Re: [Freeipa-users] FreeIPA DMZ topology

2015-10-07 Thread Aly Khimji
Yes sorry I should expand on my question as per Josh's point my scenario also has an AD trust involved. I recently learned of KDC proxying but I am not sure if replica's and KDC proxies are the preferred/accepted design solutions for DMZ's Aly On Wed, Oct 7, 2015 at 1:18 PM, Baird, Josh wrote:

Re: [Freeipa-users] FreeIPA DMZ topology

2015-10-07 Thread Baird, Josh
I'm also interested in how people are handling this - especially when using AD Trusts. When using a trust, the IPA host not only has to communicate with IPA servers, but with potentially every AD domain controller in your HUB site. For us, this is a large number of domain controllers which mea