AD 林恢复 - 常见问题解答AD Forest Recovery - FAQ

适用于: Windows Server 2016、Windows Server 2012 和 2012 R2,Windows Server 2008 和 2008 R2,Windows Server 2003Applies To: Windows Server 2016, Windows Server 2012 and 2012 R2, Windows Server 2008 and 2008 R2, Windows Server 2003

本文档包含有关林恢复) (常见问题的常见问题:This document contains frequently asked questions (FAQs) regarding forest recovery:

常规恢复General Recovery

问:我可以执行哪些操作来加快恢复速度?Q: What can I do to speed up recovery?

尽管恢复速度不是本指南的主要目标,但你可以通过以下方式实现较短的恢复时间:Although speed of recovery is not the primary goal of this guide, you can achieve shorter recovery times by:

  • 创建详细林恢复计划、定期更新,并在合理大小的模拟测试环境中将其在每年至少进行一次Creating a detailed forest recovery plan, updating it on a regular basis, and practicing it in a simulated test environment of reasonable size at least once a year
  • 使用虚拟化域控制器 (DC) 克隆Using virtualized domain controller (DC) cloning
    • 在从每个域中的备份还原一个 DC 后,虚拟化的 DC 克隆可以加速获取其他 Dc 运行的过程。Virtualized DC cloning expedites the process to get additional DCs running after one DC is restored from backup in each domain. 可以克隆额外的虚拟化 Dc,而不是等待可能需要长 AD DS 安装完成,以及在安装之后完成非关键复制。The additional virtualized DCs can be cloned rather than waiting for potentially lengthy AD DS installations to be completed and for the completion of non-critical replication after installation.
    • 如果林中的虚拟 Dc 托管在数量相对较少的连接的数据中心,则在恢复过程中克隆可能会带来最大的好处。Forests where virtual DCs are hosted in a relatively small number of well-connected data centers potentially benefit most from cloning during recovery. 但是,对于同一域中的多个虚拟化 Dc 的任何环境,都必须在同一个虚拟机监控程序主机上共存。However, any environment where multiple virtualized DCs for the same domain are co-located on the same hypervisor host should benefit.
  • (Rodc 部署只读域控制器) Deploying read-only domain controllers (RODCs)
    • Rodc 可以在恢复过程中提供业务连续性,因为它们不必与可写域控制器的网络断开连接。RODCs can provide business continuity during the recovery process because they do not have to be disconnected from the network as writable DCs do. Rodc 不执行出站复制。RODCs do not perform outbound replication. 因此,它们不会带来在将损坏的数据复制回已恢复环境时可写 Dc 所带来的风险。Therefore, they do not present the same risk that writable DCs pose for replicating damaging data back into the recovered environment.

影响林恢复过程持续时间的其他因素包括:Other factors that affect the duration of the forest recovery process include the following:

  • 从备份还原 Dc 时,需要花费一段时间来执行以下操作:When you restore DCs from backups, it takes time to:
    • 找到物理备份介质,如磁带。Locate the physical backup media, such as tapes.
    • 重新安装操作系统。Reinstall the operating system.
    • 从备份媒体中还原数据。Restore data from backup media.
      • 可以通过执行完全服务器恢复(而不是系统状态还原)来减少重新安装操作系统所需的时间,并从备份还原数据。You can reduce the time required to reinstall the operating system and restore data from backup by performing full server recovery instead of system state restore. 由于完全服务器恢复基于二进制,因此完成的速度要快于系统状态还原。Because full server recovery is binary-based, it completes much faster than system state restore.
      • 但是,如果服务器包含不希望还原的系统状态数据中的数据,则完全服务器恢复可能不是系统状态还原的可行替代方法。However, if the server contains data that is excluded from system state data that you do not want to restore, full server recovery might not be a viable alternative to system state restore. 请考虑对服务器执行完整服务器恢复而不是系统状态还原的优点,并通过执行计划稍后要还原的适当类型的备份来进行相应的准备。Consider the advantages of performing a full server recovery instead of a system state restore for your servers specifically, and prepare accordingly by performing the appropriate type of backup that you plan to restore later.
  • 重新生成 Dc 时,复制数据以进行基于网络的升级需要花费时间。When you rebuild DCs, it takes time to replicate data for network-based promotions.
    • 可以通过执行以下步骤来缩短还原 Dc 所需的时间:You can decrease the time required for restoring DCs by performing the following steps:
  • 缩短检索备份介质的时间:Reduce the time for retrieving backup media by:
  • 强制从 Dc 删除 AD DS,而不是重新安装操作系统。Force the removal of AD DS from the DCs instead of reinstalling the operating system. 如果在林范围内发生故障的原因已确定为完全位于 AD DS 范围内,则无需在 Dc 上重新安装操作系统。If the cause of the forest-wide failure has been identified to be purely within the scope of AD DS, you do not have to reinstall the operating system on the DCs.
  • 使用更快的磁带设备或磁盘备份来减少还原操作所需的时间。Use faster tape devices or disk backups to reduce the time that is required for restore operations.

还可以使用 "从媒体安装" (IFM) 功能,在每个域中重新生成 Dc,从而帮助加速 AD DS 安装。You can also help accelerate AD DS installations by using the Install from Media (IFM) feature to rebuild DCs in each domain. IFM 减少了在每个域中重建 Dc 时产生的复制延迟。IFM reduces the replication latency that is incurred when you rebuild DCs in each domain.

具有更严格的服务级别协议 (SLA) 的企业可能会考虑更改林恢复过程以加快恢复速度。Businesses that have a more aggressive service-level agreement (SLA) might consider altering the forest recovery procedures to speed recovery.

问:我能否自动执行林恢复过程?Q: Can I automate the forest recovery process?

由于林恢复过程的复杂而关键,当前没有它的端到端自动化。Because of the complex and critical nature of the forest recovery process, there is currently no end-to-end automation of it. 林恢复过程比处理自动化的技术问题更是一种后勤和组织的挑战。The forest recovery process is more a logistical and organizational challenge of restoring business continuity than a technical problem of process automation. 因此,管理该环境的人员应创建一个特定于该环境的林恢复计划,然后自动执行可自动成功完成的部分。Therefore, the individual who administers the environment should create a forest recovery plan that is specific to that environment and then automate sections of it that can be automated successfully.

您可以使用命令行工具执行大多数林恢复步骤。You can perform most of the forest recovery steps by using command-line tools. 因此,大部分步骤都可以编写脚本。Therefore, most of the steps are scriptable. 例如,Ntdsutil.exe 是林恢复过程中最常使用的工具之一。For example, Ntdsutil.exe is one of the most frequently used tools in the forest recovery process.

尽管脚本可以加快恢复速度,但在实际环境中应用这些脚本之前,必须全面测试这些脚本。Although scripts can speed recovery, you must thoroughly test these scripts before you apply them in a real environment. 此外,你必须根据 Active Directory 环境中的更改(例如添加新域或 DC)或 Active Directory 的新版本更新这些更改。Also, you must update them according to changes in the Active Directory environment, such as the addition of a new domain or DC, or a new version of Active Directory.

后续步骤Next Steps