I was wondering if anyone has either the answer or can point me in the = right direction as to how Active Directory works through a natted = firewall. I am trying to do promotion and replication. Microsoft Technet has a list of ports to open (RPC, DNS, etc...), but = goes not much further. Here is my scenario: I have a domain controller on the inside with an address of 192.168.0.5 = (255.255.255.0). In the DMZ is a domain controller to be with an address of 192.168.100.5 = (255.255.0.0). 192.168.0.5<----------Firewall<----------192.168.100.5 Of course the PC in the DMZ cannot see the domain controller on the = inside in order to allow promotion to an active directory domain = controller. IPsec is probably not an option, but perhaps PPTP may be. Any help would be greatly appreciated. Thanks in advance.