RE: splitting up a network

From: David@cawdgw.net
Date: 01/22/02


From: <David@cawdgw.net>
To: "leon" <leon@inyc.com>, "'Matt Andreko'" <mandreko@ori.net>, <security-basics@securityfocus.com>
Date: Tue, 22 Jan 2002 19:00:39 +0100

In w2k, sites are used to connect segments with lowbandwidth between them to
give granularity to the replication process and streamline logon, dhcp, etc
rather than have the slow connection inside of a site. Sounds like your
situation would be perfect for a set of sites. Domains complicate matters,
unless you want to decentralize permissions.

D. Weiss
MCSE\CCNA\SSP2

-----Original Message-----
From: leon [mailto:leon@inyc.com]
Sent: Monday, January 21, 2002 7:14 PM
To: 'Matt Andreko'; security-basics@securityfocus.com
Subject: RE: splitting up a network

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Why cant you have 1 domain and create the two offices as "sites".

I thought that domain can encompass multiple sites and a site can
encompass multiple domains. That was my understanding of how win2k
domains worked.

- -----Original Message-----
From: Matt Andreko [mailto:mandreko@ori.net]
Sent: Monday, January 21, 2002 8:38 AM
To: security-basics@securityfocus.com
Subject: splitting up a network

Hi there. I'm currently administering a network which is being split
in
half. Half of it is going to be placed on an OC3 where all our
servers
are, and the other half is our office, which is on a T1, going
through a
separate class C IP range.

I'm trying to figure out a good way to setup this NT/2000 network
with
active directory over the 2 networks. I'd prefer to have them all in
1
domain, so I don't have to deal with domain trusts and such. Is
there a
good way to do this, or do I need to setup 2 separate domains, one
for
each location, and do trust relationships between the 2? Netbios can
be
used through these 2 separate ip ranges, and is preferred (although
it
will be secured and audited regularly).

Also, is there a good way to firewall the office machines, but still
have them be part of the domain, but not publicly available (only to
a
certain group on the domain?). I would prefer to put all the
machines
behind a linksys or maybe even a cisco router, to keep them
protected.
The machines on the OC3 don't need firewall protection really.

Any help would be appreciated.

- --
Matt Andreko
On-Ramp Indiana
(317)774-2100

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com>

iQA/AwUBPExaW9qAgf0xoaEuEQJfEwCgxn1lGbzJYlTTuuqi2gS8yb3aFb4AoLRW
tsaYXp0XZNHOpxDUKrdAkpMD
=Hh4K
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: Windows 2000 IP Range Question More options
    ... What do you mean by "part" of the network? ... BROADCAST domains then they need to be separate SUBNETS. ... machines plugged into different ports are separated by a router? ... The machines with the IP 190.10.10 addresses work fine amongst each ...
    (microsoft.public.windows.server.general)
  • RE: splitting up a network
    ... I thought that domain can encompass multiple sites and a site can ... I'm currently administering a network which is being split ... separate class C IP range. ... Also, is there a good way to firewall the office machines, but still ...
    (Security-Basics)
  • splitting up a network
    ... separate class C IP range. ... I'm trying to figure out a good way to setup this NT/2000 network with ... Also, is there a good way to firewall the office machines, but still ... The machines on the OC3 don't need firewall protection really. ...
    (Security-Basics)
  • Re: Can find Vista box, cant share folders or printers.
    ... When I click 'Network' on the laptop the ... I've disabled Norton and Windows firewall entirely to make sure that's not ... public folder sharing - on ... start by running the Network Setup Wizard on all machines (see ...
    (microsoft.public.windows.vista.networking_sharing)
  • Re: XP to Vista -- only halfway there
    ... concerning networks that combine Vista and XP machines. ... I am setting up an inhouse network that links together three machines, ... by 1) a misconfigured firewall or overlooked firewall (including stateful ...
    (microsoft.public.windows.vista.networking_sharing)