|
Question : Multiple domains on one network
|
|
I need to host a standalone and self contained AD/Exchange server on my network for a while and I wanted to check whether there's anything I should be aware of. Are there any issues with having two AD domains running on the same internal network?
For the time being there are not going to be any users logging on to the second domain--the box will be used purely as an Exchange server for another branch of the organisation. Users will access from inside and outside of the network via RPC, RPC/HTTPS and SMTP/IMAP. The new Exchange box is running AD, DNS (for network2.local) and Exchange 2003 Standard.
How should I configure the DNS on the second machine, pointing to the main internal DNS server also resolving network1.local or directly to the main gateway and external DNS?
Do I need to configure trusts between the two networks? So far as I can make out I don't as there is no need for interaction between the two domains. Maybe only if I want to point to the internal DNS server.
I hope that all made sense. I don't think this is a complicated nor uncommon situation. I just wanted to check that there aren't any hidden gotcha's like domain controllers silently fighting for attention etc.
|
Answer : Multiple domains on one network
|
|
there should be no problem running 2 AD's on the same subnet. As long as you disable DHCP on one of them. you may have to sligly overlap them some because of drive shares and permissions. whichever domain you log into is the one that will be handing out the security rights to the shares. if you have one person loging into domain A and they have a share on domain B you will have to go to that share and add the user or users from domain A on that share.
as far as the DNS, you can configure that separate or you can forward all domain request to the other server. either should be fine. You do not want to forward the request to external server. you want the flow to go to the domain that is doing the DNS and authentication. so if domain A is the one they log into, the fow should be domain B --> domain A--> external dns (if you want external lookup's)
|
|
|
|