Hello,
I'm currently planning an environment which will survive any disaster 
like domain controller crash:
     PDC02
       |
      VPN
       |
     switch
    |      |
PDC01 client01
PDC01 and PDC02 are domain controllers, and have identical smb.confs.
client01 is a client, has WINS servers set to PDC01 and PDC02.
users / passwords are replicated using LDAP.
Now, under normal operations, clients is authenticated against PDC01 
which is in the same LAN, downloads profile, works, logs off, profile is 
updated.
But when I switch PDC01 off, user can authenticate against PDC02 over 
VPN, but the roaming profile is not transferred after he/she logs out.
Does anyone have any explanation?
PDC01 and PDC02 have *identical* configurations - the only difference is 
that PDC02 is behind a VPN.
Tomek
Tomasz Chmielewski wrote:> Hello, > > I'm currently planning an environment which will survive any disaster > like domain controller crash: > > PDC02 > | > VPN > | > switch > | | > PDC01 client01 > > > PDC01 and PDC02 are domain controllers, and have identical smb.confs. > > client01 is a client, has WINS servers set to PDC01 and PDC02. > > users / passwords are replicated using LDAP. > > > Now, under normal operations, clients is authenticated against PDC01 > which is in the same LAN, downloads profile, works, logs off, profile is > updated. > > But when I switch PDC01 off, user can authenticate against PDC02 over > VPN, but the roaming profile is not transferred after he/she logs out. > > Does anyone have any explanation? > > PDC01 and PDC02 have *identical* configurations - the only difference is > that PDC02 is behind a VPN.It seemed all I have to do was to switch from using tun devices to tap devices in my OpenVPN setup... Tomek
Apparently Analagous Threads
- Recently joined 2k3, shut down primary, seized roles, now have slight dns (maybe) problem.
- ADS Authentication - CLDAP request failed
- smbclient -M
- Samba suddenly restart and replication does not works anymore
- Samba suddenly restart and replication does not works anymore