Setting up 2 domains with one way trust to dmz



What I have now is a domain on the inside interface of a firewall and
workgroups on the dmz. I am thinking for easier administration that
making a second domain on the dmz with a one way trust would help cut
down the administration of accounts and such.

To me it looks fairly straight forward for the domain creation. I would
create a new domain like dmz.xxxxx.com for the dmz with inside domain
being xxxxx.com.

Now the big question what ports need to be open for all this to work
correctly on the firewall?

I found ms artical 179442 which lists a ton of ports that need to be
opened to make this work.

I have no problem with the server ports its the client ports that I
don't like. maybe I am reading it wrong or something. any help would be
most welcome.

list of server ports

135/tcp RPC
389/TCP/UDP LDAP
636/TCP LDAP SSL
3268/TCP LDAP GC
3269/TCP LDAP GC SSL
53/TCP/UDP DNS
88/TCP/UDP Kerberos
445/TCP SMB


Client ports
1024-65535/TCP/UDP

or is this the same as I have configured already on the firewall of any
on the inside has access to dmz?

.



Relevant Pages

  • Re: SKY USERS
    ... When you set the default DMZ to a non existant IP on the LAN the ... ports register as being stealthed and open if you don't. ... firewall, & I get the anomalous results from all sites mentioned in ...
    (uk.telecom.broadband)
  • Re: NetMeeting Through a NAT Router?
    ... The recommended strategy is to use the dmz feature of the router -- that ... forwards all unsolicited traffic so the number of redirected ports is ... > Windows firewall is disabled but I am running Kerio Personal Firewall, ... Presumably these are calls made to the wan IP of the router? ...
    (microsoft.public.internet.netmeeting)
  • RE: Printing Issue
    ... Opened the two or three ports it needed ... firewall and nothing is being denied access. ... so you put the TS in a DMZ and open ports ... >Microsoft MVP - Terminal Server ...
    (microsoft.public.windows.terminal_services)
  • Re: Need opinions on 3com Office Connect firewall
    ... Neat web interface for Firewall management. ... DMZ Port great for running webservers out side the LAN network. ... No way to protect the Ports from attacks, No ability to set Stealth mode ...
    (comp.security.firewalls)
  • Re: DMZ and Intranet
    ... > Pardon my ignorance since Firewall technology is not my specialty. ... > Could someone be so kind as to explain the benefits of purchasing a ... > firewall solution with DMZ capability. ... > ports for FTP, or Web Service? ...
    (comp.security.firewalls)