Networking Forums

Networking Forums > Computer Networking > Windows Networking > Domain Controller Through VPN Tunnel

Reply
Thread Tools Display Modes

Domain Controller Through VPN Tunnel

 
 
T. Garay
Guest
Posts: n/a

 
      09-14-2006, 07:18 PM
I am working to setup a disaster recovery site and I've created a
domain controller (Win2k3 Server Standard).

I have a site-to-site VPN setup using SonicWALL firewalls. For
testing purposes I have a cable line in our building and I've setup a
site-to-site VPN with that to our regular ISP Internet firewall.

When I set this new DC up, I placed it on the VPN network and used
DCPromo to make it a domain controller. We have two domain
controllers on our regular LAN.

I am now running into a problem where some users are being
authenticated to that server which is REALLY SLOW because it is
through the VPN connection.

I want the server active so that it has a current copy of the Active
Directory database but I don't what users or devices authenticating to
it.

Is there some way to block it in Windows or demote it so that it's the
last server anyone or anything tries to connect to?

My only other option would be to block it in the firewall so that only
the existing DC's can see it through the VPN to maintain the the AD
database.

Thanks!

-Tim
 
Reply With Quote
 
 
 
 
Michael Giorgio - MS MVP
Guest
Posts: n/a

 
      09-15-2006, 01:42 PM
You may want to look at the following:

How to optimize the location of a domain controller or global
catalog that resides outside of a client's site
http://support.microsoft.com/kb/306602/en-us

"T. Garay" <moc.etluhcS-noirehpS@yhtomiT> wrote in message news:
>I am working to setup a disaster recovery site and I've created a
> domain controller (Win2k3 Server Standard).
>
> I have a site-to-site VPN setup using SonicWALL firewalls. For
> testing purposes I have a cable line in our building and I've setup a
> site-to-site VPN with that to our regular ISP Internet firewall.
>
> When I set this new DC up, I placed it on the VPN network and used
> DCPromo to make it a domain controller. We have two domain
> controllers on our regular LAN.
>
> I am now running into a problem where some users are being
> authenticated to that server which is REALLY SLOW because it is
> through the VPN connection.
>
> I want the server active so that it has a current copy of the Active
> Directory database but I don't what users or devices authenticating to
> it.
>
> Is there some way to block it in Windows or demote it so that it's the
> last server anyone or anything tries to connect to?
>
> My only other option would be to block it in the firewall so that only
> the existing DC's can see it through the VPN to maintain the the AD
> database.
>
> Thanks!
>
> -Tim



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted. Ace Fekay [MVP-DS, MCT] Windows Networking 1 01-10-2010 11:08 PM
Domain Controller Con't Patrick Whittle Windows Networking 9 08-08-2009 10:33 PM
Clients can't join domain-new Primary Domain Controller installed blinton25 Windows Networking 7 06-23-2008 09:58 PM
Server 2003 Standard - Cannot browse domain with domain controller! davidw@dwynn.demon.co.uk Windows Networking 2 04-12-2006 04:28 PM
Moving a domain 2003 domain controller to a different subnet John zhang Windows Networking 1 07-27-2004 01:41 PM



1 2 3 4 5 6 7 8 9 10 11