Recently, I need to confirm DFSR function for one Project verification. Based on this necessity, I have to study DFSR mechanism on 64 bit Windows Server 2008 R2 so that build a environment for testing its function on my lab.
data:image/s3,"s3://crabby-images/ab11c/ab11c39a85f7881eeb20d855d08aec16c5d28b23" alt="Drawing1 Drawing1"
The following process summary my testing steps for your reference. In this article, I will introduce the prerequisite of one way DFSR.
TMG 2010 Firewall Rule Setting
Set “Firewall Rule” from DMZ (Server with DFSR Role) to Internal (Server with DFSR Role) for TCP:135, 445, 24158 (Custom)
, 49999 (Custom)
data:image/s3,"s3://crabby-images/1102a/1102adfbcd6e2c29f6309c42851896c00da4f53b" alt="ScreenHunter_11 Jun. 15 19.24 ScreenHunter_11 Jun. 15 19.24"
Set “Firewall Rule” from DMZ (Server with DFSR Role) to Internal (Server with AD Role) for TCP: 53, 88, 135, 389, 5000~5100 (Custom), 50000 (Custom)
data:image/s3,"s3://crabby-images/0532e/0532eb1ebd0ce2c04e43487be2fc9b9c2b0b4ddb" alt="ScreenHunter_10 Jun. 15 19.24 ScreenHunter_10 Jun. 15 19.24"
Set “Firewall Rule” from Internal (Server with DFSR Role) to DMZ (Server with DFSR Role) for TCP:135, 445, 24158 (Custom) , 49999 (Custom)
Set static RPC for AD Logon/Directory Replication
Add Registry Key and correct value as a single port(50000/TCP). For detailed configuration, please refer to this URL as ADLogon/DirRep setting.
Open firewall port for Computer join Domain & Account logon Domain
Disable Windows Firewall
Turn off Windows Firewall on all Servers with DFSR role
Installing DFS Replication
In Server Manager, click “Roles” ---> “Add Roles” to trigger [Add Roles Wizard]
data:image/s3,"s3://crabby-images/bb342/bb3423775e835dda6b6ad26d41edba0dcd66caf1" alt="ScreenHunter_01 Jun. 12 14.57 ScreenHunter_01 Jun. 12 14.57"
Click “Next >” button if you have already verified the suggestion.
data:image/s3,"s3://crabby-images/ae09b/ae09b3e216cd847768d6736968d113c8a4b56915" alt="ScreenHunter_02 Jun. 12 15.00 ScreenHunter_02 Jun. 12 15.00"
Enable “File Services” check box next to click “Next >” button
data:image/s3,"s3://crabby-images/84ab8/84ab8f6256ac66ffc84be760f00a37fb9ad8eb33" alt="ScreenHunter_03 Jun. 12 15.11 ScreenHunter_03 Jun. 12 15.11"
Click “Next >” button
data:image/s3,"s3://crabby-images/ee1d1/ee1d13c02bfd1796a223d8ff49e1f108646297e3" alt="ScreenHunter_04 Jun. 12 15.11 ScreenHunter_04 Jun. 12 15.11"
Enable “DFS Replication” check box next to click “Next >” button
data:image/s3,"s3://crabby-images/85de4/85de4fd2eb3e70b34decd817e22ec970f1a9dfa6" alt="ScreenHunter_05 Jun. 12 15.13 ScreenHunter_05 Jun. 12 15.13"
Click “Install” button
data:image/s3,"s3://crabby-images/3f569/3f56933ed72ff41de3683910bfb6bf0d154fe4f8" alt="ScreenHunter_06 Jun. 12 15.22 ScreenHunter_06 Jun. 12 15.22"
Click “Close”button if the installation succeeded.
data:image/s3,"s3://crabby-images/d81a3/d81a32798f70dc1f311358f064c6409fe01d0714" alt="ScreenHunter_07 Jun. 12 15.24 ScreenHunter_07 Jun. 12 15.24"
So dose that it also install the DFS Management Console(dfsmgmt.msc) with MMC snap-in in the feature of Server Manager.
Configure DFSR to a Static Port
By running the
DFSRDIAG STATICRPC command on the DFSR Server as VBHV-FS-01, the DFSR RPC listening port will be forced on a static port as TCP/49999.
data:image/s3,"s3://crabby-images/1fd93/1fd93c73be95b5decb4be1556c0de31f7d018c45" alt="ScreenHunter_01 Jun. 15 18.04 ScreenHunter_01 Jun. 15 18.04"
After finish the above activity, please remember to restart “DFS Replication Service” again.
Set a Fixed Port for WMI
By executing the command on the console of DFSR role servers as VBHV-FS-01 & VBHV-FS-11 to set a fixed port as TCP/24158 for WMI
Until now, I have already finish the related prerequisite for DFSR. In next article, I will introduce the configure and setup DFSR mechanism.