RE: AD in the DMZ . . . OK?

From: Ferino Mardo (RMardo_at_ALJOMAIHBEV.com)
Date: 07/29/04

  • Next message: mike_at_genxweb.net: "Re: Network Traffic Monitor"
    Date: Thu, 29 Jul 2004 11:13:42 +0300
    To: <security-basics@securityfocus.com>
    
    

    Hey Karl.

    The only reason people put Exchange on the DMZ is to act as an SMTP
    relay whereby this relay will be the middle-man between the internal
    Exchange server and the Internet.

    As far as syncing AD in the DMZ I don't think it's recommended as this
    would defeat the purpose of DMZ which is to hide the internal LAN's
    resources.

    > -----Original Message-----
    > From: karl [mailto:opium@runningriver.co.uk]
    > Sent: Wednesday, July 28, 2004 1:49 PM
    > To: security-basics@securityfocus.com
    > Subject: AD in the DMZ . . . OK?
    >
    >
    > Hello
    >
    > One of the developers I work with has come up with a wild and crazy
    > notion to write a .NET app that sits on a DMZ Web server but
    > gets user
    > information from the Active Directory on the other side of
    > the firewall..
    >
    > I'm inexperienced with this, so did some research and found that this
    > kind of thing is possible (plenty of articles on putting Exchange
    > servers in the DMZ), but found myself wondering if this ever happens,
    > i.e. do people actually have their networks set up this way? Do folk
    > expose/replicate AD to the DMZ in practice?
    >
    > It's all very well that this stuff is possible, but if it's
    > perceived as
    > insecure and not implementable in the real world . . . . . . .
    >
    > Thanks for any advice . . . . .
    >
    > Karl
    >
    >
    > --------------------------------------------------------------
    > -------------
    > Ethical Hacking at the InfoSec Institute. Mention this ad and
    > get $545 off
    > any course! All of our class sizes are guaranteed to be 10
    > students or less
    > to facilitate one-on-one interaction with one of our expert
    > instructors.
    > Attend a course taught by an expert instructor with years of
    > in-the-field
    > pen testing experience in our state of the art hacking lab.
    > Master the skills
    > of an Ethical Hacker to better assess the security of your
    > organization.
    > Visit us at:
    > http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    > --------------------------------------------------------------
    > --------------
    >
    >

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: mike_at_genxweb.net: "Re: Network Traffic Monitor"

    Relevant Pages

    • RE: Webserver on a DMZ still needed?
      ... Certainly your suggestion to have a email server in a DMZ but still have ... having the exchange server on the internal LAN with only the smtp ports ... Talking of the financial cost of setup by the book vs the security cost ...
      (Security-Basics)
    • RE: AD in the DMZ . . . OK?
      ... We put Exchange in the DMZ for OWA. ... Exchange server and the Internet. ... Attend a course taught by an expert instructor with years of ...
      (Security-Basics)
    • Re: AD in the DMZ . . . OK?
      ... is at risk. ... repository in your DMZ a "good idea"? ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)
    • Re: Netzschema
      ... Insofern braucht der DMZ Exchange auch entsprechende ... dass du durch den ISA Server etliche ... Stell doch deinen OWA Server in die Domain und publishe SMTP und OWA durch ...
      (microsoft.public.de.german.isaserver)
    • RE: FW: Exchange Server and External Access
      ... Hence the necessity of setting up something on the DMZ. ... requires Exchange Enterprise and not to mention ... > Windows Advanced Server. ... Symantec is the Diamond sponsor. ...
      (Security-Basics)