Re: Two domains - creating one



Hi
Inline
We would like to create on forest and just have two domains under that
forest.

What do you win with that?

But we are concerned because of the degree that the firewall between
the two sites is locked down.

If security is very important and you don't want to take risks, use a
dedicaded line for internal communications.

The other problem is that the network on the
secure side is in mixed mode with some W2K shares still on their network.
Why this is a problem, aren't you trying to move to only one Domain, that
means that everybody belongs to the same forest, of course that DFL may be
considered less secure, in that case you'll need to move to next level wich
is 2000 Native, just make sure that no NT4 DCs are in the domain or they'll
loose the ability to communicate with 2000 DCs.

The other network is running in native mode on W2003 R2. We are also
concerned with the opening in the firewall that will be needed for that
domain traffic.
You have VPN connections or dedicated lines to communicate, using FW between
those comunications you'll need to open ports, otherwise no communications
are allowed you can't run from this.

Our current solution is to create all the users from the sensitive domain
in
our domain and just make them authenticate here for e-mail (most will use
OWA
anyway). It will just be labor intensive to create all these users and
then
we will have to manage them from this point forward.
You can always export the users, but, as you said you'll need to maintain
them separately

--

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MCSE, MVP Directory Services

"Joan" <Joan@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:35A3ECB3-1F4B-4899-9BEA-3F9502F407CF@xxxxxxxxxxxxxxxx
Scenario:

We have one network but two completely separate domains with a firewall in
between (one domain has very sensitive data). We are currently
implementing
Exchange 2007. Because of its heavy dependency on AD we have hit a few
stumbling blocks.

We would like to create on forest and just have two domains under that
forest. But we are concerned because of the degree that the firewall
between
the two sites is locked down. The other problem is that the network on
the
secure side is in mixed mode with some W2K shares still on their network.
The other network is running in native mode on W2003 R2. We are also
concerned with the opening in the firewall that will be needed for that
domain traffic.

Our current solution is to create all the users from the sensitive domain
in
our domain and just make them authenticate here for e-mail (most will use
OWA
anyway). It will just be labor intensive to create all these users and
then
we will have to manage them from this point forward.

Any suggestions?

Thanks for your help!



.



Relevant Pages

  • Re: Win3k Forest Trusts
    ... DMZ and Internal network are their own Forest both running Win3k with SP1. ... We have a firewall sitting between the two domains and we opened the necessary ports between them according to this MS link. ... The problem comes when we are on our DMZ SQL server and try to add a new login with an AD user in the other forest. ...
    (microsoft.public.windows.server.general)
  • Re: Urgent - Windows 2003 Trust and NAT
    ... the proper ports opened so communications between the two forests can occur. ... Select articles and click on firewall ports needed for replication. ... I have a windows 2003 forest that is behind a NAT firewall. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Changing Domain Name
    ... VPN connections have been severed, and the sellers AD objects, as far as I ... I USED to be a network admin for a few years but have found ... > You HAVE to set up a new forest for the buyer and migrate the appropriate ... to this new forest. ...
    (microsoft.public.windows.server.setup)
  • Re: Do i need to create a site in AD?
    ... site, in AD, do i need to configure my network id and subnet for the remote ... domains in the AD forest. ... We now are connecting a remote site over ... and if so do i need to create a site link, ...
    (microsoft.public.windows.server.active_directory)
  • Re: upgrade plan to 2008
    ... Control Panel \ Network Connections ... If you do not plan to use IPv6 i would uncheck it on all Server NIC's. ... I am putting together a basic procedure for upgrading the AD forest ...
    (microsoft.public.windows.server.active_directory)