Solved

LDAP Traffic between Domains

Posted on 2016-09-01
2
21 Views
Last Modified: 2016-10-22
We have recently added our first child domain into our forest and we are currently seeing LDAP traffic between the root and child domain which we were not expecting. We have noticed that all of our root domain PCs seem to be sending LDAP packets to the child domains DC when logging on, unlocking PCs etc. Is there any way of preventing the traffic between the domains? Any advice on the matter would be highly appreciated. Thanks.
0
Comment
Question by:stanleyltd
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 41

Accepted Solution

by:
Adam Brown earned 500 total points
ID: 41780184
There isn't a way to prevent LDAP traffic between domains in the same forest. At least, not if you want AD to function properly. Domain Joined computers have the capability of accepting logins to any domain in the same forest. The LDAP traffic you're seeing from the root domain computers to child domain DCs is a lookup to ensure the child domain is available for login if needed. This is normal. The only way to stop unwanted intra-domain LDAP lookups (aside from using a firewall, which would likely cause tons of unwanted error messages) is to have the domains in separate forests and utilize selective authentication to prevent each domain's systems from being able to authenticate against the other domain.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question