網頁

2012年6月17日 星期日

one-way DFSR on Windows Server 2008 R2 (part 1 of 3)

Recently, I need to confirm DFSR function for one Project verification. Based on this necessity, I have to study DFSR mechanism on 64 bit Windows Server 2008 R2 so that build a environment for testing its function on my lab.
Drawing1The following process summary my testing steps for your reference. In this article, I will introduce the prerequisite of one way DFSR.

TMG 2010 Firewall Rule Setting
Set “Firewall Rule” from DMZ (Server with DFSR Role) to Internal (Server with DFSR Role)  for TCP:135, 445, 24158 (Custom) , 49999 (Custom)
ScreenHunter_11 Jun. 15 19.24Set “Firewall Rule” from DMZ (Server with DFSR Role) to Internal (Server with AD Role) for TCP: 53, 88, 135, 389, 5000~5100 (Custom), 50000 (Custom)
ScreenHunter_10 Jun. 15 19.24Set “Firewall Rule” from Internal (Server with DFSR Role) to DMZ (Server with DFSR Role) for TCP:135, 445, 24158 (Custom) , 49999 (Custom)
ScreenHunter_12 Jun. 15 19.25
Set static RPC for AD Logon/Directory Replication
Add Registry Key and correct value as a single port(50000/TCP). For detailed configuration, please refer to this URL as ADLogon/DirRep setting.
Open firewall port for Computer join Domain & Account logon Domain

Disable Windows Firewall
Turn off Windows Firewall on all Servers with DFSR role
ScreenHunter_07 Jun. 13 15.42
Installing DFS Replication
In Server Manager, click “Roles” ---> “Add Roles” to trigger [Add Roles Wizard]
ScreenHunter_01 Jun. 12 14.57Click “Next >” button if you have already verified the suggestion.
ScreenHunter_02 Jun. 12 15.00Enable “File Services” check box next to click “Next >” button
ScreenHunter_03 Jun. 12 15.11Click “Next >” button
ScreenHunter_04 Jun. 12 15.11Enable “DFS Replication” check box next to click “Next >” button
ScreenHunter_05 Jun. 12 15.13Click “Install” button
ScreenHunter_06 Jun. 12 15.22Click “Close”button if the installation succeeded.
ScreenHunter_07 Jun. 12 15.24So dose that it also install the DFS Management Console(dfsmgmt.msc) with MMC snap-in in the feature of Server Manager.
ScreenHunter_09 Jun. 12 15.43
Configure DFSR to a Static Port
By running the DFSRDIAG STATICRPC command on the DFSR Server as VBHV-FS-01, the DFSR RPC listening port will be forced on a static port as TCP/49999.
ScreenHunter_01 Jun. 15 18.04After finish the above activity, please remember to restart “DFS Replication Service” again.
ScreenHunter_06 Jun. 13 15.22


Set a Fixed Port for WMI
By executing the command on the console of DFSR role servers as VBHV-FS-01 & VBHV-FS-11 to set a fixed port as TCP/24158 for WMI


Until now, I have already finish the related prerequisite for DFSR. In next article, I will introduce the configure and setup DFSR mechanism.

沒有留言:

張貼留言

Since 2010 Design by Davidwa
©Copyright Davidwa Inc. All rights reserved.