Discussion:
Help with ISA/TMG Array Domain Membership.....
(too old to reply)
MikeS@MLS
2010-01-19 16:12:01 UTC
Permalink
Hope some smart folks here can help me figure out how to answer a "boss"
question about ISA/TMG array domain membership.

We have a project to build an internally-segmented enviroment using ISA or
TMG. The idea is that we would build a COMPLETELY NEW environment, with it's
own AD forest, and that the new ISA/TMG array would be intstalled IN that
forest (as would servers behind ISA/TMG in the various protected segments).
We would then use one-way forest trusts to grant access to servers/published
apps within that environment.

Here's the problem - another issue in our current production environment has
push up the deployment of the new segmented environment, and I now have to
deploy a basic version of the new infrastructure that can be built out at a
later date into the full-blown environment.

Here's the question: I'm getting pushback from my manager about why we have
to deploy the new AD forest NOW.

He wants to know why we can't just build the ISA array using the existing AD
forest, and then change it to the new forest later. Or, deploy it now as a
standalone array, and add it to the new forest later.

I know that both of those are BAD ideas, when it comes to ISA/TMG, and I can
provide a litany of techno-babble that would not help my cause one bit. Can
anyone give me some good, plain-english "manager-level" reasons why we should
push forward with the new AD forest now? Or, why either alternative is a BAD
idea (in the same, plain-english managerspeak way)?

Thanks,
Mike
Jens Baier
2010-01-19 16:50:03 UTC
Permalink
Hi,
Post by ***@MLS
He wants to know why we can't just build the ISA array using the existing AD
forest, and then change it to the new forest later. Or, deploy it now as a
standalone array, and add it to the new forest later.
it is possible and supported to change the domain membership of ISA/TMG
after installation!
--
Gruss Jens
www.it-training-grote.de
www.forefront-tmg.de
https://mvp.support.microsoft.com/profile/Marc.Grote
http://blog.it-training-grote.de
MikeS@MLS
2010-01-19 18:28:02 UTC
Permalink
Thanks Jens. I didn't know that it was possible; all the posts I've read
elsewhere said that the best way to handle such a situation was a reinstall.
Can you point me to some info on what's involved in such a process?

Also, I probably should have used the term ISA "Enterprise", not "array".
Does that make a difference, moving an entire enterprise from one domain to
another?

Also, we would be moving that enterprise between AD forests, not just
different domains within a forest. Does that make a difference, either?

"Jens Baier" wrote:


It is possible and supported to change the domain membership of ISA/TMG
after installation!

Loading...