Solved

Changing Active Directory Domains

Posted on 2013-10-30
3
218 Views
Last Modified: 2013-11-06
Hoping someone can help with a Domain change.  I'm overwhelmed and can't think clearly.

I need to merge (sort of) two separate domains.

Domain 1 is:
     - using SBS (which I want to do away with)
     - with the domain name of citylan
     - with the scope of 172.16.3.XXX
     
Domain 2 is
     - using server 2003
     - with the domain name of annexlan
     - with the scope of 192.168.1.XXX

I want to end up with (I think):
    - Forest of citylan
    - Sites for chlan (changing everyone currently on citylan to this one) and annexlan
    - Everyone using 192.168.1.XXX except for a few computers that need to remain on     172.16.3.XXX


Everyone can use the same gateway except for a few computers.  I currently have two routers/firewalls on each network and there is fiber running between each site.
Just need sites to be able to share resources yet be restricted from full access to other sites computers.

Losing connectivity has to be minimal as this is a 24/7 operation.

I'm not sure if I need to get a third server and build it this way and manually enter each user (ugh) or raise a domain level and merge the other....

Any help is super appreciated!
0
Comment
Question by:carolinasgirl28
  • 2
3 Comments
 
LVL 45

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 39612033
Bit messy, but you'd have to perform a migration to a new domain from the SBS box - at the very least.  This would require a new/temporary server.

I would create a new domain, then migrate the users/data from the SBS domain and the annexlan domain to the new domain.  You can do this easily using domain trusts.

I'd treat the site connectivity restrictions as a separate issue.  This is what a firewall is for - not domain security (this is an additional layer).
0
 

Author Comment

by:carolinasgirl28
ID: 39622599
How would you handle the two computers that need to stay on the 172 domain?
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 39622666
Exactly the same.

Unless you've got DCs in separate sites, on separate IP ranges, you don't need to worry about this from an AD perspective.  This isn't really an issue with clients.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now