Domain child segregation


hello, 

currently have following architecture:

parent-domain.local (server 2012 standard)

        |

|

|

    |    |

child1-domain.parent-domain.local (server 2008r2 standard) child2-domain.parent-domain.local (server 2008r2 standard)

in ad domain , trusts forest setup this:

parent-domain.local 

--child1-domain.parent-domain.local

--child2-domain.parent-domain.local

the child domains trust parent transitive set yes.

if go child 2 member server can add user child1 , visa versa.  i noticed in firewall logs child1 , child2 talk each other.  i want complete separation between child1 , child2 , want block firewall communication between them.  right doesnt seem can this.  

how childs through parent , have complete seperation between 2 childs?  that means if try add a child1 group child2 member server wont able to.

thank you, 

yes - ad has no capabilities proxy thru root domain. 

enfo zipper
christoffer andersson – principal advisor
http://blogs.chrisse.se - directory services blog



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...