Can AD domains/forests (LAN & DMZ) share a DNS domain?

From: Erick Thompson (ethompson)
Date: 09/25/02


From: "Erick Thompson" <ethompson at nbr.org>
Date: Tue, 24 Sep 2002 16:04:41 -0700


I am going to be setting up a new AD network. The network has 3 parts
(subnets), the LAN, a DMZ with the SQL Server, and a public network,
connected with a firewall/router. The public network won't be part of the AD
structure. My current plan is to set up AD in the following way.

1. Create a forest and nbr.local domain in the LAN
2. Create a new forest for the DMZ and a dmz.nbr.local domain
3. Make dmz.nbr.local trust nbr.local but not vise versa (so I can use
integrated security in SQL)

Is this going to work? Is this a good way to partition security?

My main concern is that the forest dmz.nbr.org is a subdomain of nbr.org, at
least as far as DNS is concerned. I could see this causing me problems (two
forests sharing a domain). Also, this is the solution I have come to so far,
but I'm sure there other ways. I'd really like to hear how other people
setup this type of network.

Thanks,
Erick



Relevant Pages

  • Re: Win3k Forest Trusts
    ... DMZ and Internal network are their own Forest both running Win3k with SP1. ... We have a firewall sitting between the two domains and we opened the necessary ports between them according to this MS link. ... The problem comes when we are on our DMZ SQL server and try to add a new login with an AD user in the other forest. ...
    (microsoft.public.windows.server.general)
  • Re: Issue connecting through firewall using jdbc connector.
    ... Web applicationin DMZ ... SQL Server on internal network ... Not a solution for us, though, since the web master has set up a Microsoft network within the DMZ. ...
    (microsoft.public.sqlserver.jdbcdriver)
  • Re: Changing Domain Name
    ... VPN connections have been severed, and the sellers AD objects, as far as I ... I USED to be a network admin for a few years but have found ... > You HAVE to set up a new forest for the buyer and migrate the appropriate ... to this new forest. ...
    (microsoft.public.windows.server.setup)
  • Re: Do i need to create a site in AD?
    ... site, in AD, do i need to configure my network id and subnet for the remote ... domains in the AD forest. ... We now are connecting a remote site over ... and if so do i need to create a site link, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Exchange 2003 Design Issues
    ... the internal network, or 3 domains internally. ... domains in a forest make the forest more of a security boundary than a ... When we add users to the staff or student domain we want the exchage server ...
    (microsoft.public.exchange.design)