Solved

site-to-site VPN domain help

Posted on 2006-11-30
4
212 Views
Last Modified: 2010-03-18
I have a site-to-site VPN that is currently working between two Cisco Pixs.  My current setup is:

Site A has no domain.  Site A has a Terminal Server (Windows 2003).  
Site B has a domain controller (Windows 2003).

Currently, Site A has users set up in "Computer Management" not Active Directory.  
Site B has users set up in Active Directory.

So all users have to connect to Site A's Terminal Server with one username and Site B's with another.  We would like to consolidate this, however, using our current hardware/software.

Microsoft suggests not making a Terminal Server a Domain Controller, and we don't want to have to buy another Windows Server 2003 to act as a domain controller at Site A.

How can we have Site A's Terminal Server authenticate through Site B's domain controller?  Additionally, is this wise?

Thanks!

0
Comment
Question by:eluh
  • 3
4 Comments
 
LVL 10

Expert Comment

by:MATTHEW_L
ID: 18053734
Simply joining those PC's in site a to the domiain including the terminal server will allow domain authentication.  This will occur over the WAN / VPN to the domain controller in site b.  This can be done and will work, but you need to watch out for bandwidth concerns as authentication traffic will be crossing the WAN.  If it is a small amount of users in this office it may not be bad.  Also, remember that you must point DNS to the domain controller for resolution.  So DNS traffic will have to cross the WAN as well.
0
 

Author Comment

by:eluh
ID: 18070013
What do I need to do on Site B's end?  I changed the DNS on Site A, but it can't find Site B's domain.
0
 
LVL 10

Accepted Solution

by:
MATTHEW_L earned 500 total points
ID: 18070653
Is the site a computers pointing to the dns server at site b?  If not this will not work.  Once this is changed you should be able to join the computer to the domain using the domain.com format or domain to join it.  From that point you should be able to authenticate with AD accounts to resources from either domain to either domain.
0
 
LVL 10

Expert Comment

by:MATTHEW_L
ID: 18079667
Did that work for you?
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Nslookup is a command line driven utility supplied as part of most Windows operating systems that can reveal information related to domain names and the Internet Protocol (IP) addresses associated with them. In simple terms, it is a tool that can …
Greetings, Experts! First let me state that this website is top notch. I thoroughly enjoy the community that is shared here; those seeking help and those willing to sacrifice their time to help. It is fantastic. I am writing this article at th…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now