Re: unable to join domain from dmz

From: Dan Tesch (dan.tesch_at_comcast.net)
Date: 08/24/04

  • Next message: Charles J. Hammett Jr.: "RE: Event log Monitor"
    To: "Security Basics" <security-basics@lists.securityfocus.com>
    Date: Tue, 24 Aug 2004 15:50:20 -0500
    
    

    You can do this by adding an entry in LMHOSTS also, you can google
    for instructions - simpler than setting up WINS.

    > You need to setup a WINS server. Otherwise you cannot cross subnets.
    >
    > On Mon, 23 Aug 2004 12:12:52 +0300, Bilal Dar <bdar@pbad.sbg.com.sa>
    wrote:
    > > I am having a problem, i couldn't figure out the reason till now. We are
    > > having our NT 4 Primary Domain Controller on the inside network, now i
    am
    > > installing another server in the DMZ as a Backup Domain Controller. When
    i
    > > try to join the domain during installation i get an error stating "The
    > > domain controller for the domain cannot be located"
    > >
    > > Dmz = 172.17.0.0/16
    > > Inside = 172.16.0.0/16
    > >
    > > PDC = 172.16.4.2
    > > NewServer = 172.17.0.10/16
    > >
    > > conduit permit icmp any any
    > > conduit permit ip host 172.17.0.10 172.16.0.0 255.255.0.0
    > > conduit permit ip host 172.17.0.10 172.17.0.0 255.255.0.0
    > > conduit permit tcp host 172.17.0.10 eq smtp any
    > > conduit permit tcp host 172.17.0.10 eq pop3 any
    > > conduit permit tcp host 172.17.0.10 eq domain any
    > > conduit permit udp host 172.17.0.10 eq domain any
    > > conduit permit ip host 172.17.4.2 host 172.17.0.10
    > >
    > > I can ping NewServer from Inside network. Am i missing something?
    > >
    > > Thanks
    > >
    > >
    >
    >
    > --
    > END OF LINE
    > -MCP

    ---------------------------------------------------------------------------
    Computer Forensics Training at the InfoSec Institute. All of our class sizes
    are guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Gain the in-demand skills of
    a certified computer examiner, learn to recover trace data left behind by
    fraud, theft, and cybercrime perpetrators. Discover the source of computer
    crime and abuse so that it never happens again.

    http://www.infosecinstitute.com/courses/computer_forensics_training.html
    ----------------------------------------------------------------------------


  • Next message: Charles J. Hammett Jr.: "RE: Event log Monitor"

    Relevant Pages

    • Re: Why cant I use a search engine anymore?
      ... Those instructions are well-meaning, but wrong. ... dissociate .hta files from the mshta.exe application. ... > Vista, and other search engines, each time getting routed ... > google and indicates that I must ...
      (microsoft.public.windowsxp.security_admin)
    • Re: OT: Google Walking Directions. Who knew?
      ... Lymaree wrote ->> Except that if you ask, Google will tell you how to swim ... might ask you to walk places where walking isn't possible. ... year) Mapquest's instructions for leaving the parking lot included a turn ... computerized directions for walking or driving. ...
      (rec.arts.mystery)
    • Re: DIY repair instructions for Toshiba SP6000?
      ... was told that the most likely problem with it was that the power ... I can't find these instructions with Google. ... FYI you will need a fine soldering iron to complete the repair. ...
      (uk.comp.sys.laptops)
    • Re: PSD Thumbnails
      ... Go to Google and do a search for "psicon.dll aiicon.dll psd thumbnail" and ... find a number of websites with instructions and links to the necessary ...
      (comp.graphics.apps.photoshop)
    • Re: [opensuse] Frozen Throne
      ... instructions, I did not check this out fully. ... Google is your friend, I ... (not Frozen Throne went fine. ...
      (SuSE)