Results 1 to 4 of 4

Thread: Adding 2008 DC to a firewalled Child Domain

  1. #1
    Join Date
    Apr 2011
    Posts
    3

    Adding 2008 DC to a firewalled Child Domain

    Okay.. So we have all the firewall ports open for AD/DNS and replication thats is fine... however... we cant route to all the subnets that the child domain DC's are on.. I think thats where we are failing. We moved the FSMO roles to the DC on the segment that we can reach, but when looking at the netmon the DC we're promoting is trying to reach the DC's on the network that we cant route.

    So i'll explain..
    Promoting DC IP : 1.x.x.x

    Firewall is open to these DC's in the root/child domains and communication is fine :
    2.x.x.x (Has FSMO)
    3.x.x.x
    4.x.x.x
    5.x.x.x

    Now when we try to promote the DC on the other network t tries to reach un-routable networks :
    6.x.x.x
    7.x.x.x

    My question how do i make sure that the DC i'm promoting only looks at the 2/3/4/5 DC's and ignores the others?

  2. #2
    Join Date
    Apr 2011
    Posts
    3

    Re: Adding 2008 DC to a firewalled Child Domain

    is this in the correct forum area?

  3. #3
    Join Date
    Oct 2004
    Posts
    1,342

    Re: Adding 2008 DC to a firewalled Child Domain

    In order to create a child domain on your network, you will need another server, or rather a Domain Controller. You can build that DC in your main office and then ship it out to the new office. This DC will also be a Global Catalog as well as DNS Server to assist all the clients in the new office with any DNS requests, etc. You also need to prepare your current network for the new sub domain.

  4. #4
    Join Date
    Apr 2011
    Posts
    3

    Re: Adding 2008 DC to a firewalled Child Domain

    The new DC is going to be a member of an existing child domain... But on the other side of the firewall that network cant see all the domain controllers on ourside.

    so two networks..

    Network A has 10 DC's... in a child domain

    Network B (where we want to build an additional DC) can only see a 7 of the 10 DC's on Network A and the DCPROMO is failing with an RPC error.

    I want to make sure that the DC doesnt even try to commuinicate to the three DC's it cant see. but only the FSMO role holders in that domain.

Similar Threads

  1. Adding a 2008R2 Child Domain to a 2003R2 forest
    By Kaysel in forum Active Directory
    Replies: 2
    Last Post: 01-05-2010, 09:33 PM
  2. Remove child domain after child domain DC has failed
    By DANIEL 602 in forum Active Directory
    Replies: 1
    Last Post: 26-03-2010, 03:13 AM
  3. Replies: 2
    Last Post: 10-11-2008, 07:38 PM
  4. domain upgrade to 2008 by adding new 2008 server
    By manishdk in forum Active Directory
    Replies: 3
    Last Post: 30-07-2008, 10:15 PM
  5. Replies: 1
    Last Post: 19-06-2008, 01:58 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,439,816.99555 seconds with 16 queries