Setting Up a Trust Between External Domains, IP Forwarding

Posted on 2011-04-19
Last Modified: 2012-05-11
We recently merged our company with 2 of our sister companies.  At this time, we are looking to establist a trust between our company domain and one of the two sister companies (located in a different state) so users at one site can access resouces (files) at the other.  

We would set up a VPN between our networks to provide the connectivity.  Once thats in place, I understand how to setup the trust between the two domains.  My question that I am unclear on, is once the trust is in place I understand we need to setup each of our DNS servers to have the others entries.

In reading it appears we would setup a forworder on each of our DNS servers pointing to each others.  

Coming in through a VPN, do each of us need to be concerned with what the others internal IP scheme is?  If internally both companies use 172.16.X.X as their IP scheme, can computers at one site have the same IP on their ntwork as a computer on the other domain, and can DNS etc keep it straight.

I am also seeking some documentation from our firewall vendor to better under stand how the IP scheme would work through a VPN.

Have never worked with a domain trust, so pardon the questions.
Question by:hamblin-d
    LVL 38

    Accepted Solution

    If both sites have the exact same IP scheme, you're going to run into problems with connectivity over a VPN, if one can even be established with such a setup. If one site is 172.16.1.x and the other is 172.16.1.x, any attempt to ping (for example) on either network will never traverse the VPN because it's considered local. If, however, 172.16.2.x and 172.16.3.x are the local subnets for each site (with the appropriate subnet mask of then communication should go okay as long as the appropriate routing is in place.

    As for DNS, you'll actually want to utilize Stub zones instead of using Forwarders. This speeds DNS resolution considerably and just plain works better. has information on Stub Zones in windows DNS.

    Author Comment

    Thanks, I will read up on the stub zones.

    Again pardon my ignorance, but is there a better way to connect the two networks than a VPN between our two firealls?  Would it get us around any possible IP conflicts?

    Very much open to suggestions here.
    LVL 38

    Expert Comment

    by:Adam Brown
    You could utilize a dedicated WAN link between sites, but those are generally very expensive and would run into the exact same problems with two sites on the same IP scheme.

    Author Closing Comment

    Yes, it turns out both sites use overlapping IP schemes.  One of the two would need to change.  Not sure we'd want to pursue a WAN link due to expense and long term goal of eventually creating a new single domain.


    Featured Post

    Maximize Your Threat Intelligence Reporting

    Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

    Join & Write a Comment

    I will assume you are running a non-server version of some sort of Windows throughout this article. There are many flavors of Windows since Windows Server 2000 - 2008, XP Home & Pro, Vista Home & Pro, and Windows 7 Starter, Home, Pro, Ultimate, etc.…
    Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
    This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

    732 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    21 Experts available now in Live!

    Get 1:1 Help Now