FW: AD replication over WAN

From: Keith Smith (ksmith@firesnacks.com)
Date: 01/13/03

  • Next message: Chris Weiscopf: "RE: AD replication over WAN"
    From: "Keith Smith" <ksmith@firesnacks.com>
    To: <focus-ms@securityfocus.com>
    Date: Mon, 13 Jan 2003 12:07:16 -0500
    
    
    

    All:

    I apologize for not being more specific... I was referring to using OL2002
    in MAPI mode. As I understand it, ISA server has publishing rules to make
    the firewall config easy. In addition, I also read that MAPI uses
    encryption of the RPC. Is anyone familiar with this?

    The primary docs I was referring to are:

    From Microsoft Exchange 2000 Server Hosting Series
    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/prodtechn
    ol/exchange/exchange2000/plan/exchterm.asp?frame=true

    Chapter 3 (Planning) discuss clients.

    Thanks
    Keith

    -----Original Message-----
    From: Keith Smith [mailto:ksmith@firesnacks.com]
    Sent: Monday January 13, 2003 10:53 AM
    To: focus-ms@securityfocus.com
    Subject: RE: AD replication over WAN

    I have a similar question, though in application to Outlook 2002 clients
    accessing an exchange server across the Internet. Microsoft claims that with
    OL2002, clients don't need to employ a VPN across the internet, as the RPC
    is all encrypted.

    Would a VPN also be recommended in this instance given the observations
    below?

    Thanks
    Keith

    -----Original Message-----
    From: Jim Harrison (SPG) [mailto:jmharr@microsoft.com]
    Sent: Sunday January 12, 2003 9:43 PM
    To: Valentine M. Smith; focus-ms@securityfocus.com
    Subject: RE: AD replication over WAN

    Given that the replication path (port/protocol) is well-defined and
    generally understood, it also makes sense that they could also provide a
    "door" to your AD controllers for those who wish to do you harm for no
    apparent reason.
     
    With that in mind, it seems clear to me that a site-to-site VPN is not only
    preferable, it's mandatory.
     
    * Jim Harrison <mailto:jmharr@microsoft.com>
    MCP(NT4/2K), A+, Network+
    Security Business Unit (ISA)

    ________________________________

    From: Valentine M. Smith [mailto:vmsmith@grokking.org]
    Sent: Thu 1/9/2003 06:21
    To: focus-ms@securityfocus.com
    Subject: AD replication over WAN
             

    Hi,

    I'm looking for some feedback from the community regarding the transfer of
    AD
    traffic over a public WAN.

    The basic plan is this:

    Single Win 2000 domain spread over two sites in different cities. Each site
    has perimeter NAT device and are obscuring internal subnets with IP
    addresses
    provided by a single ISP. No internetwork VPN planned. DNS is AD-integrated
    at both sites. Both DCs are patched to SP3.

    The MS documentation I've consulted indicates that AD replication, and by
    extension, DNS zone information that is AD-integrated is automatically
    encrypted.

    My question: if the data is already encrypted and is passing only across a
    single ISP's network, should one be bothering with a router-router VPN
    tunnel
    for this traffic? IOW, would setting up such a tunnel for this data be
    redundant/unnecessary or am I missing something important here? Would anyone
    care to comment on the relative safety of AD encryption out-of-the-box?

    Thanks in advance for any feedback,

    VS



    Relevant Pages

    • Re: Advice needed on secure remote datacenter and secure communication
      ... fair bit of time working with windows server, ... as for VPN, ... Addressing your issue with PGP encryption on sensitive files, ...
      (alt.computer.security)
    • RE: VPN Issue
      ... 317025 You Cannot Connect to the Internet After You Connect to a VPN Server ... | first done with a standard usb broadband modem on XP Professional. ...
      (microsoft.public.windows.server.sbs)
    • Re: Sometimes it works sometimes it doesnt (VPN data issues)
      ... NIC1 "Internet" is set to ... (the IP of the external firewall) and the DNS is set to ... A connection between the VPN server and the VPN client xxx.xxx.xxx.xxx ...
      (microsoft.public.windows.server.networking)
    • RE: VPN Error code 800 HELP!
      ... Can you visit Internet and OWA on SBS server? ... Just one PC get error code 800 connecting VPN connecting to SBS? ...
      (microsoft.public.windows.server.sbs)
    • RE: Sharing VPN client connection
      ... as a VPN server, configure the internal clients to connect the remote ... office by VPN connection and then access to the Internet from the Remote ... Enable internal clients to access the Internet. ... On the server, go to My Network Places, click New Connection Wizard. ...
      (microsoft.public.windows.server.sbs)