Networking Forums

Networking Forums > Computer Networking > Windows Networking > Question about configuring 2 DC's for 2 different domains on the same wire.

Reply
Thread Tools Display Modes

Question about configuring 2 DC's for 2 different domains on the same wire.

 
 
AlvinG
Guest
Posts: n/a

 
      03-05-2008, 02:20 AM
I have a small workgroup of about 30 computers, and they are physically
connected to a large network for Internet access only. They are not apart of
Domain XYZ, but they are DHCP enabled and get their IP addresses from Domain
XYZ.

In my workgroup, I have users who need security on their files, folders, and
I need to create shares which will be located on one centralized computer.
So to minimize the overhead of administration, I'd like to setup a DC to
create a domain for the workgroup computers, but it MUST, (this is most
important) be completely non-existent to the DC's on Domain XYZ.

I'm not sure if this is possible or if it is how to go about it.

I've read several articles saying that multihomed isn't the best way to go
with server2K3. One article suggested configuring RRAS. I don't know if I
could just take a Dlink router or any retail router for that matter, and
just NAT between Domain XYZ and the new Domain ABC of 30 computers, and use
private addressing in Domain ABC.

What's the best way to do this or is it even possible?

Thanks


 
Reply With Quote
 
 
 
 
Bill Grant
Guest
Posts: n/a

 
      03-05-2008, 04:52 AM
Yes, you could set up a second domain on the network behind a NAT router.
But it would be better if they were no longer actually "on the same wire".
They would be better located on their own switch. Only the NAT router would
have a connection to both networks.

You could use a hardware router for this, but I wouldn't recommend one
of the SOHO ADSL routers. Or you could use a server running RRAS, but not a
DC. I would not even make it a member of either domain. Just run it as a
dedicated router.

Don't use the address translation or mini-DHCP options in the NAT
router. All machines should use the local DNS for name resolution, and you
can set this DNS server to forward to a DNS server on the "parent" network
so that it can resolve both local and public URLs. Just use the router as a
NAT router to give the inner domain machines access to the public network.
If they are on a separate switch you can even use DHCP on the DC for your
inner network.

You can also access machines on the existing domain if you need to, but
they cannot get to your machines. NAT is a one-way address translation.
Private machines can see out, but public machines cannot see in.

The references to "public" are only in relation to the NAT router. This
will still work even if your existing domain is actually on a private
address scheme. I have a domain set up like this using virtual machines.
They run in a 192.168.31.0/24 subnet on a virtual network behind a RRAS
NAT router. The "public" side of this NAT router is actually in a 10.0.0.0/8
subnet behind a hardware NAT router.

"AlvinG" <(E-Mail Removed)> wrote in message
news:ueV9m$(E-Mail Removed)...
>I have a small workgroup of about 30 computers, and they are physically
>connected to a large network for Internet access only. They are not apart
>of Domain XYZ, but they are DHCP enabled and get their IP addresses from
>Domain XYZ.
>
> In my workgroup, I have users who need security on their files, folders,
> and I need to create shares which will be located on one centralized
> computer. So to minimize the overhead of administration, I'd like to setup
> a DC to create a domain for the workgroup computers, but it MUST, (this is
> most important) be completely non-existent to the DC's on Domain XYZ.
>
> I'm not sure if this is possible or if it is how to go about it.
>
> I've read several articles saying that multihomed isn't the best way to go
> with server2K3. One article suggested configuring RRAS. I don't know if I
> could just take a Dlink router or any retail router for that matter, and
> just NAT between Domain XYZ and the new Domain ABC of 30 computers, and
> use private addressing in Domain ABC.
>
> What's the best way to do this or is it even possible?
>
> Thanks
>


 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Disconnecting ringer wire question Tim Downie Broadband 44 05-02-2012 01:51 AM
A different Disconnecting Ringer wire question Davey Broadband 3 04-24-2012 05:59 PM
two domains question Tcs Windows Networking 6 02-23-2006 07:16 PM
crazy question: temporarily blocking self from selected domains? Jim Linux Networking 2 02-25-2005 08:42 PM
Wire less Hub / broadband modem question? Philip Home Networking 0 07-19-2003 01:12 PM



1 2 3 4 5 6 7 8 9 10 11