判斷網域所需的數目Determining the Number of Domains Required

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

森林每開頭單一網域。Every forest starts with a single domain. 使用者可以包含單一網域樹系的上限根據必須符合您想要配置給 Active Directory Domain Services (AD DS) 頻寬網域控制站之間複製慢連結。The maximum number of users that a single domain forest can contain is based on the slowest link that must accommodate replication between domain controllers and the available bandwidth that you want to allocate to Active Directory Domain Services (AD DS). 下表包含網域可以根據網域單一樹系的速度 [慢] 連結,以及您想要保留的複寫頻寬百分比的使用者人數,建議的最大值。The following table lists the maximum recommended number of users that a domain can contain based on a single domain forest, the speed of the slowest link, and the percentage of bandwidth that you want to reserve for replication. 這項資訊,包含最多個 100000 使用者,有連接 28.8 以每秒 56 kbps 或更高的樹系適用於。This information applies to forests that contain a maximum of 100,000 users and that have a connectivity of 28.8 kilobits per second (Kbps) or higher. 適用於包含超過 100000 使用者或連接小於 28.8 的樹系的建議,請洽詢經驗 Active Directory 設計師。For recommendations that apply to forests that contain more than 100,000 users or connectivity of less than 28.8 Kbps, consult an experienced Active Directory designer. 下表中的值為基礎複寫流量產生具有下列特性環境中:The values in the following table are based on the replication traffic generated in an environment that has the following characteristics:

  • 新的使用者加入樹系的每 20 年 %速率。New users join the forest at a rate of 20 percent per year.

  • 使用者退出樹系速率為 15%每年。Users leave the forest at a rate of 15 percent per year.

  • 每個使用者是五個的全域群組和五個通用群組成員。Each user is a member of five global groups and five universal groups.

  • 電腦的使用者比例為 1:1。The ratio of users to computers is 1:1.

  • 會使用 active Directory 整合網域名稱系統 (DNS)。Active Directory-integrated Domain Name System (DNS) is used.

  • 使用 DNS 清除。DNS scavenging is used.

注意

下表中列出的數字會近似值。The figures listed in the following table are approximations. 複寫流量數量而定主要 directory 在一段指定時間的變更的數目。The quantity of replication traffic depends largely on the number of changes made to the directory in a given amount of time. 確認您的網路,可容納您複寫流量藉由在實驗室測試的預估的數量和變更您的設計的之前將您的網域部署。Confirm that your network can accommodate your replication traffic by testing the estimated quantity and rate of changes on your design in a lab before deploying your domains.

慢連接網域控制站 56 kbps 的連結Slowest link connecting a domain controller (Kbps) 最多的使用者如果頻寬 1%的電量可用Maximum number of users if 1-percent bandwidth is available 最多的使用者如果頻寬 5%的電量可用Maximum number of users if 5-percent bandwidth is available 最多的使用者如果頻寬 10%可用Maximum number of users if 10-percent bandwidth is available
28.828.8 10,00010,000 25,00025,000 40,00040,000
3232 10,00010,000 25,00025,000 50,00050,000
5656 10,00010,000 50,00050,000 100,000100,000
6464 10,00010,000 50,00050,000 100,000100,000
128128 25,00025,000 100,000100,000 100,000100,000
256256 50,00050,000 100,000100,000 100,000100,000
512512 80,00080,000 100,000100,000 100,000100,000
1,5001,500 100,000100,000 100,000100,000 100,000100,000

若要使用此表格:To use this table:

  1. 最慢連接網域控制站的連結欄中,找出符合的所有 AD DS 會複寫網域中的慢連結的速度。In the Slowest link connecting a domain controller column, locate the value that matches the speed of the slowest link across which AD DS will replicate in your domain.

  2. 在 [慢連結快速對應的列,找出代表您想要到 AD DS 配置百分比頻寬欄。In the row that corresponds to your slowest link speed, locate the column that represents the percentage bandwidth you want to allocate to AD DS. 在該位置的值為使用者網域中單一網域可包含上限。The value at that location is the maximum number of users that the domain in a single domain forest can contain.

如果您認為您森林中的使用者總數小於可包含您的網域中的使用者人數,您可以使用單一網域。If you determine that the total number of users in your forest is less than the maximum number of users that your domain can contain, you can use a single domain. 請務必容納規劃未來成長,當您進行此判斷。Be sure to accommodate for planned future growth when you make this determination. 如果您認為您森林中的使用者總數大於可包含您的網域中的使用者人數,您需要保留較高百分比的頻寬複寫,加快連結速度,或您組織區域網域進行除法運算。If you determine that the total number of users in your forest is greater than the maximum number of users that your domain can contain, you need to reserve a higher percentage of bandwidth for replication, increase your link speed, or divide your organization into regional domains.

分割組織區域網域Dividing the organization into regional domains

如果您無法容納所有使用者在單一網域中,您必須選取的地區網域模型。If you cannot accommodate all of your users in a single domain, you must select the regional domain model. 將您的組織的區域的方式,可讓您的組織和您現有的網路感知器。Divide your organization into regions in a way that makes sense for your organization and your existing network. 例如,您可能會建立型邊界大陸上的區域。For example, you might create regions based on continental boundaries.

請注意,因為您需要建立的 Active Directory domain 您所建立的每個地區,我們建議您最小化數目 AD DS 定義您的地區。Note that because you need to create an Active Directory domain for each region that you establish, we recommend that you minimize the number of regions that you define for AD DS. 雖然您很可能包含森林中的數量網域,性建議樹系包含不會超過 10 網域。Although it is possible to include an unlimited number of domains in a forest, for manageability we recommend that a forest include no more than 10 domains. 您必須建立最佳化您複製的頻寬,將區域網域組織時,將您的系統管理複雜最小化之間適當的餘額。You must establish the appropriate balance between optimizing your replication bandwidth and minimizing your administrative complexity when dividing your organization into regional domains.

首先,判斷使用者可以管理您的樹系的上限。First, determine the maximum number of users that your forest can host. 依據的樹上的網域控制站複寫中的 [慢] 連結,而且想要配置複寫 Active Directory 頻寬平均量。Base this on the slowest link in the forest across which domain controllers will replicate and the average amount of bandwidth you want to allocate to Active Directory replication. 下表列出最大的建議的使用者可以包含樹系的數字。The following table lists the maximum recommended number of users that a forest can contain. 這根據的速度 [慢] 連結,以及您想要保留的複寫百分比頻寬。This is based on the speed of the slowest link and the percentage bandwidth that you want to reserve for replication. 這項資訊適用於樹系的包含最多個 100000 的使用者,有連接 28.8 或更高版本。This information applies to forests that contain a maximum of 100,000 users and that have a connectivity of 28.8 Kbps or higher. 下表中的值為基礎假設如下:The values in the following table are based on the following assumptions:

  • 所有網域控制站都的通用伺服器。All domain controllers are global catalog servers.

  • 新的使用者加入樹系的每 20 年 %速率。New users join the forest at a rate of 20 percent per year.

  • 使用者退出樹系速率為 15%每年。Users leave the forest at a rate of 15 percent per year.

  • 使用者的通用五的五個的全域群組成員。Users are members of five global groups and five universal groups.

  • 電腦的使用者比例為 1:1。The ratio of users to computers is 1:1.

  • Active Directory 整合 DNS 使用。Active Directory-integrated DNS is used.

  • 使用 DNS 清除。DNS scavenging is used.

注意

下表中列出的數字會近似值。The figures listed in the following table are approximations. 複寫流量數量而定主要 directory 在一段指定時間的變更的數目。The quantity of replication traffic depends largely on the number of changes made to the directory in a given amount of time. 確認您的網路,可容納您複寫流量藉由在實驗室測試的預估的數量和變更您的設計的之前將您的網域部署。Confirm that your network can accommodate your replication traffic by testing the estimated quantity and rate of changes on your design in a lab before deploying your domains.

慢連接網域控制站 56 kbps 的連結Slowest link connecting a domain controller (Kbps) 最多的使用者如果頻寬 1%的電量可用Maximum number of users if 1-percent bandwidth is available 最多的使用者如果頻寬 5%的電量可用Maximum number of users if 5-percent bandwidth is available 最多的使用者如果頻寬 10%可用Maximum number of users if 10-percent bandwidth is available
28.828.8 10,00010,000 50,00050,000 75,00075,000
3232 10,00010,000 50,00050,000 75,00075,000
5656 10,00010,000 75,00075,000 100,000100,000
6464 25,00025,000 75,00075,000 100,000100,000
128128 50,00050,000 100,000100,000 100,000100,000
256256 75,00075,000 100,000100,000 100,000100,000
512512 100,000100,000 100,000100,000 100,000100,000
1,5001,500 100,000100,000 100,000100,000 100,000100,000

若要使用此表格:To use this table:

  1. 最慢連接網域控制站的連結欄中,找出符合的速度 [慢] 連結 AD DS 會複寫您森林中的所有的值。In the Slowest link connecting a domain controller column, locate the value that matches the speed of the slowest link across which AD DS will replicate in your forest.

  2. 在 [慢連結快速對應的列,找出代表您想要到 AD DS 配置百分比頻寬欄。In the row that corresponds to your slowest link speed, locate the column that represents the percentage bandwidth that you want to allocate to AD DS. 在該位置的值為使用者可以管理您的樹系的上限。The value at that location is the maximum number of users that your forest can host.

如果可以管理您的樹系的使用者人數大於您需要裝載的使用者人數,單一樹系適用於您的設計。If the maximum number of users that your forest can host is greater than the number of users that you need to host, a single forest will work for your design. 如果您需要裝載比上限您找出有更多的使用者,您需要加快最低的連結,配置更高百分比的頻寬 AD ds,或部署其他森林。If you need to host more users than the maximum number that you identified, you need to increase the minimum link speed, allocate a greater percentage of bandwidth for AD DS, or deploy additional forests.

如果您認為單一樹系的將容納您需要裝載的使用者人數下, 一步就是判斷每個地區可支援的使用者人數為 [慢] 連結位於該地區。If you determine that a single forest will accommodate the number of users that you need to host, the next step is to determine the maximum number of users that each region can support based on the slowest link located in that region. 樹系分為數據用量感知器對您的地區。Divide your forest into regions that make sense to you. 請確定您基本項目上的不會變更您決策。Make sure that you base your decision on something that is not likely to change. 例如,而不是銷售地區使用大陸。For example, use continents instead of sales regions. 當您找到的使用者人數這些地區將您的網域結構的基礎。These regions will be the basis of your domain structure when you have identified the maximum number of users.

判斷使用者必須在每個地區裝載,然後確認 [,它們不會超過允許的最大的數目根據慢連結速度和配置到 AD DS,在此區域中的頻寬。Determine the number of users that need to be hosted in each region, and then verify that they do not exceed the maximum allowed based on the slowest link speed and the bandwidth allocated to AD DS in that region. 下表列出最大的建議的使用者可以包含地區網域數目。The following table lists the maximum recommended number of users that a regional domain can contain. 它所依據的速度 [慢] 連結,以及您想要保留的複寫頻寬百分比。It is based on the speed of the slowest link and the percentage of bandwidth you want to reserve for replication. 這項資訊適用於樹系的包含最多個 100000 的使用者,有連接 28.8 或更高版本。This information applies to forests that contain a maximum of 100,000 users and that have a connectivity of 28.8 Kbps or higher. 下表中的值為基礎假設如下:The values in the following table are based on the following assumptions:

  • 所有網域控制站都的通用伺服器。All domain controllers are global catalog servers.

  • 新的使用者加入樹系的每 20 年 %速率。New users join the forest at a rate of 20 percent per year.

  • 使用者退出樹系速率為 15%每年。Users leave the forest at a rate of 15 percent per year.

  • 使用者的通用五的五個的全域群組成員。Users are members of five global groups and five universal groups.

  • 電腦的使用者比例為 1:1。The ratio of users to computers is 1:1.

  • Active Directory 整合 DNS 使用。Active Directory-integrated DNS is used.

  • 使用 DNS 清除。DNS scavenging is used.

注意

下表中列出的數字會近似值。The figures listed in the following table are approximations. 複寫流量數量而定主要 directory 在一段指定時間的變更的數目。The quantity of replication traffic depends largely on the number of changes made to the directory in a given amount of time. 確認您的網路,可容納您複寫流量藉由在實驗室測試的預估的數量和變更您的設計的之前將您的網域部署。Confirm that your network can accommodate your replication traffic by testing the estimated quantity and rate of changes on your design in a lab before deploying your domains.

慢連接網域控制站 56 kbps 的連結Slowest link connecting a domain controller (Kbps) 最多的使用者如果頻寬 1%的電量可用Maximum number of users if 1-percent bandwidth is available 最多的使用者如果頻寬 5%的電量可用Maximum number of users if 5-percent bandwidth is available 最多的使用者如果頻寬 10%可用Maximum number of users if 10-percent bandwidth is available
28.828.8 10,00010,000 18,00018,000 40,00040,000
3232 10,00010,000 20,00020,000 50,00050,000
5656 10,00010,000 40,00040,000 100,000100,000
6464 10,00010,000 50,00050,000 100,000100,000
128128 15,00015,000 100,000100,000 100,000100,000
256256 30,00030,000 100,000100,000 100,000100,000
512512 80,00080,000 100,000100,000 100,000100,000
1,5001,500 100,000100,000 100,000100,000 100,000100,000

若要使用此表格:To use this table:

  1. 最慢連接網域控制站的連結欄中,找出符合的所有 AD DS 會將您所在地區最慢連結的速度。In the Slowest link connecting a domain controller column, locate the value that matches the speed of the slowest link across which AD DS will replicate in your region.

  2. 在 [慢連結快速對應的列,找出代表您想要到 AD DS 配置百分比頻寬欄。In the row that corresponds to your slowest link speed, locate the column that represents the percentage bandwidth that you want to allocate to AD DS. 該值代表使用者地區可裝載的上限。That value represents the maximum number of users that the region can host.

評估每個提議的地區和判斷中每個地區的使用者人數小於使用者網域可包含建議上限。Evaluate each proposed region and determine if the maximum number of users in each region is less than the recommended maximum number of users that a domain can contain. 如果您認為地區,可提供您要求的使用者人數,您可以建立網域的地區。If you determine that the region can host the number of users that you require, you can create a domain for that region. 如果您判斷您無法裝載的許多使用者,請考慮將您的設計到較小的地區和重新計算每個地區可裝載的使用者人數。If you determine that you cannot host that many users, consider dividing your design into smaller regions and recalculating the maximum number of users that can be hosted in each region. 選擇其他項目是配置多個頻寬或加速的連結。The other alternatives are to allocate more bandwidth or increase your link speed.

雖然您可以將它放在網域多網域中的使用者總數小於使用者網域中單一網域中的數字,可更高版本多網域森林中的使用者的整體數目。Although the total number of users that you can put in a domain in a multidomain forest is smaller than the number of users in the domain in a single domain forest, the overall number of users in the multidomain forest can be higher. 每個網域多網域中的使用者少數容納建立維持此環境中的通用其他複製成本。The smaller number of users per domain in a multidomain forest accommodates the additional replication overhead created by maintaining the global catalog in that environment. 適用於包含超過 100000 使用者或連接小於 28.8 的樹系的建議,請洽詢經驗 Active Directory 設計師。For recommendations that apply to forests that contain more than 100,000 users or connectivity of less than 28.8 Kbps, consult an experienced Active Directory designer.

文件認定地區Documenting the regions identified

之後,您將您的組織分成區域網域、文件,表示您想要的地區和使用者將會在每個地區存在數目。After you divide your organization into regional domains, document the regions that you want represented and the number of users that will exist in each region. 此外,請在每個地區,您將會使用 Active Directory 複寫慢連結的速度。In addition, note the speed of the slowest links in each region that you will use for Active Directory replication. 這項資訊用來判斷是否需要額外的網域或樹系。This information is used to determine if additional domains or forests are required.

協助您在擬您找出地區試算表,下載 Job_Aids_Designing_and_Deploying_Directory_and_Security_Services.zip 從工作協助工具的 Windows Server 2003 部署套件 (http://go.microsoft.com/fwlink/?LinkID=102558) 以及開放」檢測軍人地區」(DSSLOGI_4.doc)。For a worksheet to assist you in documenting the regions you identified, download Job_Aids_Designing_and_Deploying_Directory_and_Security_Services.zip from Job Aids for Windows Server 2003 Deployment Kit (http://go.microsoft.com/fwlink/?LinkID=102558) and open "Identifying Regions" (DSSLOGI_4.doc).