Vous êtes sur la page 1sur 5

Deployment Topology for AD Fail Over

Summary
Customer request for creation of Windows 2016 Active Directory on Azure, acting as a Master DC.
Secondary DC is located on-premise customer site In the event of master DC failure, staffs will
authenticate via secondary DC on-premise through Intranet. A site to site VPN from Azure to on-
premise will be establish via RouteBased. No RRAS server will be used for this setup. Azure Active
Directory is only for user to authenticate for Office 365 services.

Westcon Group Philippines Unit 6 and 7, 9th flr. Wilcon IT Hub. 2251 Chino Roces Avenue, Bangkal, Makati City, 1233 Tel: (+632) 893 98 88 Website: www.westconcomstor.com
Pre-requisites
• IP Pool configuration for Azure
• 2 Static Public IP - Azure and Site
• Valid Microsoft Azure Subscription
• Compatible Site VPN Device
• Secure ROOT Cert
• Valid On-Premise Windows 2016 License

Implementation Plan
1. Configuration of Azure Network and S2S VPN
2. Configuration of Windows 2016 AD on Azure as Master AD
3. UAT Azure to Site and Site to Azure
4. Failover Testing Master to Secondary

Azure Network Configurations


• Vnet Virtual Network
• Vnet Virtual Gateway Subnetwork
• DNS Server Configuration - Azure and Site
• Vnet Virtual Gateway Network - VPN - Route-Based - Public IP
• Vnet Local Network Gateway - Local IP
• Site to Site VPN Gateway

Local VPN Configuration


Site VPN Configuration

Secondary AD Fail Over Setup


1. Master Active Directory Clean-Up
2. Windows 2008 AD to Windows 2016 AD Migration
3. Windows 2008 R2 ADSync to Windows 2016 Azure Migration
4. Windows 2016 AD on-premise
5. Windows 2016 Add Roles and Features - Active Directory Domain Services
6. Windows 2016 AD Configuration Sync to on-premise
7. Windows 2016 ADysnc to Windows 2016 Azure
8. Verification Windows 2016 Active Directory
9. UAT Testing and Failover

Westcon Group Philippines Unit 6 and 7, 9th flr. Wilcon IT Hub. 2251 Chino Roces Avenue, Bangkal, Makati City, 1233 Tel: (+632) 893 98 88 Website: www.westconcomstor.com
Azure DNS Server
1. Configuration of DNS Server
2. Verification of DNS Server
3. UAT Testing and Failover

Assumptions
• Applicable licenses must be ready prior to deployment (If any)
• Provision of SSL connection for Site-to-Site VPN (If any)
• Provision of configuration settings (e.g. IP addresses, server name) by customer (If required)
• Provision of relevant network configuration / diagrams by customer (If required)
• All relevant information is to be provided by customer prior to project commencement
• Customer will configure and update GPO on Windows 2016 AD
• Compatible VPN Hardware will be used for Azure VPN to successfully establish connection

Westcon Group Philippines Unit 6 and 7, 9th flr. Wilcon IT Hub. 2251 Chino Roces Avenue, Bangkal, Makati City, 1233 Tel: (+632) 893 98 88 Website: www.westconcomstor.com
Project Timeline
Customer Scope of Project Kick Local VPN Azure VPN Azure Windows UAT Project Sign
Documentation Work Off Configuration and Network 2016 Deployment Off
Configuration
Week 1 Week 2 Week 2.1 Week 3 Week 3 Week 3 Week 4 Week 5
7 Days 7 Days 1 Day 1 Days 1 Days 3 Days 2 Days 1 Days
1. Server Roles Customer and Sign Kick off and Configuration of Configuration of 1. Deployment 1. Fail over Test Project
Documentation Vendor will establish Project Local VPN for Site Azure Network of Azure VM 2. Verification Completion and
2. Network discuss on Scope start date to Site to Azure and Site to Site 2. Adding of Server Invoicing
Topology of work between On- Server AD 2016 AD
IP Pool Table Premise and Roles 3. Verification
3. MS Azure Azure 3. Server AD of Site to Site
Administrator Migration
Documentation from Master
AD
4. Establish
Master and
Secondary
AD

Westcon Group Philippines Unit 6 and 7, 9th flr. Wilcon IT Hub. 2251 Chino Roces Avenue, Bangkal, Makati City, 1233 Tel: (+632) 893 98 88 Website: www.westconcomstor.com
Cost
Upfront Cost
Professional Services – 7 Days USD 4,500.00
Monthly
- Projected Azure monthly cost is based on high-level
assessment of consumption to be migrated to Azure
- Price may vary depending on actual usage

Azure Server VM USD 108.47


1 B2MS (2 vCPU(s), 8 GB RAM) x 730 Hours; Windows – (OS
Only); Pay as you go; 1 x 256GB SSD managed OS disks – E15
Virtual Network USD 20.48
1 TB data transfer from Southeast Asia region to Southeast
Asia region
VPN Gateway USD 260.98
VPN Gateways type, VpnGw1 tier, 730 gateway hour(s), 1 TB,
VPN outbound VPN gateway type
Support USD 250.00
Level 2 – Server Administrator & Networking
Total Monthly USD 639.93

Westcon Group Philippines Unit 6 and 7, 9th flr. Wilcon IT Hub. 2251 Chino Roces Avenue, Bangkal, Makati City, 1233 Tel: (+632) 893 98 88 Website: www.westconcomstor.com

Vous aimerez peut-être aussi