Firewalls on Windows Domain Controllers.

From: Bill-MT (BillMT_at_discussions.microsoft.com)
Date: 04/22/05


Date: Fri, 22 Apr 2005 09:56:02 -0700

I've been looking into the features of the firewall now included with W2K3
sp1 and while I think its great MS is now including a firewall on it's server
software. I'm not sure their 'first iteration' firewall has a rich enough
feature set to log and/or block everything a DC may have come at it.

So, I'm wondering what 3rd party firewalls people have been installing on
their Windows AD Domain Controllers, specifically on Windows 2000 server
Domain Controllers right now, but eventually on Windows 2003 server Domain
Controllers.

Anyone who has an opinion on or better yet experience with this issue please
reply to this thread. I'd be curious to know....

- What 3rd party firewall software has worked on Domain Controllers.
- And any DC specific configuration issues I should be aware of.

- What 3rd party firewall software is a problem (has not worked well) on
Domain Controllers.

- What firewall features are important with reguard to firewall software
installed on Domain Contollers.

I have my opinions (but no experience with this) but I'm looking for more
insight.
Thanks in advance for any info you can offer on this topic.

-- 
Bill


Relevant Pages

  • Re: How To Force LDAP Queries Through One Domain?
    ... In any case, my focus wasn't on whether a firewall was necessary, but more ... Other white papers on the topic of isolating domain controllers behind ... Windows 2003 that documents behavior between two forests in a trust, ... >> When you login to a domain on a computer that is a member server in the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Windows firewall for domain controllers
    ... So, if the Windows Firewall on the Domain Controllers is blocking the authentication requests, you will get the symptoms your users report. ... It is quite possible that the Firewall Policy you configured for the Domain has different settings for the Standard Profile than for the Domain Profile in the Windows Firewall part of the GPO. ...
    (microsoft.public.windows.group_policy)
  • 3rd Party Firewalls on Domain Controllers.
    ... I've been looking into the features of the firewall now included with W2K3 ... Domain Controllers right now, but eventually on Windows 2003 server Domain ... - What 3rd party firewall software has worked on Domain Controllers. ...
    (microsoft.public.win2000.active_directory)
  • Re: Stand Alone DHCP Servers and Windows 2000
    ... but I stand by the statement that a firewall limits ... client network from domain controllers by an ISA Server 2004 firewall, ... RPC, and that is solved by ISA Server 2004. ... Every virus I have ever been hit with would not have even been slowed down ...
    (microsoft.public.windows.server.networking)
  • Re: 3rd Party Firewalls on Domain Controllers.
    ... I would - were money not an issue - opt for a Hardware solution. ... I would be very hesitant to run any Firewall on a Domain Controller. ... > Domain Controllers right now, but eventually on Windows 2003 server Domain ... > - What 3rd party firewall software has worked on Domain Controllers. ...
    (microsoft.public.win2000.active_directory)