ååãäŒæ¥ããã°ã®ããã«æžããããã¡ã€ã³ã³ã³ãããŒã©ãŒãšActive Directoryèªäœã®ããã¯ã¢ãããšåŸ©å
ã«ç¹åããäžé£ã®èšäºãåŒãç¶ãå
¬éããŠããŸãã
ãã®ã·ãªãŒãºã®ååã®
èšäºã§ã¯ãç©çããã³ä»®æ³ãã¡ã€ã³ã³ã³ãããŒã©ãŒïŒDCïŒã®ããã¯ã¢ããæé ã«ã€ããŠèª¬æããŸããã 仿¥ã¯åœŒãã®å埩ã«ã€ããŠã話ããŸãã
ãã®æçš¿ã¯Active Directoryã®å埩ã¬ã€ãã§ã¯ãªãããšãããã«èšããªããã°ãªããŸããã ãã®ã¿ã¹ã¯ã¯ãããã¯ã¢ããããADãŸãã¯ç¹å®ã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒã埩å
ãããšãã«èæ
®ããå¿
èŠããããã®ã«ã€ããŠè©±ããVeeamãœãªã¥ãŒã·ã§ã³ã䜿çšããŠãããã®ã¢ã¯ã·ã§ã³ãå®è¡ããæ¹æ³ã瀺ãããšã§ãã

ã€ã³ãã©ã¹ãã©ã¯ãã£ã®å®å
šãªç¥èã¯ãADãªã«ããªã®èšç»ã«éåžžã«åœ¹ç«ã¡ãŸãã ããŒã¿ãæ£åžžã«å埩ããããã®çããç¥ãããã«å¿
èŠãªè³ªåã®ã»ãã®äžéšã次ã«ç€ºããŸãã
- ç°å¢å
ã«1ã€ä»¥äžã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒãããã€ãããŸããïŒ
- ãããã®èªã¿åã/æžã蟌ã¿ãã¡ã€ã³ã³ã³ãããŒã©ãŒïŒRWDCïŒãŸãã¯èªã¿åãå°çšãã¡ã€ã³ã³ã³ãããŒã©ãŒïŒRODCïŒã§ããïŒ
- æ
éããŠããã³ã³ãããŒã©ãŒã¯1ã€ã ãã§ããããããšãADã€ã³ãã©ã¹ãã©ã¯ãã£å
šäœãç ŽæããŠããŸããïŒ
- è€æ°ã®ã³ã³ãããŒã©ãŒãããå Žåããã¡ã€ã«è€è£œãµãŒãã¹ïŒFRSïŒã䜿çšããŠç°ãªããã¡ã€ã³ã³ã³ãããŒã©ãŒéã§å€æŽãåæããŸããããŸãã¯åæ£ãã¡ã€ã³ã«åãæ¿ããŠç°ãªããã¡ã€ã³ã³ã³ãããŒã©ãŒéã§å€æŽãåæããŸããïŒ
æ³šïŒ Windows Server 2008以éãDFSRã¬ããªã±ãŒã·ã§ã³ã¯SYSVOLãã£ã¬ã¯ããªã¬ããªã±ãŒã·ã§ã³ã®ããã©ã«ãã®æ§æãªãã·ã§ã³ã«ãªããŸããã
ä»®æ³åãã¡ã€ã³ã³ã³ãããŒã©ãŒã®åŸ©å
ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®åŸ©å
ãèšç»ããå Žåãæåã«
éæš©éã¢ãŒãã§ååãã©ããããŸãã¯
æš©éã¢ãŒãã䜿çšããå¿
èŠããããã©ããã倿ããå¿
èŠããããŸãã
2ã€ã®ã¢ãŒãã®éãã¯ãå埩ã¢ãŒãã§ã¯ã
æš©éã®ãªããã¡ã€ã³ã³ã³ãããŒã©ãŒããã°ããã®éåæãããããšãèªèããããšã§ãã ãããã£ãŠãä»ã®ã³ã³ãããŒã©ãŒãããŒã¿ããŒã¹ãæŽæ°ããäžåšäžã«çºçããææ°ã®å€æŽã«ããããšãã§ããŸãã ãããŠã
æš©éã®ããå埩äžãã³ã³ãããŒã©ãŒã¯èªåã ããæ¬åœã«æ£ããããŒã¿ããŒã¹ãæã£ãŠãããšä¿¡ããŠãããããèªåã®ããŒã¿ã«åºã¥ããŠä»ã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®ããŒã¿ããŒã¹ãæŽæ°ããæš©éãåãåãã®ã¯åœŒã§ãã
ã»ãšãã©ã®å埩ã·ããªãªã§ã¯ãç°å¢å
ã«ããã€ãã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒãããããã
æš©éã®ãªãã¢ãŒãã䜿çšããå¿
èŠããããŸãã ïŒããã«ã
æš©éã®ãã埩å
ã¯æ°ããåé¡ã«ã€ãªããå¯èœæ§ããããŸããïŒ
ããã¯ãVeeam BackupïŒReplicationããžãã¯ã®åºã«ãªã£ãŠããŸããããã©ã«ãã§ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã¯åé·æ§ãåããŠæ§ç¯ãããè€æ°ã®ã³ã³ãããŒã©ãŒãå«ãŸããŠãããšèããããŠããããã
æš©éã®ãªããªã«ããªãå®è¡ãããŸãã
Veeamã䜿çšããŠ
Authoritative Recoveryãå®è¡ããã«ã¯ãåŸã§èª¬æãã远å ã®æé ãå®è¡ããå¿
èŠããããŸãã
æçšïŒãã¡ã€ã³ã³ã³ãããŒã©ãŒã«é害ãçºçãããã1ã€ã®äžè¬çãªãªãã·ã§ã³ã¯ãä»ã®ã³ã³ãããŒã©ãŒéã§åœ¹å²ã忣ããå埩ãèµ·ããããã«ãªãå Žåã«ã¡ã¿ããŒã¿ãã¯ãªã¢ããããšã§ãã ãã®å Žåãä»ã®DCã«é害ãçºçããDCã®æ©èœãå®è¡ããããã«æç€ºããŸãã埩å
ããå¿
èŠã¯ãããŸããã
éæš©éã¢ãŒãã§ã®å埩
ãããã£ãŠãããã¯ã¢ãããã¡ã€ã«ã«æ»ããŸããããã¯ã¢ãããã¡ã€ã«ã®äœæã«ã€ããŠã¯ãåã®èšäºã§èª¬æããŸããã Veeam BackupïŒReplicationããã¯ã¢ãããããã¡ã€ã³ã³ã³ãããŒã©ãŒã埩å
ããã«ã¯ã以äžãè¡ãå¿
èŠããããŸãã
- Veeam Backupã³ã³ãœãŒã«ã§ãªã«ããªãŠã£ã¶ãŒããå®è¡ããŸãã
- å¿
èŠãªãã¡ã€ã³ã³ã³ãããŒã©ãŒãèŠã€ããŸãã
- ãªã«ããªã¡ãã¥ãŒã§ãVMå
šäœã埩å
ãããªãã·ã§ã³ãéžæããŸãïŒVMå
šäœã®åŸ©å
ïŒã
- 埩æ§ãã€ã³ããæå®ããŸãã
- ãœãŒã¹ãŸãã¯æ°ãã埩æ§å ŽæãéžæããŸãã
- æé ãå®äºããŸãã
ããã§æãæ³šç®ãã¹ãããšã¯ãããã¯ã¢ããã®äœææã«ã¢ããªã±ãŒã·ã§ã³ã®ç¶æ
ãèæ
®ã«å
¥ããããŒã¿åŠçã®ãããã§ãä»ã«äœãããå¿
èŠããªããšããããšã§ãã Veeamã¯ãæå®ãããVMã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒãèªèããæ¬¡ã®äžé£ã®ã¢ã¯ã·ã§ã³ã䜿çšããŠæ
éã«åŸ©å
ããŸãã
- VMã®ãã¡ã€ã«ãšãã£ã¹ã¯ã®å埩ã
- ãã¡ã€ã³ãµãŒãã¹ã®å埩ã®ç¹å¥ãªã¢ãŒãïŒDSRMã¢ãŒãïŒã§OSãèµ·åããŸãã
- ã¢ããªã±ãŒã·ã§ã³èšå®ã
- éåžžã¢ãŒãã§åèµ·åããŸãã
ãã¡ã€ã³ã³ã³ãããŒã©ãŒã¯ãããã¯ã¢ããããã®å埩ãèªèããé©åãªã¢ã¯ã·ã§ã³ãå®è¡ããŸããæ¢åã®ããŒã¿ããŒã¹ã¯ç¡å¹ã§ãããšå®£èšãããã¬ããªã±ãŒã·ã§ã³ããŒãããŒã¯ãããæŽæ°ããŠææ°ã®æ
å ±ãå°å
¥ã§ããŸãã
æš©éã®ããå埩
é«ã確çã§ããã®å埩ã¢ãŒãã¯å¿
èŠãããŸããã ãã ãã圌ã®ããšããã£ãšããç¥ããŸããããããããã°ããªããããªã®ããçè§£ã§ããŸãã
ãã®ã¢ãŒãã¯ãããšãã°ãADæ§é å
šäœãäœããã®çç±ïŒãã«ãŠã§ã¢ããŠã€ã«ã¹ãªã©ïŒã§ç ŽæããŠããã«ãããããããè€æ°ã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒãããç°å¢ã§ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®æå¹ãªã³ããŒã埩å
ããããšããå Žåã«äœ¿çšã§ããŸãã ãã¡ããããã®ç¶æ³ã§ã¯ãç Žæãããã¡ã€ã³ã³ã³ãããŒã©ãŒãæ°ãã埩å
ãããã³ã³ãããŒã©ãŒãã倿ŽãåãåãããšãæãŸããã§ãã
泚ïŒå®è¡ãããæé ã¯ãVeeam SureBackupã䜿çšããŠéé¢ãããç°å¢ã§ãã¡ã€ã³ã³ã³ãããŒã©ãŒã埩å
ããå Žåãšåæ§ã§ãã
æš©éã®ããã¢ãŒãã§åé€ããããªããžã§ã¯ããŸãã¯ã³ã³ãããŒã埩å
ãããã¡ã€ã³ã³ã³ãããŒã©ãŒããã®DCããä»ã®ã³ã³ãããŒã©ãŒã«å埩ãããããŒã¿ã匷å¶çã«ã³ããŒããã«ã¯ïŒ
- Veeamã®å®å
šãªVMãªã«ããªæäœãéžæããŸããããã°ã©ã ã¯ãæš©éã®ãªãã¢ãŒãã§æšæºã®DCãªã«ããªãèªåçã«å®è¡ããŸãïŒäžèšãåç
§ïŒã
- 2åç®ã®DCã®åèµ·åã§ã¯ãããŒããŠã£ã¶ãŒããéãïŒF8ããŒãæŒããŸãïŒãDSRMãéžæããDSRMã¢ã«ãŠã³ãæ
å ±ïŒãã®ã³ã³ãã¥ãŒã¿ãŒããã¡ã€ã³ã³ã³ãããŒã©ãŒã«å²ãåœãŠããšãã«æå®ããã¢ã«ãŠã³ãïŒã§ãã°ã€ã³ããŸãã
- ã³ãã³ãããã³ãããéãã ntdsutilãŠãŒãã£ãªãã£ãå®è¡ããŸã
- 次ã®ã³ãã³ãã䜿çšããŸãã
activate instance ntds;
- ãã®åŸã
authoritative restore;
- 次ã«ã
restore object âdistinguishedNameâ
restore subtree âdistinguishedNameâ
ãrestore subtree âdistinguishedNameâ
restore object âdistinguishedNameâ
äŸïŒ restore subtree âOU=Branch,DC=dc,DC=lab, DC=local
- æš©éã®ããå埩ã確èªããæäœã®å®äºåŸã«ãµãŒããŒãåèµ·åããŸãã
SYSDFã®
æš©éã®ããå埩æé ïŒDFSRãµãŒãã¹ã䜿çšããå ŽåïŒã¯ã次ã®ããã«å®è¡ãããŸãã
- ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®æš©éã®ãªã埩å
ãå®è¡ããŸãïŒããšãã°ãVeeam BackupïŒReplicationã§VMå
šäœã埩å
ããŸãïŒã
- 2åç®ã®èµ·åã§ãã¬ãžã¹ããªãã©ã³ãHKLM \ System \ CurrentControlSet \ Services \ DFSRã«ç§»åãã RestoreããŒãäœæããŠãããå€authoritativeã§ SYSVOLè¡ãäœæããŸã ã
ãã®å€ã¯ãDFSRãµãŒãã¹ã«ãã£ãŠèªã¿åãããŸãã èšå®ãããŠããªãå Žåãããã©ã«ãã§ã¯SYSVOLãéæš©éã¢ãŒãã§åŸ©å
ãããŸãã - HKLM \ System \ CurrentControlSet \ Control \ BackupRestoreã«ç§»åããŠSystemStateRestoreããŒãäœæããGUIDå€ïŒããšãã°ã 10000000-0000-0000-0000-0000000000000000ïŒã§ LastRestoreIdæååãäœæããŸãã
- DFSRãµãŒãã¹ãåèµ·åããŸãã

SYSVOL
æš©éã®ãã埩å
æé ïŒFRSã䜿çšããå ŽåïŒïŒ
- ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®æš©éã®ãªã埩å
ãå®è¡ããŸãïŒããšãã°ãVeeam BackupïŒReplicationã§VMå
šäœã埩å
ããŸãïŒã
- 2åç®ã®èµ·åã§ãã¬ãžã¹ããªãã©ã³ãHKLM \ System \ CurrentControlSet \ Services \ NtFrs \ Parameters \ Backup / Restore \ Process at Startupã«ç§»åãã BurflagããŒã®å€ã000000D4ïŒhexïŒãŸãã¯212ïŒdecïŒã«å€æŽããŸãã
ããã«ãããæš©éã¢ãŒãã§å€ãFRSãã¯ãããžã䜿çšããŠãããŒã¿ããã¡ã€ã³ã³ã³ãããŒã©ãŒã«åŒ·å¶çã«ã³ããŒãããŸãã FRSã®åŸ©å
ã®è©³çްã«ã€ããŠã¯ã ãã¡ããã芧ãã ãã ã
- NTFRSãµãŒãã¹ãåèµ·åããŸãã
Veeam Endpoint Backupã䜿çšããç©çãã¡ã€ã³ã³ã³ãããŒã©ãŒã®å埩
Veeam Endpoint Backupã䜿çšããŠããã¯ã¢ããããç©çãã·ã³ã埩å
ããæ¹æ³ã«ã€ããŠå°ã説æããŸãã
ããªããå¿
èŠã«ãªããŸãïŒ
- äºåæ§ææžã¿ã®Veeamç·æ¥ããŒããã£ã¹ã¯ã
- ããã¯ã¢ããèªäœãžã®ã¢ã¯ã»ã¹ïŒUSBã¹ãã£ãã¯ãŸãã¯ãããã¯ãŒã¯ãã©ã€ãäžïŒã
éèŠïŒ ãã®å Žåãç¹å¥ãªVeeam BackupïŒReplicationããžãã¯ã¯äœ¿çšãããªãããšã«æ³šæããŠãã ããã
Veeam Endpoint Backupã§ãªã«ããªããåŸããã¡ã€ã³ã³ã³ãããŒã©ãŒã¯ãªã«ããªã¢ãŒãã§èµ·åããŸãã ã¬ãžã¹ããªããŒã倿ŽããããVMãéåžžã¢ãŒãã§ããã«åèµ·åããããæ±ºå®ããå¿
èŠããããŸãã ããããã
ãã®Veeamãã¬ããžããŒã¹ã®èšäºã圹ç«ã€ã§ãããã
ããã§ã¯ãVeeam Endpoint Backupã䜿çšãããã¢ã¡ã¿ã«ãªã«ããªã®è©³çްãèªãããšãã§ããŸãã
ããã§ãå¥ã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒã埩å
ããããšãæ€èšããŸããã ãã ããã»ãšãã©ã®å ŽåãADã䜿çšããå Žåã誀ã£ãŠåé€ãããªããžã§ã¯ãã埩å
ããå¿
èŠããããŸãããã®å Žåãã³ã³ãããŒã©ãŒå
šäœã埩å
ããããšã¯æã广çãªãªãã·ã§ã³ã§ã¯ãããŸããã ãããã£ãŠã次ã®èšäºã§ã¯ãMicrosoftç¬èªã®ããŒã«ãšActive Directoryçšã®Veeam ExplorerãŠãŒãã£ãªãã£ã䜿çšããŠãåã
ã®ADãã£ã¬ã¯ããªãªããžã§ã¯ãã埩å
ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
䟿å©ãªãªã³ã¯ïŒ