Re: Extranet Authentication



Not really an IIS/Security question.

I have never done this sort of thing, but I suspect you would install
an Active Directory in the DMZ, set up a one way trust between the AD
in the DMZ and your Intranet, and punch holes in your Intranet Firewall
to only allow the AD in DMZ machine to talk to your AD in your
Intranet.

This way, IIS can talk to the AD in the DMZ, which has the one-way
relationship with the AD in your Intranet, and Intranet users can
authenticate through IIS. Without exposing your Intranet AD to the
Internet.

I would suggest that you pose the question in an Active Directory
oriented newsgroup because they would be better suited. IIS just tags
along as a member server of a domain.


//David
http://w3-4u.blogspot.com
//


Mike wrote:
I'm currently building a new company website. (asp.Net) Our web server is a
stand-alone in the DMZ. On the website, I'd like to have a place for
employees to logon
using their same internal, network username/password, so they don't need
additional logon information. (We do expire passwords regularly) Is it
possible to securly authenticate to the internal active directory? We have 1
forest with 3 domains (1 local & 2 across VPN's). Users from all domains
would need to authenticate. We use a hardware firewall, not ISA. I'd
appreciate it if someone can steer me in the right direction.

--
Mike

.



Relevant Pages

  • Re: W2KPRO - DNS Dial-up problem
    ... > network using dial-up (I'm still conected to the intranet by the ... > DNS server wich should be assigned by the dial-up conection. ... Microsoft Windows MVP - Active Directory ...
    (microsoft.public.win2000.dns)
  • Re: Firewall-Konzept - Technische Umsetzung
    ... D.h. in die DMZ kommt im Prinzip ... Damit man das ganze nicht durch die Verkabelung aushebelt ist es halt ... durch Verkabelung die Netzwerke brückt (z.B. über zweite Netzwerkkarte ... Intranet --- Server ohne RemoteAccess ...
    (de.comp.security.firewall)
  • RE: DMZ Design
    ... Don't use public IP space on your intranet. ... I suggest not using public IP's for your DMZ and/or Intranet. ... > network just as it stops all incoming requests from the Internet to your ...
    (Security-Basics)
  • Re: Using information from AD
    ... One feature Human Resources is asking for is an up to ... Since the information in Active Directory is the most ... >incorporate data from AD into our intranet. ... >need is a GUI based tool that could query directory against AD. ...
    (microsoft.public.windows.server.active_directory)
  • Re: DMZ webserver portal question
    ... AD in the DMZ is 'generally' not a good idea. ... > compatible for internet explorer, FireFox or others) in our dmz and want ... Also, If the user close his browser, and open a fresh ... > We are looking into setting up active directory in the dmz. ...
    (microsoft.public.win2000.active_directory)