domain controller on public IP subnet

J Z 21 Reputation points
2022-01-26T11:45:51.8+00:00

Hi i have deployment to integrate on prem AD and GOV cloud, i have to deploy additional tree domain within existing forest, but in gov cloud i have public ip segment on which will be sit two new DC. Networks on prem is private A class but cloud has public subnet. Network is fully routed with any any comunications btween dcs on headoffice and cloud. Is that supported scenario to have public subnet on DCs?. Cloud network i think will be not exposed to public internet.

Thank you

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | Networking | Network connectivity and file sharing
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2022-01-26T20:18:14.277+00:00

    On your private network in theory you can use any addressing scheme. Just make sure that the domain controller is not multi-homed and that all members use the static ip address of DC listed for DNS and no others such as router or public DNS.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

4 additional answers

Sort by: Most helpful
  1. Anonymous
    2022-01-26T13:34:33.47+00:00

    No, this isn't going to work. All domain members must use domain DNS to find and logon to domain so you'll need to use a VPN.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  2. J Z 21 Reputation points
    2022-01-26T20:12:51.897+00:00

    Hi DSPatrick that range is in 100.74.xxx.xxx range it seems that its a private range can be this adress space used on AD DNS?

    Shared address space[5] for communications between a service provider and its subscribers when using a carrier-grade NAT.
    https://en.wikipedia.org/wiki/IPv4_shared_address_space

    0 comments No comments

  3. J Z 21 Reputation points
    2022-01-26T20:33:02.247+00:00

    Ok but I will rather to use normal private adress space for placing DCs, so i will be ask to reconfigure network to comply with RFC.
    Thanks Patrick


  4. J Z 21 Reputation points
    2022-02-02T09:02:36.877+00:00

    HI DSPatrick, network guy suggest me that network 100.74.xx.xx is private so no problem I have already setup tree domain to the root forest, but have question about default zone _msdcs.root.forest.net. Domain controllers is replicating fine but on new tree domain controller DNS this zone is missing. When I check _msdcs.root.forest.net on root domain, zone is configured to only replicate all domain controlers in this domain (for windows 2000 compatibility), its necessary to change replication of this zone to all domain controller in forest ? Is there some chance to broke something. On root domain is bunch of old w2008r2 controllers and others is w2016. Its safe to change this?

    Thanks


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.