Configure Read Only Domain Controller to receive config

domain-controllerwindows-server-2012

We have two writable Server 2012 R2 Domaincontroller in our internal network and a Server 2012 R2 RODC in our DMZ.

I don't want to have a connection from the DMZ in our internal network.

I only want one connection from the internal network to the DMZ.

So my question is: Can you tell me how I can configure the writable DCs to push all config to the RODC?

Is that possible?

Thank you!

Best Answer

You have to think about a few things

  1. The ports needed to be open in order for the RODC and Writable DC to talk to each other
  2. Securing the communication between your RODC and the writable DC
  3. Provisioning the RODC and More....

There is a link below to an article on provisioning an RODC in the perimeter / DMZ. Take particular note of the Ports / Firewall and Security sections

https://technet.microsoft.com/en-us/library/dd728028(v=ws.10).aspx

Hope this helps,

Mike.