Answered RODC in DMZ

  • Wednesday, January 23, 2013 7:28 AM
     
     

    Hi all

    1) I need to put a RODC in teh DMZ for directory lookups from our ISP. The RODC obviously need to be on the domain. Do i just open the appropriate ports to communicate from DMZ to internal network for replication, etc to take place properly or what is the best practices when it comes to RODC in a DMZ communicating to the rest of the network?

    All are Win Server 2008 R2

    2) seeing that there is a FW between Internal and DMZ which can make tracing traffic difficult can i just setup the RODC in the internal network and once it is setup and working move it to the DMZ - can that work or will it make my life difficult for some reason?

    3) When alowing communication through the firewall would i need to restrict communication from the RODC in the DMZ to 1 DC only on the internal network or should i allow network traffic to all 3 writable DC's on the internal network?

    Apprecaite all your help



    • Edited by CraMey Wednesday, January 23, 2013 8:58 AM
    •  

All Replies