Hi,
From your post, I'm understanding that you have two (2) 'workgroups' with multitudes of computers in them - your 'workgroups' are:
Workgroup 1 = MOG-Exchange
Workgroup 2 = TOG-Exchange
You'd have to provide a little more background as to why you've created two (2) 'workgroups'; that said, I'll assume it's because you wanted to keep various groups of computers isolated from each other.
Few networking pointers when it comes to 'workgroups':
1) Members of a 'workgroup' cannot see members of another 'workgroup' but can connect to each other using explicit mapping (ex: net use * \\xxxxx\yyy) or via TCP/IP (ex: \\###.###.###.###)
2) Members of a 'workgroup' cannot connect to members in another 'workgroup' if the other 'workgroup' is not on the same IP/Subnet (ex: 1: xxx.xxx.xxx.xxx, 2: yyy.yyy.yyy.yyy)
3) Members of a 'workgroup' cannot connect to members in another 'workgroup' if separated by a gateway unless a 'complex' routing device facilitates the interconnections.
4) Alternating the name of your DNS would cause connectivity issues as 'workgroup' devices (aka NetBIOS) traditionally broadcast over 255.255.255.255.
As for A/D integration; would be nice if the DNS-323 supported A/D integration as has been introduced in f/w 1.02 of the DNS-343. Not convinced though that it would address some of the DNS security exposures that have been posted of late.
Cheers,