[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

difficulty in adding a second domain controller windows 2003 server

Posted on 2006-06-30
4
Medium Priority
?
303 Views
Last Modified: 2010-04-18
Hi Experts,
I have a DC running 2003 enterprise AD
i have 3 other servers, all on the same domain.
One of my servers is in the DMZ and serves as a Secure Gateway for a citrix server.
Some of the reading I have done suggests it is not a good idea to keep the SG server on the same domain as the rest.
How difficult is it to make that SG server a domain controller (probably using the wrong term)  

I would like the SG to have abc.com domain instead of the abc.net domain.

If you could give me a step by step on this I would appreciate it.  I'm not an expert.
0
Comment
Question by:Quadeeb2003
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 51

Expert Comment

by:Netman66
ID: 17021630
Is it necessary to even have the DMZ server be a DC?

You should be able to setup this server to host an IIS (web) front-end for the Citrix server and have clients connect using the ICA client.  This way only a very small hole needs to be open to the real domain.

0
 
LVL 1

Author Comment

by:Quadeeb2003
ID: 17021685
I have SG server hosting IIS and WI, but it is on the same domain.
A benefit of switching the server to its own domain is I can use an outside CA certificate for my server on that domain.  The FQDN of my internal network cannot have a outside CA certificate because the domain is public.  ABC.net for example.
If the SG server becomes a DC for a different domain, I make a few trusts from my DC, and I would imagine I would be in business.

It is a new server, there are no apps other than citrix, and reinstalling would be a snap.
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 2000 total points
ID: 17021704
I suppose it would work although I'm not sure you really need it to be a DC.  You should be able to use ADAM for authentication and keep it entirely separate.

However, yes, I agree that a different domain would be proper - if the current domain was compromised then your entire AD would be exposed.

0
 
LVL 1

Author Comment

by:Quadeeb2003
ID: 17022207
So, any idea how to get it done?
0

Featured Post

NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Learn about cloud computing and its benefits for small business owners.
Have you created a query with information for a calendar? ... and then, abra-cadabra, the calendar is done?! I am going to show you how to make that happen. Visualize your data!  ... really see it To use the code to create a calendar from a q…
In this video, Percona Solution Engineer Rick Golba discuss how (and why) you implement high availability in a database environment. To discuss how Percona Consulting can help with your design and architecture needs for your database and infrastr…
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question