Monday, March 14, 2011

Domain and Forest fucntional levels in Windows 2008 server:


Domain Mode Forest Supported Domain Controller by Operating System
Windows 2008 Server Windows 2008 Server Windows 2008 Server
Windows 2000 native Windows 2000 Windows Server 2008,2003,2000
Windows 2003 Server Windows 2003 Server Windows 2003 and 2008 Server

In Windows Server 2008, forest and domain functionality provides a way to enable forest-wide or domain-wide features remove outdated backward compatibility within the environment, and improve Active Directory performance and security Active Directory features.Different levels of forest and domain functionality are available, depending on domain and forest functional level

When the first Windows Server 2008–based Domain Controller is deployed in a domain or forest, the domain or forest operates by default at the lowest functional level that is possible in that environment, meaning Windows 2000 Native Mode. This allows you to take advantage of the default Active Directory features while running versions of Windows earlier than Windows Server 2008. When you raise the functional level of a domain or forest, a set of advanced features becomes available.

After the domain functional level is raised, DCs that are running earlier operating systems cannot be introduced into the domain. For example, if you raise the domain functional level to Windows Server 2008, Domain Controllers that are running Windows Server 2003 cannot be added to that domain.

Unless you still have old NT 4.0 BDCs there's no reason for staying in Mixed Mode, and as you already know, Windows Server 2008 does not support NT 4.0 BDCs, so if you are still using them and planning to upgrade your Active Directory to Windows Server 2008, re-think your strategy.

As for Windows 2000 Native Mode, unless you still have Windows 2000 Domain Controllers, again, there's no reason for staying in that function level. However, if you still do, remember that Windows Server 2008 does only supports Windows 2000 SP4. Be sure to have SP4 on all your Windows 2000 DCs.
Note: Network clients can authenticate or access resources in the domain or forest without being affected by the Windows Server 2003 or Windows Server 2008 domain or forest functional levels. These levels only affect the way that domain controllers interact with each other. However, be aware of the fact that regardless of the domain or function level, servers running Windows NT Server 4.0 are NOT supported by domain controllers that are running Windows Server 2008, meaning you MUST have additional DCs running Windows 2000/2003 to support older NT 4.0 servers.
Domain Function Levels
To activate a new domain function level, all DCs in the domain must be running the right operating system. After this requirement is met, the administrator can raise the domain functional level. Here's a list of the available domain function levels available in Windows Server 2008:

Windows 2000 Native Mode

This is the default function level for new Windows Server 2008 Active Directory domains.

Supported Domain controllers – Windows 2000, Windows Server 2003, Windows Server 2008.

Features and benefits:

Group nesting – Unlike Windows NT 4.0, allows placing of a group of one scope as a member of another group of the same scope.


Universal security groups – Allows usage of Universal security type groups.


SidHistory – Enables usage of SidHistory when migrating objects between domains.


Converting groups between security groups and distribution groups – Unlike Windows NT 4.0, allows converting of a group type into another group type (with some limitations).
Windows Server 2003 Mode

To activate the new domain features, all domain controllers in the domain must be running Windows Server 2003. After this requirement is met, the administrator can raise the domain functional level to Windows Server 2003

Supported Domain controllers – Windows Server 2003, Windows Server 2008.

Features and benefits include all default Active Directory features, all features from the Windows 2000 native domain functional level, plus:

Universal group caching – Windows Server 2003 functional level supports Universal group caching which eliminate the need for local global catalog server.


Domain Controller rename – By using the NETDOM command.


Logon time stamp update – The lastLogonTimestamp attribute will be updated with the last logon time of the user or computer. This attribute is replicated within the domain.


Multivalued attribute replication improvements – Allows incremental membership changes, which in turn enables having more than 5000 members in a group and better replication capabilities.


Lingering objects (zombies) detection – Windows Server 2003 has the ability to detect zombies, or lingering objects.


AD-integrated DNS zones in application partitions – This allows storing of DNS data in AD application partition for more efficient replication.


Users and Computers containers can be redirected – This allows the redirection of the default location of new users and computers (by using the REDIRUSR and REDIRCMP commands).


Support for selective authentication – Makes it possible to specify the users and groups from a trusted forest who are allowed to authenticate to resource servers in a trusting forest.
Windows Server 2008 Mode

To activate the new domain features, all domain controllers in the domain must be running Windows Server 2008. After this requirement is met, the administrator can raise the domain functional level to Windows Server 2008.

Raising the domain and forest functional levels to Windows Server 2008 is a nonreversible task and prohibits the addition of Windows 2000–based or Windows Server 2003–based Domain Controllers to the environment. Any existing Windows 2000–based or Windows Server 2003–based Domain Controllers in the environment will no longer function, and in fact, the upgrading wizard will not allow you to continue with the operation. Before raising functional levels to take advantage of advanced Windows Server 2008 features, ensure that you will never need to install domain controllers running Windows 2000-based or Windows Server 2003–based Domain Controllers in your environment.

Supported Domain controllers – Windows Server 2008.

Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:

Fine-grained password policies – Allows multiple password polices to be applied to different users in the same domain.


Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.


Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.


Granular auditing – Allows history of object changes in Active Directory.


Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.


Last Interactive Logon Information – Displays the time of the last successful interactive logon for a user, from what workstation, and the number of failed logon attempts since the last logon.
Forest function levels
Forest functionality activates features across all the domains in your forest. To activate a new forest function level, all the domain in the forest must be running the right operating system and be set to the right domain function level. After this requirement is met, the administrator can raise the forest functional level. Here's a list of the available forest function levels available in Windows Server 2008:

Windows 2000 forest function level

This is the default setting for new Windows Server 2008 Active Directory forests.

Supported Domain controllers in all domains in the forest – Windows 2000, Windows Server 2003, Windows Server 2008.

Windows Server 2003 forest function level

To activate new forest-wide features, all domain controllers in the forest must be running Windows Server 2003. Read my "Raise Forest Function Level in Windows Server 2003 Active Directory" article for more info about that.

Supported Domain controllers in all domains in the forest – Windows Server 2003, Windows Server 2008.

Features and benefits include all default Active Directory features, plus the following features:

Forest trust.


Domain rename.


Linked-value replication – Changes in group membership to store and replicate values for individual members instead of replicating the entire membership as a single unit.


Deployment of an RODC.


Intersite topology generator (ISTG) improvements – Supports a more efficient ISTG algorithm allows support for extremely large numbers of sites.


The ability to create instances of the dynamicObject dynamic auxiliary class.


The ability to convert an inetOrgPerson object instance into a User object instance, and the reverse.


The ability to create instances of the new group types, called application basic groups and Lightweight Directory Access Protocol (LDAP) query groups, to support role-based authorization.


Deactivation and redefinition of attributes and classes in the schema

Friday, March 11, 2011

Global catalog network ports

Here I have specified which are ports are using by global catalog server.



Global catalog in active directory

     Global catalog is a centralized and distributed data repository;

It contains searchable and partial representation of every object in every domain in the forest.

It stored on a domain controller, it has been designated as global catalog server and is distributed by
multimaster replication.

If we search the active directory objects that are redirected to the global catalog, because it is faster, it
does not involve referral to different domain controller.

It has ability to locate objects from any domain without having to know the domain name.

The global catalog updated and built automatically by active directory.

For optimize search, we can edit the schema by adding and removing attributes that are stored in global
catalog.

In single domain forest, global catalog server stores a full and writable replica of the domain. It does not
store partial data.

                                    I will post more details in the upcoming articles.

Wednesday, March 9, 2011

Active Directory network ports


                The below image show, which are the network ports are being used by active directory functionalities’.
Active Directory Network Ports

How to block Gmail on sonicwall firewall, not Google apps - solved


                 If you want to block Gmail on sonicwall firewall, most of the people try to add the urls. But it won’t block, because it block domain only. If you want allow Google apps and block gmail. Better need to add keyword /mail in the keyword blocking. For more info refer this link Block gmail Sonicwall

Tuesday, March 8, 2011

Windows Deployment Services – Changes from RIS (Remote Installation Services)


RIS is a predecessor of windows deployment services. It has some of lot improvements in this version.

I)                    Here GUI that allows us to select and deploy images and to mange windows deployment services server and clients.

II)                  It has higher performing and extensible PXE server.

III)                It can transfer data and images by using multicast namespace on a standalone server.

IV)               A new boot menu format for selecting the boot images.

V)                 It can transfer data and images by using multicast transmission.

VI)               It can deploy windows 2008 and vista operating system. Windows PE is the boot OS, it uses image based installation using .wim file.  

Windows Deployment services – Server functionalities (windows 2003):-

                         In windows Deployment services there are three server modes (roles). These modes determine the image format, boot environment and administration experience. To check the operating mode in WDS, from the command prompt WDSUTIL /get-server /show:config , above command output displays the server mode(role).



Native Mode:

                In native mode we can deploy only .wim images only. To enable native mode, install and configure WDS on a server that has RIS Installed but should not configure it. If already configured need to uninstall and reinstall before configuring windows deployment services.

Legacy Mode:

                Legacy mode environment used generally, if you do not have windows vista in the environment. For this mode install and configure RIS and then install Windows deployment services (but should not configure).

Mixed Mode:

                In Mixed mode environment we can deploy RISETUP and RIPREP images type using OSChooser and also can deploy .wim based images by using WDS management tools. For mixed configuration, configure Windows deployment services on existing RIS configuration.


Web Hosting