VMware

This Question is Possibly Answered

1 "correct" answer available (10 pts)
1 2 Previous Next 21 Replies Last post: Feb 24, 2006 2:03 PM by Weatherman  

Discuss: Virtualisation of Active Directory Infrastructure ? posted: Feb 20, 2006 1:14 AM

Click to view MichaelJKnight's profile Hot Shot 239 posts since
Nov 3, 2004
I am trying to assemble some background information on the viability of virtualising our Active Directory infrastructure.

Our current policy is to virtualise servers wherever possible. Servers that contain specialist PCI cards or other exotic hardware are naturally excluded.
Servers that demonstrate resource utilisation close to or above the current largest VM specification of 3.6GB ram and 2 vCPU are also exempt until ESX 3.0 arrives and we can get hardware with enough horsepower to run 4 way VMs with 16GB of ram ;-)

Our Active Directory servers do not contain any exotic hardware and from a capacity perspective they should fit within the 2 vCPU and 3.6GB of ram limitations we have today.

Naturally we will be implementing development, then pre production and finally production to shake out any gremlins. The Domain Controllers themselves will be dispersed across ESX hosts in different farms where possible to minimise the risk of them ending up the same ESX host during VMotions. ESX 3 will introduce the ability to set affinity and anti-affinity rules between VMs so this should help in the future ;-)

I have read the following threads and apart from the Time keeping issue and making sure that is addressed are there any other gotchas or issues to be aware of from real world experiences?

Should we mix the environment and keep a small percentage of Domain controllers physical ?

I have found the following references so far:

VMware Forum Postings

Anyone build a whole active directory system on VMware?
http://www.vmware.com/community/thread.jspa?messageID=326863

New AD environment - recommendation for ESX use

http://www.vmware.com/community/thread.jspa?threadID=28828&tstart=75

ESX Production Active Directory Environment

http://www.vmware.com/community/thread.jspa?messageID=301727

VMware Whitepapers

http://www.vmware.com/pdf/vmware_timekeeping.pdf

VMware KB Articles

VMware Time Sync and Windows Time Service

http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=1318

Microsoft KB Articles

Things to consider when a Windows Server 2003-based domain controller or a Windows 2000-based domain controller runs in a virtual hosting environment
http://support.microsoft.com/kb/888794/en-us

Support policy for Microsoft software running in non-Microsoft hardware virtualization software

http://support.microsoft.com/kb/897615/en-us

Comments please....

Michael.

If you have implemented a virtualised AD infrastructure please share if possible, how many VMs, how many users supported etc.

Message was edited by:
MichaelJKnight

Click to view kix1979's profile Champion 3,769 posts since
Oct 14, 2004
About 15,000 users in about 10 countries all getting AD, DNS, DHCP from Domain controllers that are all virtualized. The only issue we had was NTP issues, which we worked out thanks to lots of posts on the forums. We did a single parent domain that is hardware based, basically 3 servers around the world. They are kept that way for support's sake with MS, but all child domains are 100% virtual. It runs like a champ and I never looked back at that project, still running smooth to this day.

Kix
Click to view mlmpella's profile Hot Shot 217 posts since
Nov 7, 2004
Win 2003 AD support about 5000 users.
Combination of Hardware and VM DCs. New DCs are Virtual. 14 Physical 11 VM
Only problem was getting the NTP issues straightened out.

If we look as DC for any reason we tend to rebuild from scratch rather than attempt a restore. Tends to be quicker and less error prone.
Click to view sbeaver's profile Guru 7,719 posts since
Nov 1, 2004
At my last life we had about 90-95% of all server virtualized. At the beging we had all DC running as VM's in over 26 offices world wide supporting between 5000 and 7000 users. We had well over 600 virtual machines in the Enterprise when I left.
Click to view MR-T's profile Champion 4,146 posts since
Apr 19, 2005
Hi Mike, it looks like you've done your reading so there isn't anything to add.

At our place we've got around 20,000 machines in the AD and we run a mix of physical and virtual. I'm not aware of any issues as a result of the virtual machines.

Over the coming months I plan to introduce a few more DC's in the virtual world and begin to switch off the physical.

Eventually all our infrastructure type servers (dhcp, dns, wins) will be shifted to VMware.
Click to view nkrick's profile Hot Shot 128 posts since
Jan 3, 2006
Thanks for all these links in one place. As we virtualize our infrastructure, the plan is to virtualize all the DC's in our "VM capable" data centers. Actually, the plan for this year sounds much like what you are doing, virtualize every server that can be virtualized. I have not seen any other "gotcha's" for DC's so far.

Message was edited by:
sorry for the fluff post...I admit it, I was just putting up a quick post to get my "flag."
nkrick
Click to view Ken.Cline's profile Champion 5,146 posts since
Jul 7, 2004
Congrats on the flag!!
Click to view jcayer's profile Hot Shot 213 posts since
Dec 20, 2005
We've got one running for DR and a couple physical ones. No problems. My only comment is, ever try to restore AD to different hardware. Doesn't work. With a virtual DC, easy as pie.
Click to view sbeaver's profile Guru 7,719 posts since
Nov 1, 2004
ever try to restore AD to different hardware

I just got back from DR at Sunguard and I restore AD from an HP to a DELL. The only thing you should restore is the System State
Click to view simon.l's profile Expert 543 posts since
Jul 18, 2004
Our AD farm is currently physical boxes but we will move them to VMware when the hardware comes up for refresh. Just need to tell the AD admin chaps (can't work out whether to do it before or after :-} ).

Si
Click to view simon.l's profile Expert 543 posts since
Jul 18, 2004
Si,

We had a user that contacted us; to confirm when his
machine was scheduled to be virtualised. We checked
our schedule and to his suprise he had been
virtualised two weeks earlier and not noticed :D

Michael.

LOL, we had the same but with new server, they demanded a physical, we game them a virtual and for 6 month they did not noticed a thing. Don't you just love VMware?

Si

Click to view mlmpella's profile Hot Shot 217 posts since
Nov 7, 2004
Good summarization.

One thing I forgot to mention in my earlier post. We had MS in to do a formal "Active Directory Health Check" last fall. Other than a few off-hand comments about "we don't recommend that" they made no big deal about the DCs that were Virtual Machines. We do have premier support which helps with that type of thing ;-)

mike

VMware Developer

SDKs, APIs, Videos, Learn and much more in the Developer community.

Learn More

Developer Sample Code

Increase your developer productivity with VMware API sample code.

Learn More

VMworld Sessions & Labs

Online access to the latest VMworld Sessions & Labs and online services.

Learn more

Purchase PSO Credits Online

Purchase credits to redeem training and consulting services online.

Buy Now

Community Hardware Software

View reported configurations or report your own.

Learn More

VMware vSphere

Come witness the next giant leap in virtualization.

Register Today

Communities