Re: Is NetBIOS Over TCP Required For Authentication?

From: Phillip Windell (_at_.)
Date: 03/29/04

  • Next message: Jim: "Antivirus scan on new network machine."
    Date: Mon, 29 Mar 2004 09:52:21 -0600
    
    

    "CHANGE USERNAME TO westes" <DELETE_westes@earthbroadcast.com> wrote in
    message news:oPCdneRm--Kl4Prd4p2dnA@giganews.com...
    > In our case, we do not want anyone at the proxy server console to be able
    to
    > easily resolve hostnames on the internal network using DNS.

    I'm sorry, but that is an unrealistic thing to "want". If the proxy cannot
    resolve internal names then it will not be able to verify if a FQDN is
    internal of external because it won't be able to resolve it, then it will
    not be able to compare it to the LAT to determine if it should be processed
    by the proxy services or allow to function directly.

    In an Active Directory Environment (Win2000 or 2003) the proxy must use the
    Internal DNS to resolve names, then the DNS Server will use "Forwarders" to
    pass the requests to the ISP's DNS for name it cannot resolve from its own
    database.

    > Why wouldn't
    > we put the external NIC at the top of the list?

    Because it won't function on the Domain properly. It will start having
    trouble finding the Domain Controller and authentication will either fail or
    at least become unreliable.

    --
    Phillip Windell [MCP, MVP, CCNA]
    www.wandtv.com
    

  • Next message: Jim: "Antivirus scan on new network machine."

    Relevant Pages

    • Re: Intranet Issue
      ... I created a dns record called intranet so ... > than trying to resolve it or access it on the outside. ... For example a CERN Compliant Web Proxy would resolve the URL on behalf of ... the client. ...
      (microsoft.public.win2000.group_policy)
    • Re: Intranet Issue
      ... I created a dns record called intranet so ... > than trying to resolve it or access it on the outside. ... For example a CERN Compliant Web Proxy would resolve the URL on behalf of ... the client. ...
      (microsoft.public.win2000.dns)
    • Re: Intranet Issue
      ... I created a dns record called intranet so ... > than trying to resolve it or access it on the outside. ... For example a CERN Compliant Web Proxy would resolve the URL on behalf of ... the client. ...
      (microsoft.public.win2000.networking)
    • Re: Intranet Issue
      ... I created a dns record called intranet so ... > than trying to resolve it or access it on the outside. ... For example a CERN Compliant Web Proxy would resolve the URL on behalf of ... the client. ...
      (microsoft.public.inetserver.iis)
    • Re: do I need to configure Forwarder in my AD DNS???
      ... > Is it good practice not to configure my Local DNS to forward Query (if ... > failed to resolve it) to Public DNS? ... > Since the users relying in Proxy to solve external names ... Microsoft Windows MVP - Active Directory ...
      (microsoft.public.win2000.dns)