I've been researching into ways to patch our laptops that do not use vpn anymore. I am planning to setup a downstream replica server for this but we do not have a true dmz with RODC. I will NAT the server IP and have 2 separate network connections. However, if I only allow ports 8530 and 8531 for both network connections, I'll lose domain services (AD, DNS, etc), correct? If I allow those ports, I'll have to sacrifice security, right?
Are there any other secure way to overcome this without managing 2 separate wsus servers or setting up a true DMZ?
Thanks