S
Steven T
Our company have some regional offices around the globe and would like to
plan for a single domain(multi-site) AD architecture.
Say, we have location A, B and C. The offices do not have VPN connection
between them and the only form of communication is through the Internet.
What I am going to do is to place 2 DC(One carrying all the FSMO roles and
the other a GC) in site A and 1 DC(GC also) for each of B and C.
I am just wondering if I really need a VPN connection. I may want to just
allow the ports that replication need with IP restrictions. However, I know
that DC replication requires RPC communication between servers and this may
not work over a WAN connection? Any suggestions are welcomed.
By the way, I am actually asking for "Possiblity" only. I know that even if
it works, it should have potential security problems. Thank you.
plan for a single domain(multi-site) AD architecture.
Say, we have location A, B and C. The offices do not have VPN connection
between them and the only form of communication is through the Internet.
What I am going to do is to place 2 DC(One carrying all the FSMO roles and
the other a GC) in site A and 1 DC(GC also) for each of B and C.
I am just wondering if I really need a VPN connection. I may want to just
allow the ports that replication need with IP restrictions. However, I know
that DC replication requires RPC communication between servers and this may
not work over a WAN connection? Any suggestions are welcomed.
By the way, I am actually asking for "Possiblity" only. I know that even if
it works, it should have potential security problems. Thank you.