Je@nb a écrit :
Ton article parle que d'ADDS, pas d'ADLDS, ni d'ADFS. Perso pour de l'ADDS je préfère de loin une forêt de DMZ avec un trust unidirectionnel si possible
|
Pour ADLDS = NO ADDS dans le tableau ....
Si tu lis bien la section
Forest trust model figure 4, c ta solution exposé ci dessus.
his model helps reduce the exposure of corporate information in the perimeter network because directory information that is stored in one forest does not physically reside in the other forest. In addition, forest trusts can be unidirectional so that the perimeter network forest trusts the internal forest but not the other way around.
A drawback of this model is the increased administration costs of maintaining an extra forest and the added complexity of managing firewall rules for domain controllers and client computers crossing trust boundaries.
As a variation of this model, you can also use Active Directory Federation Services (ADFS) to create a federation with the perimeter forest. For more information, see the ADFS Deployment Guide
Ta solution est bonne mais complique énormément la gestion ...
Message édité par statoon54 le 20-11-2011 à 20:33:19