About complex network architecture design and its term


Recommended Posts

Hi all,

I have few questions puzzling me for few weeks, hope someone can guide me through as the scenario below:

Background:

Enterprise terminal clients (PC/laptop) most likely will classify into Active Directory/Cluster/Domain, and they use site-to-site VPN connection many times, this would be easier to take care of. The overall network architecture is as below:

Center -> Local Branch AD/Cluster/Domain, joined by local system with different department object unit (OU) in the domain -> these users/clients will need to grant access into specify domain in the entire AD because they are categariezed into different department/team/group.

-> Different region may have many AD/Cluster/Domain, they sometime have trusted bridge connection or site-to-site VPN connection in order to fastern certain process that need time to travel all the way back to Center

Case 1:

If one of the client system is transferring from one outlet / branch to the other one, would it be fine if this client system removed from the old domain/AD? Would that impact the entire network structure?

Case 2:

If one of the server that has a site-to-site VPN connection / trusted bridge connection to another branch, and eventually they decided to brake up the 2, what is/are the impact and would this affect the connectivity from Center to both these branches (in term of server connection). How or what should have done to avoid this?

Queries:

My udnerstanding is in AD, there are many different type of domains that served different purpose. And every single system/server is consider as object unit (OU) and they would join to either one of the domain in the AD in order to share data.

If the enterprise is big enough, and the server/major system will brake into Cluster.

-> What is/are the differences of Active Directory and Domain?

-> They is a domain controller and how can this affect the entire network structure?

Thank you all.

Regards,

A Domain is a group of computing systems or services on a network based on DNS and are most likely to be under single Administrative Control. Where, computing Systems may include any computer that the organization have, and Computing Serivces may represent any network services that is made available with the support of DNS.

Microsoft Active Directory is a repository (think of it as a database) of AD objects (resources and security principles) stored or managed in a hierarchical structure (like a tree structure). AD objects can be organized and managed into AD with help of Sites, Forests, and Domains, OUs.

I will add more as I get time.

Wow I hope you aren't charging people for your time. I don't know where to begin with what's wrong with that.

I'll have a go anyway as much as I can be bothered . . .

If one of the client system is transferring from one outlet / branch to the other one, would it be fine if this client system removed from the old domain/AD? Would that impact the entire network structure?

How or what should have done to avoid this?

Intersite replication perhaps? A basic of AD. Read up on what a domain is first and not domain name. You really need to understand the basics

They is a domain controller and how can this affect the entire network structure?

Expand please, It wont affect your "Network Infastructure" It would affect your domain infastruture ALOT

My udnerstanding is in AD, there are many different type of domains that served different purpose. And every single system/server is consider as object unit (OU) and they would join to either one of the domain in the AD in order to share data.

If the enterprise is big enough, and the server/major system will brake into Cluster.

Again NO! It doesnt break into cluster automatically. Again I think you need to read up on Windows clustering. And No thats not what an OU is.

You have a lot to understand about Active Directory and Domains

Where did you get this from??

"Enterprise terminal clients (PC/laptop) most likely will classify into Active Directory/Cluster/Domain"

Is this something you wrote?? Or is it out of some book?? To be honest its pretty much gibberish..

"Local Branch AD/Cluster/Domain, joined by local system with different department object unit (OU) in the domain"

Again --- Where did this come from.. Its Gibberish as well.

"Case 1:

If one of the client system is transferring from one outlet / branch to the other one, would it be fine if this client system removed from the old domain/AD? Would that impact the entire network structure?"

How I'm reading this. Can you move a client system (Member PC) from one Active directory domain to another.. Yes this is not a problem never was, never will be.. What impact would it have on the network structure??? Um that would be ZERO, a client means nothing -- there can be hundreds to thousands of them, they have nothing to do with the network structure at all. Worse case is if there were other clients that need to talk to this client. But as far as AD goes clients (Member PCs) have nothing to do with anything.

Case 2?? have no idea what your talking about.. Sure you can have location to location network connections.. But without understanding your overall connection topology its impossible to say what impact if any it would have.. You have not laid out any sort of topology for network connectivity between locations, nor any sort of AD Hierarchy. Are these locations part of the same forest? Are their trusts between forests or domains? Are they child domains, etc.

"there are many different type of domains that served different purpose"

Serve different purposes?? I believe your talking about a Forest, or domain or a child domain - as to serving different purposes??? Not sure what your asking??

'If the enterprise is big enough, and the server/major system will brake into Cluster"

Again at loss to understand what your wanting to ask even? Yes if the need is there then you might want to cluster servers to provide for High Availability.. But this really has nothing to directly do with Active directory. Clustering is a way to provide for fail over or load balancing.

"> What is/are the differences of Active Directory and Domain?"

Again are you confusing the term domain as used within active directory with general DNS (Domain Naming System) as used on the internet for example neowin.net is a domain?

A domain in active directory refers to all objects in a common database, now you never even mention Trees which would be either a single domain, or domain and its children -- ie all domains that fall under the same namespace. And you also make no mention of Forests which would be made up of trees and represent the security boundary of an active directory.

As to how a Domain Controller affects network structure?? Again not sure what your asking.. Network structure is outside the hierarchy of a AD structure. Yes normally you would design your active directory around your current network structure. For placement of DCs and breakup of sites, etc. But your AD structure does not dictate your network structure -- but network structure might dictate placements of of your DCs

Its not always about what the OP understands, but who else might read the thread and pickup some info, etc. ;)

Exactly! I love reading over various networking threads, especially those you have commented on. Not sure if I'll ever be a system admin, but I'm studying management information systems right now so I'm familiar (not an expert) in most of the information being discussed. With this topic, I definitely learned more about AD's. :p

Where did you get this from??

"Enterprise terminal clients (PC/laptop) most likely will classify into Active Directory/Cluster/Domain"

Is this something you wrote?? Or is it out of some book?? To be honest its pretty much gibberish..

"Local Branch AD/Cluster/Domain, joined by local system with different department object unit (OU) in the domain"

Again --- Where did this come from.. Its Gibberish as well.

"Case 1:

If one of the client system is transferring from one outlet / branch to the other one, would it be fine if this client system removed from the old domain/AD? Would that impact the entire network structure?"

How I'm reading this. Can you move a client system (Member PC) from one Active directory domain to another.. Yes this is not a problem never was, never will be.. What impact would it have on the network structure??? Um that would be ZERO, a client means nothing -- there can be hundreds to thousands of them, they have nothing to do with the network structure at all. Worse case is if there were other clients that need to talk to this client. But as far as AD goes clients (Member PCs) have nothing to do with anything.

Case 2?? have no idea what your talking about.. Sure you can have location to location network connections.. But without understanding your overall connection topology its impossible to say what impact if any it would have.. You have not laid out any sort of topology for network connectivity between locations, nor any sort of AD Hierarchy. Are these locations part of the same forest? Are their trusts between forests or domains? Are they child domains, etc.

"there are many different type of domains that served different purpose"

Serve different purposes?? I believe your talking about a Forest, or domain or a child domain - as to serving different purposes??? Not sure what your asking??

'If the enterprise is big enough, and the server/major system will brake into Cluster"

Again at loss to understand what your wanting to ask even? Yes if the need is there then you might want to cluster servers to provide for High Availability.. But this really has nothing to directly do with Active directory. Clustering is a way to provide for fail over or load balancing.

"> What is/are the differences of Active Directory and Domain?"

Again are you confusing the term domain as used within active directory with general DNS (Domain Naming System) as used on the internet for example neowin.net is a domain?

A domain in active directory refers to all objects in a common database, now you never even mention Trees which would be either a single domain, or domain and its children -- ie all domains that fall under the same namespace. And you also make no mention of Forests which would be made up of trees and represent the security boundary of an active directory.

As to how a Domain Controller affects network structure?? Again not sure what your asking.. Network structure is outside the hierarchy of a AD structure. Yes normally you would design your active directory around your current network structure. For placement of DCs and breakup of sites, etc. But your AD structure does not dictate your network structure -- but network structure might dictate placements of of your DCs

:blush:

Thanks Budman and yes, sorry to say, basic network knowledge is fine for me, but to be honest, those are kinda unknown to me. Sincerely thanks for your precious time replying with comprehensive points and questions that make me think and learn more.

I will try to sort all the questions that were put back to me one by one with my friend ~ Google. Thanks, hope the next time i come here again with different level of network knowledge :)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • No news articles about the Arch Linux repo being majorly infected with malware?!?
    • Waymo recalls self-driving software after cars enter closed freeway work zones by Paul Hill Waymo, the self-driving car maker owned by Alphabet – the parent company of Google –, has recalled some of its fifth-generation Automated Driving Systems (ADS). It did so after some of its cars drove through closed construction zones. According to the National Highway Traffic Safety Administration (NHTSA), the affected vehicles were capable of driving through a closed freeway construction zone and continuing to drive at speed. The listing on the NHTSA website says that Waymo is currently developing a solution to fix this issue, but in the meantime, freeway driving is being restricted. Waymo will update its ADS software so that vehicles can detect when they can avoid entering construction zones. According to the Safety Recall Report, on April 20, 2026, Waymo’s Field Safety Committee began meetings reviewing an event from April 11, 2026, and five events from April 19, 2026, where Waymo’s autonomous vehicles didn’t recognize and drove past ramp closure signs into the pre-planned freeway construction zones. This took place in Phoenix, Arizona. Separately, on May 18, 2026, seven Waymo vehicles entered freeway lanes with active construction in the San Francisco Bay Area by driving between cones that were placed to show the lane was closed. On the back of both of these events, Waymo restricted freeway driving until it could address the issue. In June, Waymo’s Safety Board reviewed the issue and additional information related to ADS performances around construction zones; then, as a result, it decided to conduct a recall. This development is not good for Waymo as it adds to a growing list of technical hiccups its cars have experienced. Ultimately, it will lead to more scrutiny from lawmakers around the world who will be more cautious about letting autonomous vehicles on their roads without tighter regulation. For readers in areas where Waymo operates, does this news make you more wary about stepping into one of these vehicles?
    • I'm still on Windows 10 22H2 because I didn't want to deal with all the issues in Windows 11, so I waited almost a week before installing the latest Patch Tuesday update (KB5094127), I went ahead and did it, and it was a huge mistake—ever since then, my File Explorer has seen a performance drop of about 30% when transferring large files... Once again, Microsoft has outdone itself! This update cannot be uninstalled, either through the Control Panel (via Settings) or by accessing Advanced Startup Options. The only possible alternative would be to use system restore points, but I’d have to reinstall all app and driver updates (and there’s no guarantee it would work). Or there’s the “nuclear option” of a in-place repair without losing files or apps, but even then, all my customizations would be lost! Microsoft just can’t help but mess everything up! Way to go, Microsoft! But I still don’t want your c****y Windows 11!
    • Microsoft: Windows 11 could finally solve a major issue across AMD, Nvidia, and Intel GPUs by Sayan Sen While Microsoft has been trying to improve it, Windows 11 is definitely not flawless, as even today some issues are taking a year to publicly acknowledge. However, one area of trouble that may finally see much better results soon is graphics driver crashes. Work on graphics driver timeouts, also called Timeout and Detection Recovery (TDR), is not new as the latest WDDM 3.2 also has specific improvements regarding it. Windows Display Driver Model (WDDM) version 3.2 is supported on Windows 11 24H2 and 25H2. However, with the upcoming version 26H2, TDR crash diagnosis could go to the next level as Microsoft is introducing a new DirectX 12 API feature called "DirectX Dump Files". Similar to how system memory dump files work when a system crashes or freezes or encounters any such major issue, DirectX Dump Files (DDF) will essentially record a snapshot of the GPU execution right at the moment a graphics-related crash or hang or freeze occurs, so that developers can better understand and diagnoze these TDR and timeout detection errors. The dump will be available as a .dxdmp file for analysis and it will be a comprehensive dump file generated with detailed insights about the hardware, drivers, Windows, as well as the affected application. This should be another welcome change in this department. Earlier at GDC 2026, when the technology was first debuted, Microsoft had shared more details regarding it. The company had explained how DDF is designed to gather data from every layer of the graphics stack into a single file, eliminating the need for developers to manually correlate logs from multiple tools. As mentioned above, the dump can contain a lot of useful details like GPU hardware state information such as register values, shader program counters, page fault virtual addresses, shader memory data, and command buffers. Alongside that, it also captures DirectX runtime and kernel information, including D3D objects, pipeline state objects, device error data, adapter details, and CPU call stacks. Microsoft says the feature has been built around two primary use cases: retail device removals and local device removals. The former allows developers to collect crash information from end users' systems in the field, while the latter helps QA teams and developers investigate issues on test machines. Developers will also be able to include up to 2 MB of custom application data through new D3D12 APIs, providing additional context for troubleshooting. In addition, Microsoft is introducing three dump collection modes ranging from zero-overhead capture, which has no runtime performance impact on supported hardware, to higher-detail modes that collect more vendor-specific debugging data. On compatible Tier 2 hardware, zero-overhead dumps will be enabled by default, meaning developers may begin receiving useful crash diagnostics without making any code changes. The table below explains the three tiers: Tier Description NO_OVERHEAD Enables crash capture with no runtime cost and is suitable for broad deployment MEDIUM_OVERHEAD Provides a balance, capturing additional diagnostic data with moderate impact HIGH_OVERHEAD Collects the most detailed GPU and driver state available, enabling deeper investigation at the cost of higher runtime overhead In terms of availability, the company expects broader release to be around the fall of 2026, which should be right around the time when Windows 11 version 26H2 lands. Right now, DirectX Dump Files are available as a preview and currently, only AMD has the compatible AgilitySDK Developer Preview driver version 26.10.07.02. You can find the official announcement post here on Microsoft's website.
    • And with SO much better perf than the laggy mess that is Files.
  • Recent Achievements

    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
    • First Post
      BizSAR earned a badge
      First Post
    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      598
    2. 2
      +Edouard
      190
    3. 3
      PsYcHoKiLLa
      79
    4. 4
      Michael Scrip
      76
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!