本文来自《windows server Active Directory 2008 Resource kit 》第五章活动目录设计部分,对俺这种涉世不深的毛头小子,第一次看到非单森林模型时,还是有点好奇的。
Forest Design Models

At a high level, there are three common forest design models used when creating the forest design. Most organizations will require one of these forest design models, although you may need to use a combination of designs in some organizations.
1、Organizational Forest Model

In the organizational forest model, the forests are designed along some organizational criteria.For example, an organization with multiple business units or geographical locations, or an organization that was formed by acquisitions or mergers, may choose to use an organizational forest model. To enable access to resources between the organizational entities, you can configure forest trusts between forests or external trusts between specific domains in each forest. See Figure 5-4 for an illustration of the organization forest model.
In this model, all user accounts and shared resources related to each organizational entity are stored within the relevant forest. By creating separate forests, you can ensure administrative autonomy and isolation between the business units.
2、Resource Forest Model

In the resource forest model, user and group account management is isolated from resource management by creating separate forests for each function. All user and group accounts are stored in one or more account forests, and all shared resources are configured on servers in one or more resource forests. The resource forests do not contain user accounts other than administrative accounts and service accounts required by applications.
In the resource forest model, you must configure trusts between the two forests. In most cases, this will be a one-way forest trust configured so that users in the account forest can access the resources contained in the resource forest. You can enable two way trusts, external trusts, or forest trusts with selective authentication in this model. See Figure 5-5 for an illustration of the organization forest model.
3、Restricted Access Forest Model

The restricted access forest model is a variation on the organizational forest model. In a restricted access forest model, a separate forest is created to contain user accounts and shared resources that must be isolated from the rest of the organization. The restricted access forest is different than the organizational forest in that no trusts are configured between the two domains.
The restricted access forest is designed to ensure administrative isolation. This means that no user account in a forest outside the restricted access forest can have any permissions or access to any data in the forest. If users in the organizational forest require access in the restricted access forest, they must have a separate user account created in this forest and must have two client computers, each joined to a different forest. See Figure 5-6 for an illustration of the restricted access forest model