How To Force LDAP Queries Through One Domain?



When you login to a domain on a computer that is a member server in the
domain, and then create an ACL against a file that refers to entities in
other domains in the same forest, it appears that the LDAP query is placed
directly to the domain controllers for each domain you reference in the ACL.
I can see this in the firewall log pretty clearly (there is a firewall
between the clients and the domain controllers). Is there any way to
configure a client or its member domain's DC so that the LDAP queries for
entities in other domains go through the member server's domain as a proxy
for the other domains? I want to avoid the direct contact between the
computer that is a member server of a domain and the DCs of any other
domain.

Would this behavior be any different if the domains were in different
forests with a trust between them? In the case of a trust, where a user on
a member server logged into its domain creates an ACL on a file that
references a trusted domain, will the LDAP queries go directly to the
trusted domain's DC? Is there any way to stop that behavior?

--
Will


.



Relevant Pages

  • Re: How To Force LDAP Queries Through One Domain?
    ... directly to the domain controllers for each domain you reference in the ACL. ... I can see this in the firewall log pretty clearly (there is a firewall ... computer that is a member server of a domain and the DCs of any other ... will the LDAP queries go directly to the ...
    (microsoft.public.windows.server.active_directory)
  • Re: External trust and a member server
    ... I can ping the the trusted domains DC and nslookup also gives the correct ... I tried the connection from an ancient Windows NT member server that is used ... account is disabled in the trusted domain. ...
    (microsoft.public.win2000.active_directory)
  • DMZ Authentication
    ... This was nice for DMZ type ... a point that could authenticate against the internal ... if the member server cannot contact the DC ... of the trusted domain, it doesn't try its own PDC but just ...
    (microsoft.public.win2000.active_directory)
  • Re: Exchange 2007 System Attendant not starting automatically
    ... errors in the event viewer although we did get a message that states ... but our users on the trusted domain can't access email on that server ... And yes, Exchange 2007 ... Is this a member server or domain controller? ...
    (microsoft.public.exchange.admin)
  • Re: External trust and a member server
    ... account of domain B. Please test whether the user account of domain B can ... log on this member server successfully. ... Actually I don't know any user account's password from the trusted domain B. ... ensure that the SRV records are transferred from the primary zone ...
    (microsoft.public.win2000.active_directory)