the contact email address.

  • How do I transfer a site to another member to use?

    How do I transfer a site to another member to use?

    http://forums.adobe.com/community/download_install_setup/creative_cloud_faq
    -has a link to manage your membership which may help

  • Creative cloud for teams administration how do i see how much cloud storage each team member is using

    Can i see the file storage usage for each member and what apps they have downloaded?

    Although i am totally for the collaboration features, they seem to have nothing to do with the creative cloud for teams. However, before the new updates, i could go into the manage teams area and see how much cloud space each member was using. I'm not asking to see another team member's files, i'd just like to know how much is being used for resource allocation purposes.  I'd also like to know what apps they have downloaded. No? Just to wipe out one user and assign to another user isn't really what i'm after.

  • Unknown site error while deploying web services using OC4J

    Hi,
    I have been testing the deploying webservices examples using demo.zip on OTN site.
    I have trouble in binding the web application name to stand alone OC4J.
    I am running stand alone OC4J server fine. I verified the website http://localhost:8888, which is running fine.
    If I issue the command
    java -jar admin.jar ormi://localhost:23791 admin password1 -bindwebapp demo_ejb_web_service HelloService_web http://localhost:8888/ sejb_webservices
    I get error
    oracle.oc4j.admin.internal.DeployerException: Unknown site: http://localhost:8888/
    What is the http-web-site address that needs to be given for binding web app, if I am running local standalone OC4J with no default port changes?
    Thanks,
    Mohan

    Eric,
    Thanks for the response. But, still I am not able to bind web-application to OC4J.
    Here is how my server.xml has defined the web-site tag:
    <web-site default="true" path="./http-web-site.xml" />
    My http-web-site.xml has following web-site tag:
    <web-site port="8888" display-name="OC4J 10g (10.0.2) HTTP Web Site">
    <default-web-app application="default" name="defaultWebApp"/>
    <web-app application="default" name="dms0" root="/dms0" access-log="false" />
    <web-app application="default" name="dms0" root="/dmsoc4j" access-log="false" />
    <web-app application="default" name="admin_web" root="/adminoc4j"/>
    <access-log path="../log/http-web-access.log"/>
    </web-site>
    I used the following command to bind the example web service:
    java -jar c:\XtendTools\oc4j\j2ee\home\admin.jar ormi://localhost admin password1 -bindWebApp demo_ejb_service HelloService_web default-web-site /sejb_services
    I get "oracle.oc4j.admin.internal.DeployerException: Unknown site: default-web-site" error.
    I tried to use following names as http-web-site, but nothing works.
    "http://localhost:8888"
    "dms0"
    "adminoc4j"
    I downloaded stand alone OC4J 10.1.2 from OTN and tried these samples.
    Your help will be appreciated.
    Thanks,
    Mohan

  • HT3529 I am currently deployed and was using my iMessage to be able to talk to family back in the states and my iMessage stopped working. It will no longer select my number to use as the send/receive. How do I fix this so I can continue to talk to family?

    I am currently deployed and was using my iMessage to be able to talk to family back in the states and my iMessage stopped working. It will no longer select my number to use as the send/receive. How do I fix this so I can continue to talk to family?

    Read here:
    http://support.apple.com/kb/TS2755

  • Using one public ip for ssh`ing to different internal servers using port-redirections

    Hi, we are having a requirement to use the same public IP to ssh into different internal servers using port re-direction. So lets say from outside, if a user does ssh @ root 4.4.4.4 2222, it should go to a sshsrv1 and then ssh @ root 4.4.4.4 2223 to sshsrv2
    My config is like this:-
    object network sshsrv1
    host 10.110.100.10
    nat (inside,Outside) static 4.4.4.4 service tcp 22 2222
    And then i allowed the object "sshsrv1" in my inbound acl from outside.
    It dosen`t seem to work. Is this doeable?
    Any suggestions??

    Hi,
    Would need to see your NAT configurations.
    There is a possibility that you have a NAT configuration that might be preventing this from working. Then again you are using an extra public IP address for this so it seems strange.
    Could you try the "packet-tracer" command
    packet-tracer input outside tcp 12345 2222
    This should tell us if there is some problem in the ASA configurations.
    - Jouni

  • Avoiding creation of DBlink during deployment of mappings using OMBPlus

    Hi
    we are facing an issue in our OWB 11g R2 (upgraded to patchset 10185523)
    We are deploying the mappings using OMBPlus like so
    OMBCREATE TRANSIENT DEPLOYMENT_ACTION_PLAN 'DEPLOY_PLAN' ADD ACTION '$object_type_DEPLOY' SET PROPERTIES (OPERATION)VALUES ('CREATE') SET REFERENCE $object_type '$objname'
    OMBDEPLOY DEPLOYMENT_ACTION_PLAN 'DEPLOY_PLAN'
    set OMBCONTINUE_ON_ERROR true
    OMBDROP DEPLOYMENT_ACTION_PLAN 'DEPLOY_PLAN'
    OMBCOMMIT
    The $objname is any object(in this case a mapping) that we are deploying
    OMBPlus generates a script on OWB level to create the associated DBlink each time it deploys a mapping and we get an error
    INFORMATIONAL
    multiple rows found for select into statement
    DBlink_a Create Error ORA-02011: duplicate database link name
    But the mapping deploys fine.
    Any tips how we can avoid creation of dblinks from OMBPlus whilst deploying our mappings only?
    Any help will be appreciated
    Birdy
    Edited by: birdy on 22-Nov-2011 05:22

    I dont think that you can:
    "Deploying a mapping or a process flow includes these steps:
    •Generate the PL/SQL, SQL*Loader, or ABAP script, if necessary.
    •Register the required locations and deploy any required connectors. This ensures that the details of the physical locations and their connectors are available at runtime."
    http://www.comp.dit.ie/btierney/Oracle11gDoc/owb.111/b31278/concept_deploy.htm
    But error that you get is only informational so you dont have to worry about it.

  • I want to deploy an application using firefox but I don't want it set as default browser. I am using mozilla.cfg to lockdown firefox.

    I am deploying an application using firefox. I am using the mozilla.cfg file to lockdown firefox and I don't want firefox to be the default browser.

    Try the option to "Force Firefox to make itself the default" as shown in this article - http://kb.mozillazine.org/Default_browser
    Another possibility is your email application may be hard-coded to use IE.

  • Deploying WAR file using IAS Test Drive edition...

    Hi:
    Is it okay to deploy a build using a WAR file instead of an EAR file? Is
    there any documentation for deploying WAR files? All the available docs and
    examples start with EAR files.
    Thanks,
    George

    Hi,
    A war file is okay if you are using servlets & JSP, WAR means Web Archive.
    So you can very well go ahead with a war file, incase you are thinking of EJB's
    then a .ear file will help you.
    Regards
    Raj
    George Sang wrote:
    Hi:
    Is it okay to deploy a build using a WAR file instead of an EAR file? Is
    there any documentation for deploying WAR files? All the available docs and
    examples start with EAR files.
    Thanks,
    George

  • Running a Select query against multiple sql servers using SSIS script task.

    Hi Guys,
    I need to fetch data from multiple sql servers using  SSIS scirpt task inside a foreach container.
    is there anyway i can build dynamic sql connections using ssis variables inside SSIS script task in each loop
    Please guide me or refer any blogs so that i will try..
    Thanks in advance.

    Your only options is using .net code, then it will be no different than using a console app in a loop.
    using (SqlConnection connection = new SqlConnection(connectionString))
    connection.Open();
    Console.WriteLine("ServerVersion: {0}", connection.ServerVersion);
    Console.WriteLine("State: {0}", connection.State);
    and so forth for each connection string
    the connection string would come from the ForEach loop
    Arthur My Blog

Maybe you are looking for

  • Trying to understand the basic concept of object oriented programming.

    I am trying to understand the basic concept of object oriented programming. Object - a region of storage that define is defined by both state/behavior. ( An object is the actual thing that behavior affects.) State - Represented by a set of variables

  • 5/13/2014 - Release - Flash Player 13

    The next version of Flash Player is available for immediate download.  In today's release we've updated Flash Player with important security updates and bug fixes.  We recommend users update to the latest version. With today's release, we have also u

  • Turning off the Driving Mode Announcement.

    I turned on driving mode on my Lumia 928 and now everytime I get into the car it announces: "I have turned on Driving Mode for you."  It has become real tiring.  How do you turn it off???  I have searched with no luck, please help. dwf1234

  • Creating a web template

    Hi All, My client asked me to create a web template for their web reports. They gave me their logo and asked me to include it on every web report as header. Also, they gave me the fonts and colors of the report headers and normal data and the footer

  • EPM Services status check

    Hi, I would like to know how to check the status of EPM services without logging in to the Weblogic console. EPM version is 11.1.2.3. For example, I can start/stop the Foundation Services using EPM_ORACLE_INSTANCE/bin/startFoundationServices.sh or st