Re: 2 DC's in single domain with 2 Vlans



Domains have absolutley nothing to do with IP Segments.
IP Segments have absolutely nothing to do Domains.

Define "see each other"?
If you want to block something,..then block it,...but just it,...you can not
simply "cut off" the two IP Segments from each other and expect the Domain
to survive.

Routers are Layer3 with a relationship to Layer4,...security does not begin
and end with Layers3 & 4. Blocking something with a Router ACL is not the
only way to deal with security.

Security is about controlling access to Resources. Controlling access to
Resources depends on what the Resources are and what function, application,
or service that "provides" the Resources to the users. Ask yourself how you
would handle this if they were all on the same IP Segment,...the correct
answer to that question is your answer.

Router ACLs are only for "broad & crude" access controls.


--
Phillip Windell

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


"maki" <maki@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:1D32FFEC-8246-477B-81E2-18439DEE9130@xxxxxxxxxxxxxxxx
I've got a question about this scenario: same company, two different staff
groups: Staff A and Staff B. Each one is separated by different vlans. So
one is on for instance 172.16.a.b network and the other is on a
192.168.16.a
network. They should not see each other at all. Now, if the domain is
called
company.com, can I assume that:
1. I can create 2 DC's with Active Directory - one for each group of staff
and call them staffA.company.com and staffB.company.com? Remember staffA
is
on 172 network and staffB on 192...Oh, also - each server is also a
DHCP/DNS/Printer/Antivirus server as the company doesn't have enough money
to
follow Microsoft recommendations. I am trying to picture if I go to a
membr
of Staff A and want to join his computer to the domain - what do I type in
the domain bit when joining the computer? company.com or
staffA.company.com?
Do I just let te ip address help direct the computer to the particular DC?
How would I connect them to particular DC they should belong to? Or do I
need
to create parent site company.com and then child sites staffA.company.com
and
staffB.company.com?

2. If the 2 DC's can be within same domain as above initially thought -
what
if I add a mail exchange server called mail and only want it to be for
StaffA
(staffB have no need to use email server) - can I just connect
staffA.company.com to mail.company.com? I assume staff B will not be able
to
see the mail server then?

Am new at all this so was just wondering.

Thanks.


.



Relevant Pages

  • Mapped Drive Not Opening on Double Click but on Explore
    ... Just bought new Dell Latitudes E6400's to replace old Latitude's and ... We've got server 2003 and a mapped shared drive with staff ... When we double click on the mappe shared drive with staff ... resources it says access denied, yet by typing Z: ...
    (microsoft.public.windowsxp.general)
  • RE: [fw-wiz] segmentation of DMZs
    ... Internet will be able to try to compromise your front-end web server. ... different segments: ...
    (Firewall-Wizards)
  • Re: 2 DCs in single domain with 2 Vlans
    ... Staff A and Staff B. Each one is separated by different vlans. ... DHCP/DNS/Printer/Antivirus server as the company doesn't have enough money ... that has the authority to join a pc to the domain. ... Yes all can ping this Exchange server but only those given an account within ...
    (microsoft.public.windows.server.active_directory)
  • Re: Confused engine: No SHM segments but thinks it is quiescent
    ... That tidbit about not running ipcs -m as root was an interesting one; ... I have never encountered an informix server with invisible SHM ... Normally, even when owned by root, I can see the segments in ...
    (comp.databases.informix)
  • Monitoring Performance
    ... We are shortly to open a branch office, initally to hold 2 staff and to ... We have a 2.5 GB Exchange Server that will be replicated to the remote site. ... FRS to the remote server (I know roaming profiles replication is not ...
    (microsoft.public.windows.server.sbs)