Hello ...
I will update my system from 2003 to 2008..and make some idea for networks:
look for this image:
give me yours opinions
Hello ...
I will update my system from 2003 to 2008..and make some idea for networks:
look for this image:
give me yours opinions
— good direction to sketch the topology first. was right to push for requirements: before touching servers, list every service (AD, DHCP, DNS, mail, SQL, web apps), how many users use each, and the acceptable downtime and data-recovery targets. That short requirements sheet will drive whether you do a staged migration, a side-by-side rollout, or an in-place upgrade.
When you move from Server 2003 to Server 2008, the safest route is add new Server 2008 machines (or VMs), promote them, then transfer roles and demote the old DCs rather than relying on risky cross-architecture in-place upgrades. If you do add 2008 DCs you will need to prepare the forest/domain (adprep) before promotion; note in-place upgrades have architecture and SKU limits so plan accordingly. ()
About using TMG as a site filter without manually setting a browser proxy on every client: Forefront TMG supports three client models — Web Proxy (explicit), Firewall/Forefront client, and SecureNAT (no client software, traffic routed through TMG). SecureNAT or positioning TMG as the gateway lets you filter without changing each browser, but authentication and per-user policies need extra work (Firewall client or identity agents) and HTTPS inspection requires deploying the TMG inspection CA to clients and planning exclusions. WPAD can auto‑configure browsers, but Windows DNS blocks WPAD by default on newer servers unless you explicitly enable it — proceed with care. (learn.microsoft.com)
Quick practical checklist (test in a lab first):
adprep /forestprep then adprep /domainprep from the correct FSMO holders. If you post the diagram again (label networks, VLANs, and which servers hold which roles) it will be possible to give a concrete step‑by‑step migration sequence and a recommended TMG topology (internal/DMZ NICs, NAT vs routed, authentication method).
Jump to Post— Reverend Jim 6,665What are we supposed to comment on? You didn't offer any explanation.
Jump to Post— Reverend Jim 6,665Even though I helped manage a network of a couple of dozen servers, I am not a network person. I would have no idea as to the proper way of setting up such a network. Having said that, I will add that there is no way to determine if your …
What are we supposed to comment on? You didn't offer any explanation.
What do you want to I do?
Do you want from me to put the addresses?
The network correctly?
this is right?
Even though I helped manage a network of a couple of dozen servers, I am not a network person. I would have no idea as to the proper way of setting up such a network. Having said that, I will add that there is no way to determine if your network is "correct" because configuring a network requires knowledge of its potential use. Among other things, you would need to specify
By "nature" I mean, is the network required to be available 24x7? Is the data critical? How long is it acceptable for the network to be unavailable. Such things determine replication requirements, communication requirements, etc. Our system required separate network paths for user use, replication, heartbeat, etc.
thanks Reverend Jim,,
but can you explane whats mean 24x7?
And this is image for new information:
note:
I want any thing to explane how to install tmg to use as filter web sites with out as to be proxy on ip only.
24x7 means 24 hours a day and 7 days a week. Our network was used by the people running the provincial electrical grid. Outages were not an option.
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.