I'm doing a class which involves security\malware testing and therefore want to isolate my labs to their own network with no routing to the main site. I want to be able to set policies, create users, etc. from my main DC which exists on the main network. The firewall has routing such that the main network can access both lab networks but the lab network can not talk to the main network unless related-established. I'm not a big windows guy so I need a little bit of guidance. The topology is as follows
I don't have enough rep to post images so please see the topology
I foresee the following problems:
- The lab DCs can not use the main DC as a DNS server or LDAP server since the lab DCs can not talk to the main one for the most part. The PCs in the respective labs can use their respective DCs as DNS servers.
- The main DC can "push" policies to the other DCs but as to the point above the other DCs can not pull anything from the main DC.
- I assume all FSMO roles will need to be held on the Main DC.
- How can I even DCPromo the lab DCs if they can not use the main DC as a DNS server.
Is what I'm trying to achieve even possible?