Do you have to configure a site-to-site VPN to connect remote sites through Active Directory Sites and Services? I’m not sure how one site would know how to connect to the other sites since “Active Directory Sites and Services” uses privet subnets to connect to the remote site.
Sites and services is intended to make sure a client device connects to the nearest domain controller or DFS server. It makes that distinction by mapping a subnet to a site. The site is just a label.
So if you map 10.1.0.0/16 to your Detroit site and 10.2.0.0/16 to your Orlando site, the client devices with those IPs will connect to the servers with those IPs.
It doesn’t do ANYTHING to actually build that network and connections between sites.
Create a port forward for all the AD ports at each site and open up access on the firewall. Tunnels are for cowards ! I jest… yes you need tunnels or direct connections between sites. I would strongly recommend gre over IPsec for this with two tunnels to diverse sites.
This might be a case where you probably should ask a colleague with more experience? This is kind of very basic networking.
It doesn’t do ANYTHING to actually build that network and connections between sites.
Thank you
Been away for a while thanks for your shared information
Thanks for your added information