I am "in charge" (read: people yell at me if it breaks, but I don't have the clout to fix it usually) of the network of a small division of a large company. We have a main office plus two small remote offices. The main office has an Active Directory server plus a permanent firewall-to-firewall VPN to the rest of the network.
The two remote sites, however, have no servers. They need frequent access to the main network for e-mail and file sharing purposes, so they will always need to access their domain accounts. They do this using the standard Microsoft PPTP VPN.
The powers that be have set forth these rules on my network:
1. I cannot install a server at either remote site. Everything will have to be done with their laptops.
2. We cannot install firewalls at those sites to permanently hook them in to the rest of the domain. The only way to establish a connection will be PPTP.
3. Any questions to the power that be as to the right way of doing things will be answered with vague and contradictory answers.
Now, to my questions... Is it better to have the remote sites in their own workgroups and let them try to log into the domain after the VPN is established? Or, should I join the machines there to the domain and have them use dial-up networking to log on?
If I've been to vague, let me know. My brain is a little scrambled right now!
The two remote sites, however, have no servers. They need frequent access to the main network for e-mail and file sharing purposes, so they will always need to access their domain accounts. They do this using the standard Microsoft PPTP VPN.
The powers that be have set forth these rules on my network:
1. I cannot install a server at either remote site. Everything will have to be done with their laptops.
2. We cannot install firewalls at those sites to permanently hook them in to the rest of the domain. The only way to establish a connection will be PPTP.
3. Any questions to the power that be as to the right way of doing things will be answered with vague and contradictory answers.
Now, to my questions... Is it better to have the remote sites in their own workgroups and let them try to log into the domain after the VPN is established? Or, should I join the machines there to the domain and have them use dial-up networking to log on?
If I've been to vague, let me know. My brain is a little scrambled right now!