Using an RODC to add a member server


i thought confident not possible add member server domain when have access rodc, google search got me doubting wanted double check.

we have dmz contains 2 rodcs. these have ipsec tunnels read-write dcs, , no other devices in dmz allowed communicate rwdcs. have been asked if can add member servers dmz without having access rwdcs , immediate answer 'no' - rodcs unable add computer objects member servers need access rwdcs able join member server domain.the workaround build member servers on trusted network access rwdcs , move them dmz once in domain.

then saw forum post suggested can 'netdon join' command specifying rodc target write referral it's writeable replication partner add computer object. correct or speculation on someone's part?

the dcs , member servers concerned windows server 2008, , forest/domain functional level windows 2008. firewalls between dmz , trusted network allow dc dc traffic, , not allowed open them member servers.

many in advance.

it not possible join member server in domain using rodc requires access rwdc, jorge has mentioned workaround achive, take look.

http://blogs.dirteam.com/blogs/jorge/archive/2009/01/02/domain-join-through-an-rodc-instead-of-an-rwdc.aspx

http://blogs.dirteam.com/blogs/jorge/attachment/3492.ashx

http://blogs.technet.com/b/instan/archive/2008/08/13/troubleshooting-rodc-s-troubleshooting-domain-joins-against-rodc-s.aspx

 

regards


awinish vishwakarma| check blog 

disclaimer: posting provided as-is no warranties or guarantees , confers no rights.




Windows Server  >  Directory Services



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2