Forest trust design with multiple network segments


we have 3 firewalled network segments | b | c.

= our existing internal forest
b = single dc stood create trust
c = external forest

b necessary unable make directly routable c , want avoid nat'ing.  long story.

we have opened ports between new dc in b, , existing dcs in a.  same new dc in b, , 1 or dcs in c.

forest in 2003, forest in c 2008r2.

questions:


1) member servers , workstations in cannot communicate dc in b. should additional config done account this?  (e.g. can/should restict authentication dcs in a, or ad 'figure out')

2) dc's in cannot see dc's in external forest in c. should additional config done account this?

3) should use if restict port? : http://technet.microsoft.com/en-us/library/dd772723%28v=ws.10%29.aspx


thanks,
jaime

you can't configure things - first of domain controller acting flexibel single master operations (fsmo) role pdc used establish trust , maintain trust password between domains (forests) - recommend ensure pdcs on both side can communicate each other.

for authentication requests, need understand how dclocator works cross-trusts , how dcs used authentication selected design (ad isn't going figure out)

have @ following articel guides required steps control this:
domain locator across forest trust:
http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx


enfo zipper
christoffer andersson – principal advisor
http://blogs.chrisse.se - directory services blog



Windows Server  >  Directory Services



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file