Single DNS domain name for public and internal network access 2 servers seperated by a firewall: one public and one private 2 options: Independant DNS zones with replication Independant DNS zones with internal DNS thru firewall with both internal and public, host access public resources Using DNS subdomain as AD root domain Existing DNS servers do not have to support SRV records. Using reserved private domain name for AD root (spc.local) If internet resolution (internet->lan) is ever necessary, a .local domain would require you to reinstall AD root domain with another domain name. Using different domain names for public and internal networks