"robert.waters" <(E-Mail Removed)> wrote in message
news:3cfe268b-f3ce-4a10-91ce-(E-Mail Removed)...
> I have questions like:
> - Should I change the name of the internal domain, in order for
> internet-facing hosts to have the proper domain name?
No. It is unrelated, they have nothing in common beyond both being spelled
"d-o-m-a-i-n".
> Is this even necessary?
No. It is unrelated, they have nothing in common beyond both being spelled
"d-o-m-a-i-n".
Is this what is typically done?
No. It is not.
> - Do I need a second domain?
No.
> - What separation should there be between internal and external
> resources, if those resources are sometimes shared?
There is no separation because there is no relationship,....so there is
nothing to "separate".
> - If I have a server that lives in the public facing domain, how do I
> allow clients from the internal domain to access it's services in an
> AD-integrated fashion? (i.e. trust)
"lives in the public facing domain,"?. Well, servers don't live in domains
they live on a networks, so what network does it actually live in? Domains
are not networks,...networks are not domains.
You're making way more of it than there actually is. It is simple as this:
Create a New "non-AD" Zone on your AD/DNS Server. Add whatever Records are
required. If the target machine is already a Domain Member on the LAN then
use a CNAME entry in the new Zone that points to the correct "A" Record in
the AD Zone,...if the machine exists outside the network and outside of AD
then use an "A" Record instead of a CNAME.
The Public resolves your Public Names via the ISP's DNS (not your DNS).
The LAN Users resolve your Public Names via your AD/DNS (not the ISP's DNS)
Hence the term "Split-DNS".
Therefore your users may resolve the same Name to an Internal IP# or any IP#
you specify,...while at the same time the Public users always resolve to a
Public IP#.
Make sure internal LAN Machine resolve to the correct LAN IP# (not a Public
IP).
Do *not* try to make "U-Turns" with the Firewall.
--
Phillip Windell
www.wandtv.com
The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------