Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Microsoft Support > Windows NT/2000/2003 Server/2008 Server
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Windows NT/2000/2003 Server/2008 Server Find support for Windows NT/2000/2003 Server/2008 Server editions.

Reply
 
LinkBack Thread Tools
Old 12-30-2008, 12:51 PM   #1 (permalink)
Registered User
 
Join Date: Dec 2008
Posts: 1
OS: Windows 2008


New 2008 Active Directory - need help with domain name



First of all please forgive me for my ignorance but I come from a Cisco background and I’m new to AD. I’m getting ready to implement a new Windows 2008 Active Directory in a new infrastructure (server/hosting location) and I need some help selecting/defining my domain name. The infrastructure will be used to host an internet site built on .net that provides users with the ability to complete workflows over the internet. The site is currently up and running but hosted by a partner (who has not been providing the best uptime). We will call the site www.getrdone.com. The site has a public facing web server (in a DMZ) that communicates with application and DB servers behind a firewall. DNS services for the site are currently handled by a public DNS server, so when a user wants to go to www.getrdone.com they are redirected to my web server. The current environment is not part of an AD. I want to build a windows 2008 AD in the new environment and make all of the servers apart of the AD for security and management purposes. My plan is to add two AD-DC’s on the internet network and have the web server authenticate with the AD-DC’s on the internal network. All servers will run windows 2008.

Here is my question, can I make the domain name of my Active Directory getrdone.com or will I have a problem because www.getrdone.com is already being resolved by a public web server? Do I have to make it a sub domain, something like internal.getrdonw.com? If I do have to make it a sub domain so to speak (internel.getrdone.com) can it still be an active directory integrated zone? What’s confusing me is the fact that the name is already associated with a public website and DNS resolutions is already taking place by a public DNS server that will not be in my network. Any thoughts, best practices, or ideas you have would be very much appreciated.


THANKS!!!!!!!!!
Daniel
New2This-AD is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 12-31-2008, 01:04 PM   #2 (permalink)
Registered User
 
Join Date: Oct 2007
Location: East, Texas
Posts: 105
OS: XP, Vista, Server 2003


Send a message via AIM to Klint Send a message via MSN to Klint Send a message via Yahoo to Klint
Re: New 2008 Active Directory - need help with domain name

what I am going to say and what someone else will say are going to be different BUT from my experience, DNS & security standpoint it isn't a great idea to have your web address and your domain the same.

It shouldn't hurt anything to have gtrdomain.com to be your internal domain name or will it?
__________________
-Klint (Bachelor of Science Information Technology - CompTIA A+ (Certified Computer Tech) -CompTIA Network+ (Certified Network Tech) - CompTIA Security+ (Certified Security Engineer) Microsoft Certified Professional Microsoft Certified Systems Administrator Microsoft Certified Systems Engineer)
Klint is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 01-03-2009, 04:53 AM   #3 (permalink)
TSF Enthusiast
 
Join Date: Aug 2006
Posts: 949
OS: OS2 Warp


Re: New 2008 Active Directory - need help with domain name

Unless this is going to be the root of the domain name, then don't use it for your AD name. So if you have a existing setup that uses the name i would but a diffrant name for your AD .. or use .local.

As for installing AD, it needs to be something.xxx

so
something.com OK
internal.something.com NOT OK

Once you create Something.com, you can create a sub domain internal.something.com
bilbus is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 01-03-2009, 07:33 PM   #4 (permalink)
Registered User
 
Join Date: May 2008
Location: Chicago
Posts: 123
OS: 2003SP2x86


Re: New 2008 Active Directory - need help with domain name

Quote:
Originally Posted by Klint View Post
what I am going to say and what someone else will say are going to be different BUT from my experience, DNS & security standpoint it isn't a great idea to have your web address and your domain the same.

It shouldn't hurt anything to have gtrdomain.com to be your internal domain name or will it?
I don't see the security issue with having the internal network be on the same DNS namespace as external. Goto your average large org and this is how AD is deployed.

To answer the OP's question, yes you can use the same name for both. You'll need to shadow records in the internal namespace, so you'll need a copy of the www record, the MX record, etc in order for them to be resolveable by clients which are pointing to AD DNS.
__________________
Thanks,
Brian Desmond
Windows Server MVP
bdesmondMVP is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 01:29 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85