Naming a new Active Directory?

Hi,

We are in the process of setting up a new AD domain. I have some questions regarding the naming of the domain. We would really like to name the internal AD domain the same as the public domain. I have read a bit about this and Microsofts recommendations is NOT to do this, but to use a subdomain of the public domain.

My real question for you is what caveats  and possible technical challenges do we have to deal with if using the same name?

I already know that we have to deal with a "Split-bran DNS" setup. (Not a big problem as i see it). And that internal users will not be able to reach the public website without entering "www.example.com".

/Andreas

August 31st, 2015 4:24am

Hi

 Please check out this discussion

http://serverfault.com/questions/76715/windows-active-directory-naming-best-practices

Free Windows Admin Tool Kit Click here and download it now
August 31st, 2015 4:42am

Hi Andreas,

Thanks for your post.

You can also use the same name for the internal domain and the external domain. But this method is not recommended. It creates name resolution problems because it introduces DNS names that are not unique. This method requires additional configuration to enable optimized performance.

https://technet.microsoft.com/en-us/library/Cc755946(v=WS.10).aspx

If you want to know how to set external website when the internal name is the same as the external name, you could read the articles below.

http://blogs.msmvps.com/acefekay/2009/09/03/split-zone-or-no-split-zone-can-t-access-internal-website-with-external-name/

Best Regards,

Mary Dong

August 31st, 2015 11:11pm

Split brain by definition is two dns entries for the same name, so internal users can get to the external website you just need to add a dns entry in the onsite dns server pointing to the external address and it will work. if you forget to do this internal users will not get to web site.

I have a similar setup and occasionally I have to explain to users that www.example.com from a computer on the LAN may go to a different site then if accessed from outside the company LAN.  Typically it's test sites that show this behavior.

Free Windows Admin Tool Kit Click here and download it now
September 1st, 2015 12:18am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics