Monday, March 7, 2016

Domain trust over NAT

To create a trust between domains, for example,

blogspot.com, 172.16.0.0/24, nat 10.0.0.0/24 (NS dc01=10.0.0.5, dc02=10.0.0.6)
contoso.com, 192.168.0.0/24, nat 10.0.1.0/24 (NS dc01=10.0.1.5, dc02=10.0.1.6)

you can create a false-DNS server. On false-DNS server create two zones: blogspot.com, contoso.com. On DNS-servers domains blogspot.com, contoso.com create conditional forwarders to false-DNS server.
On false-DNS server:
blogspot.com
Host A - nat IP 10.0.0.5, 10.0.0.6
Host A - dc01 - 10.0.0.5, dc02 - 10.0.0.6
NS - nat IP 10.0.0.5, 10.0.0.6
SRV(_kerberos) - Default-First-Site-Name._sites.dc._msdcs.blogspot.com - dc01.blogspot.com.
SRV(_kerberos) - Default-First-Site-Name._sites.dc._msdcs.blogspot.com - dc02.blogspot.com.
SRV(_ldap) - Default-First-Site-Name._sites.dc._msdcs.blogspot.com - dc01.blogspot.com.
SRV(_ldap) - Default-First-Site-Name._sites.dc._msdcs.blogspot.com - dc02.blogspot.com.
SRV(_ldap) - pdc._msdcs.blogspot.com - dc01.blogspot.com.




contoso.com
analogically

Then create a trust in the usual way.

No comments:

Post a Comment