Quantcast
Channel: Directory Services forum
Viewing all articles
Browse latest Browse all 31638

Computers in DMZ still authenticating on DC in internal network, rather than on RODC in DMZ

$
0
0

Hi

I have 2 networks :

  • 172.33.0.x : My internal network
  • 192.168.1.x : My DMZ network

I have a DC in the internal network for my domain, and a RODC in the DMZ for the same domain. A firewall exists between these two networks, allowing only the ports/traffic I specify.

When I add a computer in the DMZ, and try to add it to the domain, it still tries to access my DC on the internal network, rather than the RODC in the DMZ. I've done the change as specified here (http://support.microsoft.com/kb/977510?wa=wsignin1.0, i.e. allowing the RODC to be discoverable. I am allowing the following ports between my RODC and DC :

ServiceSourceDestination
Ephemeral ports49152:6553549152:65535
FRsRPC1:6553553248
Kerberos1:6553588
LDAP1:65535389
SMB1:65535445
NTP1:65535123
RPCC Endpoint1:65535135

I have two Sites setup... DMZ and Internal. The RODC is part of the DMZ Site, and the DC is part of the Internal site.

If I run a nltest /dsgetdc:mydomain.local on a computer in the DMZ, the RODC is returned.




Viewing all articles
Browse latest Browse all 31638

Trending Articles