Help - Search - Members - Calendar
Full Version: AD Sites and Services NAT subnets?
Neowin Forums > Windows Support > Windows NT4/2000/2003/2008 Server
burnham187
Currently there is many different forests, many
of which are still NT4.0. We are currently working on migrating all
of them, about 10 or so, to fall under our single domain, single
namespace. Our single domain will host about 20,000 users. There is
probably more than 300 different Class C address being used total
between all of the sites, all doing there own internal IP addressing
scheme. Currently all of their clients are servers are using private
addresses. The reason this isnt a problem now is because a firewall
takes care of the external to internal mapping to the correct
destination. We will be changing the structure to where the main
Domain controllers that will be at each site will have external IP
addresses. The problem is we wont be able to change the way they do
their internal Ip addressing for their clients, which is where some of
them may have the same internal Subnets as we have. So how do we set
up the AD sites and services. As I know you are aware, AD sites and
services is where you create the physical topology of all the sites by
defining all of the subnets for each site. First question is must we
even add the internal client NAT subnets to the correct sites, or can
we get away with just using the external subnets that the DC's are
going to be using for each site. If we do have to add the NAT
subnets, this will be a problem as some of the other sites are using
the same internal NAT subnets as we are. I know someone is going to say restructure
there ip scheme to where there is no duplicate subnets, but that may not be an option
for us. Thanks for the help ahead of time.
Mattimeo
I guess my first question would when you say external interfaces, that means public IPs? It would be a very bad idea to put your domain controllers on public interfaces.
burnham187
Thanks for the reply. Okay lets say that the DC's will stay on internal Ip addresses. This will be possible as we will be able to set up VPN's between the sites. What about the other sites that we cant controll their internal NAT Subnetes that interfear with other sites subnets meaning there may be a subnet of 10.10.40.0 in two or three different sites. Is this an issue in AD Sites and services? Thanks
Mattimeo
I would get a count of how many are the same. Changing them now will be better then in the long run.
burnham187
Thats what I figured I would have to do. Have to get my network engineers involved. thanks for the help again.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.