Link to home
Start Free TrialLog in
Avatar of ironkernel
ironkernel

asked on

Remote Authentication over site-to-site VPN

Please review the attached. I'm trying to configure NT Domain Authentication via a site-to-site VPN using a Sonicwall and both ends. Looking for experience and ideas.
Thanks
Visio-Remote-Office-2.pdf
Avatar of Blue Street Tech
Blue Street Tech
Flag of United States of America image

Hi ironkernel,

I'd recommend the following:
1. Keep authentication local, install a local DC and ensure DHCP is installed on the DC - I'd have a second DC at the remote office if possible that way you not only have built-in redundancy for your DC but replication traffic is far less significant than the traversing everything over the VPN plus its a Best Practice.
2. Create a Site in AD Sites and Services and add the subnet IP to this site
3. Make sure your DC is configured as a GC (AD Sites and Services)
For whatever reason if you cannot install a local DC and DHCP then I would recommend to create a new scope on one of your DHCP and then configure IP Helper address.  

With virtualization technologies today, I recommend you entertain option 1 mentioned above.
ASKER CERTIFIED SOLUTION
Avatar of Jeffrey Kane - TechSoEasy
Jeffrey Kane - TechSoEasy
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of ironkernel
ironkernel

ASKER

This is what has been eluding me. Thanks.