Options for joining FAC to multiple customer-managed AD domains
We have a FAC we would like to use for remote authentication + DFA for customers. Customers manage/maintain their own domain. Our connectivity is NAT'd to them - we connect to public IP, their own firewall NATs to private IP.
In lab testing, we can get it working with NAT itself. The problem I think we are having is with DNS and the SRV records.
The DNS servers our FAC is pointed to doesn't have SRV records for customer domains. Even if we got forwarding working from our DNS/DC servers to customer, the DNS answer would be a private IP which wouldn't work anyway.
Anyone aware of alternative solutions to this problem? Basically how can you join a FAC to multiple remote (unmanaged) domains where you don't have direct native IP connectivity.
The only solution I can think of is for the customer to run NPS (Network Policy Server) on their end, and we do RADIUS messaging between FAC and customer DC - but I would really, really like to avoid that.
Thanks,
