AD Sites and Services NAT subnets?


Recommended Posts

Currently there is many different forests, many

of which are still NT4.0. We are currently working on migrating all

of them, about 10 or so, to fall under our single domain, single

namespace. Our single domain will host about 20,000 users. There is

probably more than 300 different Class C address being used total

between all of the sites, all doing there own internal IP addressing

scheme. Currently all of their clients are servers are using private

addresses. The reason this isnt a problem now is because a firewall

takes care of the external to internal mapping to the correct

destination. We will be changing the structure to where the main

Domain controllers that will be at each site will have external IP

addresses. The problem is we wont be able to change the way they do

their internal Ip addressing for their clients, which is where some of

them may have the same internal Subnets as we have. So how do we set

up the AD sites and services. As I know you are aware, AD sites and

services is where you create the physical topology of all the sites by

defining all of the subnets for each site. First question is must we

even add the internal client NAT subnets to the correct sites, or can

we get away with just using the external subnets that the DC's are

going to be using for each site. If we do have to add the NAT

subnets, this will be a problem as some of the other sites are using

the same internal NAT subnets as we are. I know someone is going to say restructure

there ip scheme to where there is no duplicate subnets, but that may not be an option

for us. Thanks for the help ahead of time.

Link to comment
https://www.neowin.net/forum/topic/221784-ad-sites-and-services-nat-subnets/
Share on other sites

Thanks for the reply. Okay lets say that the DC's will stay on internal Ip addresses. This will be possible as we will be able to set up VPN's between the sites. What about the other sites that we cant controll their internal NAT Subnetes that interfear with other sites subnets meaning there may be a subnet of 10.10.40.0 in two or three different sites. Is this an issue in AD Sites and services? Thanks

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • AMAZON needs to take total accountability for this.
    • Server Summit had a heap of announcements, ADCS changes are baller.
    • Nice, hope they *finally* fixed the issue with the NTFS driver where the system would completely brick during large file copies using the built in driver. It's been broken for years requiring me to use the older, slower, NTFS-3G FUSE driver.
    • Windows 11 KB5094126 BSODing, freezing, forcing BitLocker lockout, breaks OneDrive, and more by Sayan Sen Microsoft released Windows 11 KB5094126 and KB5093998 last week as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. While Microsoft has so far not acknowledged any major problems with the release, some users online are running into problems. These range from OneDrive and Dropbox access issues, BitLocker recovery lockouts, to blue screens and BSODs. The most common one seems to be happening with HP systems wherein affected users say they hit 0xc0430001 BSOD (blue screen of death) error code after the KB5094126 update. We wonder if this could be related to the recent bug we covered on HP devices wherein the ongoing Secure Boot certificate updates are leading to similar issues. While we are not certain, users affected by this issue likely need to ensure that the boot.stl file is included on the installation media (such as a USB installer or ISO), if the above-mentioned dynamic updates are deployed. If this file is missing, computers may fail to boot from the installation media and could display the error 0xc0430001. This STL file is used by Secure Boot to verify that the boot files are trusted, so it must match the same Windows version and system architecture. To ensure the file is included, Microsoft recommends using the Update WinPE script, which automatically updates the image and handles the required files. Alternatively, you can manually copy the boot.stl file from the Windows\Boot\EFI folder on a Windows device and place it in the matching folder on your installation media before deploying the updated image. Aside from blue screening some users also note their systems have been freezing following the update. This could be happening to Lenovo PCs specifically. In the case of the OneDrive and Dropbox access issues, a user figured out that there could be a conflict with UAC. He explained: "Okay, so I did some digging, and in our environment KB5094126 breaks OneDrive and Dropbox in Explorer. I went through all our GPOs and found out that the combination of disabling UAC and having my user being a local admin breaks OneDrive in Explorer. ... If I enable UAC again, then it works, even with KB5094126 still installed." Hopefully, Microsoft will look into these issues. Source: Microsoft forum (link1, link2, link3, link4), Reddit (link1, link2, link3, link4)
    • It is when it's a desktop in my house though for a PC that's lightly used and not really important when it is. If it was a laptop, it would be a different story. The real solution is varied and begins starting at post #22 in that thread.
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      508
    2. 2
      +Edouard
      197
    3. 3
      PsYcHoKiLLa
      138
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      80
  • Tell a friend

    Love Neowin? Tell a friend!