patriots
asked on
Best way to secure a 2008 R2 DC?
We are a college campus. We are in the middle of an Active Directory roll-out. We'd like to configure a domain controller on our student segment, which is separated from faculty and staff by a firewall. We are considering simply creating a firewall conduit, permitting the student segment DC to communication with the rest of the DC's on the faculty/staff side. However, we have some questions:
1. If we don't want to use an RODC, or server core installation, are there best practices for securing a full installation of a 2008 R2 DC?
2. The DC needs to be a DNS server as well. We prefer AD integrated DNS. Therefore, this means the DC would have a full copy of our faculty/ staff zone since it will replicate with other DC's on that segment. Are there things we should consider from a security stand point with this configuration?
Goal: accomplish our task according to best practices, and with the most security possible.
If we have to do server core, I'm familiar with how to configure it. I'm aware of the requirement to use command line tools, however, you should still be able to use ADUC to manipulate it remotely.
1. If we don't want to use an RODC, or server core installation, are there best practices for securing a full installation of a 2008 R2 DC?
2. The DC needs to be a DNS server as well. We prefer AD integrated DNS. Therefore, this means the DC would have a full copy of our faculty/ staff zone since it will replicate with other DC's on that segment. Are there things we should consider from a security stand point with this configuration?
Goal: accomplish our task according to best practices, and with the most security possible.
If we have to do server core, I'm familiar with how to configure it. I'm aware of the requirement to use command line tools, however, you should still be able to use ADUC to manipulate it remotely.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Another option is to setup a separate forest with a one way or two way trust. It depends on what resources you want to make to whom.