2000/2003 AD, Subdomains, and DNS Availability

K

Keith W. McCammon

All,

I have an AD named company.com. This is a Windows 2000 AD (if it even
matters, for our purposes).

I also have a remote site that needs to be managed, which I'd like to assign
the domain name pub.company.com. This is a Windows 2003 AD in a hosting
environment, and must be its own forest root--yes, we have child domains,
know all about them, but this isn't going to be one of them.

The reasons for this are both security- and availability-related. The
security-related reasons should be obvious. As far as availability is
concerned, this domain and environment must be able to function in the
absence of all of our other systems. Thus, creating a child and having to
rely on the forest root in company.com for selected authentication and
authorization services is not acceptable. Which brings me to my question:

What are the implications for pub.company.com if the company.com name
servers no longer exist or are unreachable? And if there are implications,
are they time-sensitive (I.e., pub.company.com will be happy without
company.com for X days, etc.)?

As its own forest root, I'm not worried about authentication within
pub.company.com in the absence of company.com. I am, however, worried about
any of the usual AD caveats, such as a default setting that tells a
sub-domain that it must be able to reach its parent once every X days, or
else it starts generating all kinds of irrational errors, shutting itself
down when it knows the operators are asleep, growing legs and running away,
etc.

Any feedback, experiences and input are appreciated.

Cheers

Keith
 
C

Chriss3

Hello Keith, (I'm not sure I'm understand what you are asking for here)

How ever two forests are required if you need Autonomy and isolation. But
dose not need and are depend on replication between servers across Domain
Controllers in different forests.

You can setup forwarding between forests DNS.

If you create another domain in an existing forest and go for a single
forest design you have to trust domain admins in all domains, remember a
domain is NOT a security boundary. You will also have to replicate the
Configuration Partition and Schema Partition to all domain controllers
within the forest as by default every 15min.



I really recommend you to have a look at the Multiple Forests Considerations
White Paper:
http://www.microsoft.com/downloads/...cd-6c1c-4af6-8b2c-b604e60067ba&DisplayLang=en
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top