Hello ...

I will update my system from 2003 to 2008..and make some idea for networks:

look for this image:

give me yours opinions

Dani AI

Generated

— good direction to sketch the topology first. was right to push for requirements: before touching servers, list every service (AD, DHCP, DNS, mail, SQL, web apps), how many users use each, and the acceptable downtime and data-recovery targets. That short requirements sheet will drive whether you do a staged migration, a side-by-side rollout, or an in-place upgrade.

When you move from Server 2003 to Server 2008, the safest route is add new Server 2008 machines (or VMs), promote them, then transfer roles and demote the old DCs rather than relying on risky cross-architecture in-place upgrades. If you do add 2008 DCs you will need to prepare the forest/domain (adprep) before promotion; note in-place upgrades have architecture and SKU limits so plan accordingly. ()

About using TMG as a site filter without manually setting a browser proxy on every client: Forefront TMG supports three client models — Web Proxy (explicit), Firewall/Forefront client, and SecureNAT (no client software, traffic routed through TMG). SecureNAT or positioning TMG as the gateway lets you filter without changing each browser, but authentication and per-user policies need extra work (Firewall client or identity agents) and HTTPS inspection requires deploying the TMG inspection CA to clients and planning exclusions. WPAD can auto‑configure browsers, but Windows DNS blocks WPAD by default on newer servers unless you explicitly enable it — proceed with care. (learn.microsoft.com)

Quick practical checklist (test in a lab first):

  1. Inventory apps and map them to servers/services.
  2. Build 2008 hosts (or VMs) and test apps there.
  3. If adding DCs: run adprep /forestprep then adprep /domainprep from the correct FSMO holders.
  4. Promote 2008 DCs, transfer FSMO roles, verify replication, then demote 2003 DCs.
  5. For TMG deployments enable HTTPS inspection only after pushing the TMG CA to clients and configuring exclusions; consider WPAD or SecureNAT depending on auth needs.
  6. Install TMG SP2 and the latest rollups if you must use TMG — but remember TMG is discontinued and out of mainstream support, so evaluate current supported gateway/filter solutions for a new deployment. (learn.microsoft.com)

If you post the diagram again (label networks, VLANs, and which servers hold which roles) it will be possible to give a concrete step‑by‑step migration sequence and a recommended TMG topology (internal/DMZ NICs, NAT vs routed, authentication method).

Recommended Answers

All 7 Replies

What are we supposed to comment on? You didn't offer any explanation.

What do you want to I do?
Do you want from me to put the addresses?

The network correctly?

this is right?

Even though I helped manage a network of a couple of dozen servers, I am not a network person. I would have no idea as to the proper way of setting up such a network. Having said that, I will add that there is no way to determine if your network is "correct" because configuring a network requires knowledge of its potential use. Among other things, you would need to specify

  1. the number of users
  2. the type of use (load, data requirements, etc)
  3. nature of the network

By "nature" I mean, is the network required to be available 24x7? Is the data critical? How long is it acceptable for the network to be unavailable. Such things determine replication requirements, communication requirements, etc. Our system required separate network paths for user use, replication, heartbeat, etc.

thanks Reverend Jim,,

but can you explane whats mean 24x7?

And this is image for new information:

note:

I want any thing to explane how to install tmg to use as filter web sites with out as to be proxy on ip only.

24x7 means 24 hours a day and 7 days a week. Our network was used by the people running the provincial electrical grid. Outages were not an option.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.