70-219 - Windows 2000/2003 Network Design

by James Ellithorpe

Introduction to Network Design
The Three Faces of Network Design
Planning Migration Strategies
Select the Migration Type
  Domain Upgrade
  Domain Restructure
  Domain Upgrade Only
  Domain Restructure Only
  Domain Upgrade, Then Restructure
Evaluate the Environment for Migration
  Evaluate Current Hardware
    Automatic Method
    Manual Method
  Evaluate Security Implications
    Physical Aspects
    Certificate Services
    Logon Considerations
    DACLs, Rights, and Group Control
    Microsoft Security Configuration Manager
    User and Group Account Security
  Evaluate Application Compatibility
    Manual Inventory of Applications
    Automated inventory of Applications
    Network Services
    Manual Method
    Automated Method
Analyzing Business Requirements
Analyze the Existing and Planned Business Models
Analyze the Structure of IT Management
Analyzing Technical Requirements
Evaluate the Company's Existing and Planned Technical Environment
Analyze the Impact of Active Directory on the Existing and Planned Technical Environment Including Microsoft Exchange 2000 and SQL 2000
Analyze the Business Requirements for Client Computer Desktop Management
Designing a Directory Service Architecture
Define the Scope of the Active Directory
Design an Active Directory Forest and Domain Structure
Design an Active Directory Naming Strategy: WINS and DNS Strategies
Design and Plan the Structure of Organizational Units
Design a Schema Modification Policy
Design the Placement of Operations Masters
Design the Placement of Global Catalog Servers
Design a Replication Strategy
Planning and Deploying a Domain Upgrade
Convert Domains to Native Mode
Perform Test Deployments of Domain Upgrades
Implement Disaster Recovery Plans
Restore Pre-migration Environment
Perform Post-migration Tasks
Planning and Deploying an Intra-Forest Domain Restructure and an Inter-Forest Domain Restructure

Introduction to Network Design

Network design is one of those issues where you must consider the entire "jigsaw puzzle" when beginning the process.

By this time in the Study Guide process, you should have completed the exams for 70-210, 70-215, 70-216, 70-217, and 70-218. This will earn the Microsoft Certified System Administrator (MCSA) credential. If you have not completed these exams, you can continue with the Network Design Study Guide, but those who complete the MCSA will be in a better position to focus their energies toward the MCSE process.

When you complete the three design exams, you can truly call yourself a network engineer. Many candidates take only one of the required design exams, but I feel this is a serious mistake. How can someone ignore two thirds of the network engineering process and consider oneself a network engineer? The simple truth of the matter is: you can't!

The Three Faces of Network Design

Network design must weave Active Directory, Security, and Infrastructure together into a seamless and integrated whole. It must also take into account the client hardware and software applications. The servers must be capable of handling the DNS, WINS, DHCP, RRAS, and Terminal Services as needed. You must consider the number of HOSTS per subnet, and what is acceptable bandwidth for each subnet. Security considerations such as the physical security of the machines, routers, switches, hubs, includes setting up a DMZ to secure the VPN Servers, E-Mail Servers in front of or behind the firewall. The "pea-pod" of security always must be taken into account, and balancing the management and security of the network is a "Goldilocks and the Three Bears" issue of "not-too-hot" and "not-too-cold" but "just right." However, at all times the network must be kept operational.

The point is this. You must take all that you have learned and read up to this point and now begin to apply it in a "thoughtful" manner. As we continue in the next three study guides, we will be demonstrating that process. What you will discover, is that we have been teaching you Network Design from the very first study guide.

However, we will need to look at Network Design from a "holistic" perspective that takes into account network design from a total perspective of Active Directory, Security, and Network Infrastructure. We will attempt to put it all together for you. To do this, we will address specific issues of each major component of the three areas above. Then we will present three "labs" for each of the three areas with three examples for each major component. The labs will present a solution to the lab. However, our solution is not the only correct answer possible. It would just be one of many ways to accomplish the goals. That is the problem with Network Design. There will always be more than one way to reach the goal. What we are looking for here is a process and a conceptual solution, not a precise "one-way" solution. In network design, the "one-way" solution simply does not exist. Finally, we will have the 25 questions for each Study Guide that take you back through the three "labs" with multiple-choice questions.

Planning Migration Strategies

Before beginning work on a Domain upgrade or Restructure, now is a great time to completely document two things: the way the network looks now and the way you want it to look in the future. Why? Well you don't want to take the existing problems (and junk) with you when you migrate to the new infrastructure. Secondly, many times, depending on your job responsibilities, you may know your area very well, but have no idea of what lies beyond the router or switch the servers are plugged into. So, first things first. Do a complete inventory on all the machines in the enterprise (or at the very least, the one's that would be directly affected by the migration). That sounds very simple and straightforward doesn't it? Believe it or not, this might be the most costly part of the migration as far as time and effort on your part. This may include getting other people involved, looking in closets, behind locked doors, and potentially asking some people some uncomfortable questions ("Why DO you have a server in your office, George?"). Always remember to factor this inventory time into the project estimate timings.

We'll talk about the specifics of what the inventory should cover later.

You should also document the proposed Windows 2000/2003 Active Directory domain structure including forest(s), domain(s), organizational units, sites, and DNS Infrastructure, while taking into account whether or not you want to incorporate new functions of Windows 2000/2003 during the migration or later.

When you are to perform a migration from Windows NT, you have two options: Domain upgrading or Domain restructuring. You can look for more information for "Domain Migration Strategies" in the Windows 2000 Server Resource Kit Online Books.

Select the Migration Type

There are only two "basic" approaches to performing a migration: Doing an upgrade or performing a restructure. However, there are variables to consider and sometimes you will mix methods to obtain the best possible results for your situation. Let's look over the concepts of these two methods.

Domain Upgrade

An in-place replacement of Windows NT servers with Windows 2000/2003 servers is defined to be a domain upgrade.

Before speaking specifics about a domain upgrade, why would you choose to do an upgrade vs. other types of migrations? Several reasons come to mind:

The benefits of doing an upgrade include:

However, it does have its disadvantages also:

When we talk about migration to Windows 2000/2003 and we say domain upgrade, what are we usually talking about? We are talking about two things: the order in which the domain(s) are upgraded to Windows 2000/2003 and/or the order of the domain controllers are upgraded. Both have easy answers:

So, when we talk about a domain upgrade, we're talking about taking the existing domain structure, existing servers, existing network services, and existing user accounts and groups and upgrading them, in place, to Windows 2000/2003. In other words, doing an upgrade will take the network as it's defined now and update it to Windows 2000/2003. Another way to look at it is that you REALLY have to like what you have now to choose an upgrade. Various technical web sites are reporting that a very high percentage of companies are choosing to do a domain restructure rather than an upgrade. This allows them to "start from scratch" sort to speak.

What we are normally not talking about is upgrading member servers and clients. Those machines can be migrated to Windows 2000/2003 at any time during the process.

So, what Operating Systems can be upgraded to Windows 2000? Check the following table:

Operating SystemUpgrade to Windows 2000 ProfessionalUpgrade to Windows 2000 Server
Windows 3.xNoNo
Windows NT 3.1NoNo
Windows NT Workstation 3.51YesNo
Windows NT Server 3.51NoYes
Windows 95 and Windows 98YesNo
Windows NT Workstation 4.0YesNo
Windows NT Server 4.0 NoYes

Notice a couple of things. Workstations cannot be upgraded to servers nor can servers to be downgraded to workstations. Also, you must get the OS to at least Windows NT 3.51 in order to upgrade.

How about Windows Server 2003?

  Standard EditionEnterprise EditionDatacenter EditionWeb EditionWindows Small Business Server 2003
Windows NT 3.51          
Windows NT 4.0 Server*YesYes      
Windows NT 4.0 Terminal Server Edition*YesYes      
Windows NT 4.0 Enterprise Edition*   Yes      
Windows 2000 ServerYesYes     Yes
Windows 2000 Advanced Server   Yes      
Windows 2000 Datacenter Server     Yes    
Windows Server 2003 Standard EditionYes     Yes
Windows Server 2003 Enterprise Edition        
Windows Server 2003 Datacenter Edition        
Windows Server 2003 Web Edition        
Windows Server 2003 Beta3/RC1/RC2**YesYesYesYes****
Small Business Server 2000         Yes
Windows Small Business Server 2003          

* Windows NT 4.0 upgrade is supported by Service Pack 5 (SP5) or later. If earlier version of services pack is installed, the upgrade is not possible.

** Interim releases of Windows Server 2003 will upgrade to the release manufacturer (RTM) code of same edition. For example, RC1 Standard Edition upgrades to RTM Standard Edition.

*** Release of Windows Small business Server planned for the second half of 2003.

**** Release candidate (RC) to RTM code for Windows Small Business Server will be supported.

Theory is all "well and good" but the time comes when it is time to begin the process. So how do we upgrade a Windows NT domain controller to Windows 2000/2003?

Domain Restructure

