I am looking to deploy 2 additional Windows Server 2003 domain controllers into a separate confidential DMZ alongside 6 DCs that are installed in the regular network, making a total of 8 DCs. The 2 confidential DCs will communicate with the regular network DCs through the firewalls via IPSec.
However, I am wondering how I will stop regular network workstations and servers trying to authenticate with the confidential DCs? Is there a way of using AD Sites and Services to stop regular network workstations and server from trying to communicate with these confidential DCs?
What I am trying to say is, will there be a problem or when a regular network workstation or server tries to authenticate with the confidential DCs and times will this cause issues or will it timeout and try another DC and carry on?