We have two writable Server 2012 R2 Domaincontroller in our internal network and a Server 2012 R2 RODC in our DMZ.
I don't want to have a connection from the DMZ in our internal network.
I only want one connection from the internal network to the DMZ.
So my question is: Can you tell me how I can configure the writable DCs to push all config to the RODC?
Is that possible?
Thank you!
Best Answer
You have to think about a few things
There is a link below to an article on provisioning an RODC in the perimeter / DMZ. Take particular note of the Ports / Firewall and Security sections
https://technet.microsoft.com/en-us/library/dd728028(v=ws.10).aspx
Hope this helps,
Mike.