How to separare PCs into 2 networks within same AD

  • Thread starter Thread starter Ihab Abedrabbo
  • Start date Start date
I

Ihab Abedrabbo

I have only one Active Directory of Windows 2000. I need
to separate 2 groups of computers and users from each
other. Users and computers from group A should not access
computers and/or files on group B.

Users in my domain are temporary users, so they are easily
created, deleted, and renamed. it is difficult for me to
keep track of all users, add them and remove them from
groups... etc. and thus I'm searching for a quick solution.

I also have 3Com and CISCO switches of Layer 3, and I
already made some VLANS, but the problem is that some PC
of group A are on the same VLAN as group B "This might be
re-arranged though"

How can I separate Group A from Group B, using GPO "I
prefer this solution", or using my existing technology
without the need to buy or use a third party application
or hardware?

Thanks
 
If you want to restrict network access and even network visibility, you have
to use a Firewall, a router with port filtering, VLANs etc. If you have less
strict requirements and only need to restrict access to certain network
resources, it can be achieved a bit easier. Use NTFS on your file servers,
set up permissions on all the shares and add users to groups controlling
access to these resources according to their needs.
 
Back
Top