Can AD domains/forests (LAN & DMZ) share a DNS domain?

From: Erick Thompson (ethompson)
Date: 09/25/02


From: "Erick Thompson" <ethompson at nbr.org>
Date: Tue, 24 Sep 2002 16:04:41 -0700


I am going to be setting up a new AD network. The network has 3 parts
(subnets), the LAN, a DMZ with the SQL Server, and a public network,
connected with a firewall/router. The public network won't be part of the AD
structure. My current plan is to set up AD in the following way.

1. Create a forest and nbr.local domain in the LAN
2. Create a new forest for the DMZ and a dmz.nbr.local domain
3. Make dmz.nbr.local trust nbr.local but not vise versa (so I can use
integrated security in SQL)

Is this going to work? Is this a good way to partition security?

My main concern is that the forest dmz.nbr.org is a subdomain of nbr.org, at
least as far as DNS is concerned. I could see this causing me problems (two
forests sharing a domain). Also, this is the solution I have come to so far,
but I'm sure there other ways. I'd really like to hear how other people
setup this type of network.

Thanks,
Erick



Relevant Pages

  • Re: Win3k Forest Trusts
    ... DMZ and Internal network are their own Forest both running Win3k with SP1. ... We have a firewall sitting between the two domains and we opened the necessary ports between them according to this MS link. ... The problem comes when we are on our DMZ SQL server and try to add a new login with an AD user in the other forest. ...
    (microsoft.public.windows.server.general)
  • Re: Issue connecting through firewall using jdbc connector.
    ... Web applicationin DMZ ... SQL Server on internal network ... Not a solution for us, though, since the web master has set up a Microsoft network within the DMZ. ...
    (microsoft.public.sqlserver.jdbcdriver)
  • Re: Changing Domain Name
    ... VPN connections have been severed, and the sellers AD objects, as far as I ... I USED to be a network admin for a few years but have found ... > You HAVE to set up a new forest for the buyer and migrate the appropriate ... to this new forest. ...
    (microsoft.public.windows.server.setup)
  • Re: Do i need to create a site in AD?
    ... site, in AD, do i need to configure my network id and subnet for the remote ... domains in the AD forest. ... We now are connecting a remote site over ... and if so do i need to create a site link, ...
    (microsoft.public.windows.server.active_directory)
  • Re: upgrade plan to 2008
    ... Control Panel \ Network Connections ... If you do not plan to use IPv6 i would uncheck it on all Server NIC's. ... I am putting together a basic procedure for upgrading the AD forest ...
    (microsoft.public.windows.server.active_directory)