Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Wanet Telecoms Ltd on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Active Directory Intersite Replication NAT Firewall

Status
Not open for further replies.

mofomikes

IS-IT--Management
Feb 1, 2005
5
CA
Im trying to setup a remote domain controller, but I havent found a clear way of establishing a secure method to preform replication through our firewalls and Network address translation.

Opening ports for RPC is too much of a security risk

SMTP replication does not allow data replication (GPO, scripts)

IPsec (as far as i know) does not work with NAT in windows 2000 because altered address will fail the checksums. microsoft released client side NAT-T patch to allow clients with NAT to connect to windows 2000 via L2TP/IPSec, but there is no server side update. "Server-side NAT-T functionality is a new feature in Windows Server 2003 Routing and Remote Access only. NAT-T server-side support will not be added to Windows 2000 Routing and Remote Access."
Having this said, what are the common setups that people have for intersite replication of Active directory? Active directory intersite replication is a common issue but I'm yet to find any information online for my situation.

Im thinking i must deploy a windows 2003 domain controller to act as a bridgehead for the intersite replication. any other suggestions would be greatly apprecaited.
 
Firewall to Firewall VPN is the way to go. You can get pretty cheap vpn concentrators to do this for you.
 
is there a way to preform the intersite replication with my existing hardware? or are vpn concentrators the most recommended method??
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top