V
V
Valentin Melnik2019-06-10 00:36:34
Active Directory
Valentin Melnik, 2019-06-10 00:36:34

How to merge two domain networks?

There is a domain controller domen1.loc in the office and there is a remote cloud infrastructure with its own domain controller domen2.com.
On remote servers there is an Exchange mail server, terminals and SQL servers. What is the best way to combine these two domains to work? Interested in the right ideological way.

Answer the question

In order to leave comments, you need to log in

3 answer(s)
H
hint000, 2019-06-10
@hint000

Since there is still no clarification of what it means for you (in functional terms) to "combine these two domains for work", I will answer briefly: set up trust relationships between domains.
5cfd98dba0e69150911517.png

E
Eugene, 2019-06-10
@yellowmew

Your question raises more questions than desires to answer, FYI
Questions:
1. Are the cloud network and office network combined in the network plan, if so, who is to blame for what?
2. The question contains
- SQL: generally do not give access to anyone except admins and applications, logins must be separate from the office network
- Exchange: In general, do not give access to anyone except admins. All user interfaces for working with Exchange are external.
- Terminal Service: Here (disputed statement) it would be possible to log in under office logins, however:
Exchange is integrated with AD domen2, its logins for mail will be separate.
If you still have separate logins, then it’s not worth integrating into the terminal service either.
In general, from your question, I don’t see any reason to merge domains, so if you answer “how it’s functionally correct”, the answer will probably be: “do not merge”
But if you really want to reduce network security with a database, an application ( 1s, probably some) and mail - go for it: we combine site2site VPN subnets, set up a trust, as hint000 wrote , we hope for a chance we hope for a chance.

M
Maxim Yaroshevich, 2019-06-13
@YMax

IMHO, I see no reason to combine, the easiest way is to set up a VPN from domen1 to domen2, use Exchange through an external interface. In general, no one needs to see SQL servers directly, except for admins, terminal applications work fine via VPN.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question