|
Gnerally speaking, all DCs need to be able to contact the RID master
periodically to get a RID allocation. I have some thoughts about how to work
around the problem, but I've never tried them, so you get to be the test pilot
on your first flight :)
1. You
can change the size of the RID block allocated to the DC so that it gets
"enough" RIDs to last a really long time. There's a reg setting is defined in
KB316201. There are some caveats when setting the value to a really large
number.
2.
Point whatever processes are creating security principals (users, computers,
groups) to a DC not in the DMZ. That way the DC in the DMZ won't have to
allocate any RIDs.
HTH,
-gil
Gil Kirkpatrick
|
Title: Message
- [ActiveDir] Connectivity with FSMO role machines Abbiss, Mark
- Gil Kirkpatrick
