Forest trust design with multiple network segments
we have 3 firewalled network segments | b | c.
= our existing internal forest
b = single dc stood create trust
c = external forest
b necessary unable make directly routable c , want avoid nat'ing. long story.
we have opened ports between new dc in b, , existing dcs in a. same new dc in b, , 1 or dcs in c.
forest in 2003, forest in c 2008r2.
questions:
1) member servers , workstations in cannot communicate dc in b. should additional config done account this? (e.g. can/should restict authentication dcs in a, or ad 'figure out')
2) dc's in cannot see dc's in external forest in c. should additional config done account this?
3) should use if restict port? : http://technet.microsoft.com/en-us/library/dd772723%28v=ws.10%29.aspx
thanks,
jaime
you can't configure things - first of domain controller acting flexibel single master operations (fsmo) role pdc used establish trust , maintain trust password between domains (forests) - recommend ensure pdcs on both side can communicate each other.
for authentication requests, need understand how dclocator works cross-trusts , how dcs used authentication selected design (ad isn't going figure out)
have @ following articel guides required steps control this:
domain locator across forest trust:
http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx
enfo zipper
christoffer andersson – principal advisor
http://blogs.chrisse.se - directory services blog
Windows Server > Directory Services
Comments
Post a Comment