建立一個網站連結橋接器設計Creating a Site Link Bridge Design

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

網站連結橋接器連接兩個或更多的網站連結,並讓轉移之間的網站連結。A site link bridge connects two or more site links and enables transitivity between site links. 每個橋接器中的網站連結必須與其他網站連結中橋接器網站。Each site link in a bridge must have a site in common with another site link in the bridge. 知識一致性檢查程式 (KCC) 搭配使用的資訊每個網站連結來計算複寫一個網站連結中的網站和橋接器其他網站連結網站之間的費用。The Knowledge Consistency Checker (KCC) uses the information on each site link to compute the cost of replication between sites in one site link and sites in the other site links of the bridge. 常見的網站的網站連結之間存在,而 KCC 也無法建立網域控制站在連接的相同的網站連結橋接器網站之間直接連接。Without the presence of a common site between site links, the KCC also cannot establish direct connections between domain controllers in the sites that are connected by the same site link bridge.

根據預設,所有網站連結都的轉移。By default, all site links are transitive. 我們建議您將不會變更的預設值,支援轉移所有網站的連結,ios 都橋接器(預設功能)。We recommend that you keep transitivity enabled by not changing the default value of Bridge all site links (enabled by default). 不過,您將需要停用所有網站的連結,ios 都橋接器,如果完成網站連結都橋接器設計:However, you will need to disable Bridge all site links and complete a site link bridge design if:

  • 完全不路由傳送您的 IP 網路。Your IP network is not fully routed. 當您停用所有網站的連結,ios 都橋接器和所有網站連結被都視為非轉移,以及您可以建立設定來建立您的網路的實際路由行為模型網站連結都橋接器物件。When you disable Bridge all site links, all site links are considered nontransitive, and you can create and configure site link bridge objects to model the actual routing behavior of your network.

  • 您需要掌控複寫 Active Directory Domain Services (AD DS) 中所做的變更。You need to control the replication flow of the changes made in Active Directory Domain Services (AD DS). 停用所有網站的連結,ios 都橋接器的網站連結 IP 傳輸並設定一個網站連結都橋接器,網站連結都橋接器變成相當於斷續網路。By disabling Bridge all site links for the site link IP transport and configuring a site link bridge, the site link bridge becomes the equivalent of a disjointed network. 在網站連結橋接器所有網站連結可以都路由間接,,但不是以外的網站連結橋接器路由都傳送。All site links within the site link bridge can route transitively, but they do not route outside of the site link bridge.

如需詳細資訊,了解如何使用 Active Directory 網站和服務] 嵌入式管理單元,來停用所有網站的連結,ios 都橋接器設定,請讓或停用網站連結橋樑 (http://go.microsoft.com/fwlink/?LinkId=107073)。For more information about how to use the Active Directory Sites and Services snap-in to disable the Bridge all site links setting, see Enable or disable site link bridges (http://go.microsoft.com/fwlink/?LinkId=107073).

控制 AD DS 複寫工作流程Controlling AD DS replication flow

有兩個案例中,您需要的網站連結橋接器設計複寫流程包含控制複寫錯誤移轉以及控制從防火牆複寫。Two scenarios in which you need a site link bridge design to control replication flow include controlling replication failover and controlling replication through a firewall.

控制複寫錯誤移轉Controlling replication failover

如果您的組織已經拓撲中樞支點網路,您通常不想衛星網站,以建立複寫連接到其他衛星網站,如果中樞網站的所有網域控制站都失敗。If your organization has a hub-and-spoke network topology, you generally do not want the satellite sites to create replication connections to other satellite sites if all domain controllers in the hub site fail. 在這些案例中,您必須停用所有網站的連結,ios 都橋接器,並建立網站連結橋接器使複寫連接建立衛星網站之間只有一個或兩個躍點原位衛星網站的另一個中樞網站。In such scenarios, you must disable Bridge all site links and create site link bridges so that replication connections are created between the satellite site and another hub site that is just one or two hops away from the satellite site.

透過防火牆控制複寫Controlling replication through a firewall

如果有兩個網域控制站代表相同的網域中的兩個不同的網站專門允許彼此只是透過防火牆,您可以停用所有網站的連結,ios 都橋接器,並建立網站的網站連結橋接器一端相同的防火牆。If two domain controllers representing the same domain in two different sites are specifically allowed to communicate with each other only through a firewall, you can disable Bridge all site links and create site link bridges for sites on the same side of the firewall. 因此,如果您的網路分隔防火牆,我們建議您停用轉移的網站連結,並一方防火牆上建立的網站連結橋接網路。Therefore, if your network is separated by firewalls, we recommend that you disable transitivity of site links and create site link bridges for the network on one side of the firewall. 管理透過防火牆複寫相關資訊,會看到網路分段防火牆在 Active Directory (http://go.microsoft.com/fwlink/?LinkId=107074)。For information about managing replication through firewalls, see Active Directory in Networks Segmented by Firewalls (http://go.microsoft.com/fwlink/?LinkId=107074).