?
Solved

One domain for many network subnets

Posted on 2010-08-24
8
Medium Priority
?
380 Views
Last Modified: 2012-06-27
We are having four networks connected together by a cisco pix. Network one has Domain controller, DNS and DHCP installed we dont want to repeat this on all the different networks since they are interconnected and we don't want to use the concept of child domain. The other networks have different subnets i.e.
Network 2 10.10.2.-
Network 3 10.10.3.-
Network 4 10.10.4.-
We want to join computers from this networks to our main domain which has the address of 10.10.1.- Can we do any configuration in our cisco pix router so that the four networks will be seen as one even-though they are in different networks. or how can we achieve this. Note we can ping from any of this locations to another.
0
Comment
Question by:Atouray
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
  • +2
8 Comments
 
LVL 57

Accepted Solution

by:
giltjr earned 668 total points
ID: 33509668
You can't make the 4 IP subnets appear as a single IP subnet, it just does not work.

However, you don't need to.  All you need to do is make sure that you allow all of the needed protocols to pass from one IP subnet/Interface to another.

For the DHCP you need to configure the PIX (assuming you have 6.3 or newer) with the dhcp relay option, this will allow the dhcp requests to be forwarded to your DHCP server.

Here is a starting point for what UDP/TCP ports you need to allow to pass through between the IP subnets.

     http://support.microsoft.com/kb/832017
0
 
LVL 6

Expert Comment

by:Elwin3
ID: 33509684
Assuming all networks can access other networks then as long as you add the domain controller as the DNS server on the client then it will work fine.
0
 
LVL 39

Assisted Solution

by:Krzysztof Pytko
Krzysztof Pytko earned 668 total points
ID: 33509800
Yup, Elwin3 is completely right. But I would use additional DC in your network to provide redundancy. In case of one of them will fail you have second DC and your environment will work. You wrote about 4 subnets but did not tell us about amount of users? It is also domain requirements factor. You would notice some problems during morning logon hours if you use only 1 DC.
0
Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

 

Author Comment

by:Atouray
ID: 33509933
So you mean if I try to add a client in network in network 2 to the main network it should work without an y further configuration?
0
 

Author Comment

by:Atouray
ID: 33509935
We have about 96 users in total. These users do not do much on the network apart from login to the their machines. All the work is done on the SQL server.
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 33509952
It should be enough having 2 DCs. Yes if router knows AD location and you set DNS IP on each machine they will join to the domain.
0
 
LVL 57

Expert Comment

by:giltjr
ID: 33511187
As long as your firewall allows all of the necessary traffic to flow to/from each IP subnet you should not need to do anything.
0
 
LVL 3

Assisted Solution

by:JDavis1
JDavis1 earned 664 total points
ID: 33513057
Your configuration is pretty common. It is not at all unusual for machines in different IP subnets to belong to the same Windows domain.  You just need to set up AD in Windows Sites and Services correctly. And as giltjr stated you need to do some configuration on your network devices in order to forward the DHCP traffic correctly.   If the Pix has an interface on the user user subnets then you need to configure DHCP relay on the Pix as he said.  If there are routers between the firewall and these subnets then DHCP forwarding needs to be configured on those routers.
0

Featured Post

New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question