RE: Servers in DMZ particpitating in internal Domain

From: Jeff Qiu (jefffqiu_at_online.microsoft.com)
Date: 05/14/03


Date: Wed, 14 May 2003 06:54:44 GMT


Hi Bob,

Thank you for your post!

I am not sure why you want to get an application in DMZ to be authenticated
in an internal domain.

If we try to create some kind of connection between the DMZ and the
internal domain, the DMZ will lost its value to protect your network.

It is suggested to put the application in your internal domain.

If you have any further concerns, please let me know.

Regards,

Jeff Qiu
jefffqiu@online.microsoft.com
Online Support Professional
Microsoft Corporation

This posting is provided Ħ°AS ISĦħ with no warranties, and confers no
rights.

--------------------
>Content-Class: urn:content-classes:message
>From: "Bob" <bob_olson@spgl.com>
>Sender: "Bob" <bob_olson@spgl.com>
>Subject: Servers in DMZ particpitating in internal Domain
>Date: Tue, 13 May 2003 15:48:00 -0700
>microsoft.public.win2000.security
>
>Hello;
>
>What is the best practice for having servers in the DMZ
>that have applications that need to authenticate against
>an internal Domain?
>
>There is no domain controller in the DMZ and 3 AD DC's in
>the internal domain?
>
>Should the servers in the DMZ participate in the internal
>Domain or should another Forest or Domain be setup in the
>DMZ?
>
>Thank you;
>
>Bob
>



Relevant Pages

  • Re: DNS in DMZ
    ... > forest in the DMZ. ... There will be no trust relationships whatsoever ... admin on the internal domain will ... > need to access servers in the DMZ and DMZ servers will have to access ...
    (microsoft.public.windows.server.dns)
  • Re: Win3k Forest Trusts
    ... Can you list users from internal domain on DC in DMZ for test? ... > We are trying to setup a trust between our DMZ and Internal network. ... > (firewall disabled). ...
    (microsoft.public.windows.server.setup)
  • Servers in DMZ particpitating in internal Domain
    ... What is the best practice for having servers in the DMZ ... that have applications that need to authenticate against ... the internal domain? ...
    (microsoft.public.win2000.security)
  • RE: Secure DMZ with IIS. SQL and AD
    ... All DMZ servers are members. ... > trust to allow our internal domain to replicate data to the DMZ. ...
    (microsoft.public.security)
  • Re: ISA 2004 VPN Client can access DMZ but not Internal Domain
    ... How is your ISA 2 configured? ... you will need to publish the internal domain to the DMZ. ... On my test DMZ I have a single machine that acts as a Domain ... My VPN clients can authenticate and access all machines on the DMZ. ...
    (microsoft.public.isa)

Quantcast