Solved

Active Directory trust setup

Posted on 2006-11-07
7
1,963 Views
Last Modified: 2012-05-05
I have two seperate networks (Office network, web farm network). Both are Windows 2003 server. I currently have an active directory domain in the office network. I want to create a domain for the web farm but have it seperate from the office domain. I want there to be a one way trust to where object in the office can access object in the web farm, but the web farm cannot access object in the office.

Can someone explain what I need to do for the web farm? Do I need a Domain In A New Forest? Child domain in an existing domain tree? Or domain tree in an existing forest?

Thanks in advance
0
Comment
Question by:periker
  • 2
  • 2
7 Comments
 

Author Comment

by:periker
ID: 17892117
I'm going with a seperate forest & domain so I can do a one way trust. I'm open for any suggestions though.
0
 
LVL 48

Accepted Solution

by:
Jay_Jay70 earned 63 total points
ID: 17893665
Morning,

you do either/or really, if you create forests then you will need a forest trust, which is a little more segmenting than a single forest with two domains. For your scenario i would have created a new domain in a separate domain in an existing forest.

Can i ask why you would like to keep them separate, i mean, if its for business reasons then fair call, but if not then you might find it much easier to have a single domain, just a thought

http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/activedirectory/maintain/opsguide/part1/adogd05.mspx
0
 

Author Comment

by:periker
ID: 17893681
For security purposes. If my remote site gets broken into, it does not have access to my home office.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17893798
fair enough, you can secure it down pretty heavily with a single AD but I can understand your concern as well
0
 
LVL 9

Assisted Solution

by:vsg375
vsg375 earned 62 total points
ID: 18092506
Hi,

If you add a new domain to an existing forest, 2 way transitive trusts will automatically be generated, which means potential trouble.

Creating a new forest is OK, BUT :

1. It will generate much more administrative overhead
2. Cross-forest trusts ONLY work @ full native 2003 forest functional level. In ALL other cases, there is no way to establish a full forest trust, even one way. You would have to do it the old way, on a per domain basis.

Conclusion :

If you don't mind the administrative overhead, and have only one domain in your home office, create a new forest for your web farm, make sure the functional level is not raised to full native 2003, and establish a one way trust between home domain and web farm domain. Security shouldn't be compromised that way.

HTH
Cheers
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Preface Having the need * to contact many different companies with different infrastructures * do remote maintenance in their network required us to implement a more flexible routing solution. As RAS, PPTP, L2TP and VPN Client connections are no…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now