Re: AD replication over FW

From: Miha Pihler [MVP] (mihap-news_at_atlantis.si)
Date: 07/28/05

  • Next message: Mike: "Certificate Services: controling CRL extensions."
    Date: Thu, 28 Jul 2005 10:15:40 +0200
    
    

    Use IPSec as article describes.

    Note: how secure do you want this to be? If I somehow manage to get into
    your DC in DMZ I will always have full access to DC in LAN and from DC in
    LAN I will have access to practically all resources in LAN.

    If you want to have this as secure as possible, you should setup another
    forest in DMZ and create one way trust with forest in LAN.

    Let me know if you need more information on this.

    -- 
    Mike
    Microsoft MVP - Windows Security
    "Nir B" <nir@icomverse.com> wrote in message 
    news:OIq2x0zkFHA.576@tk2msftngp13.phx.gbl...
    > Hi All,
    >
    >
    >
    > I have AD that have two DCs, one of the DCs should move to our DMZ and the 
    > second should stay on internal network.
    >
    >
    >
    > What is the best secure way to keep these DCs synchronizing? (Without 
    > opening all the dangerous ports mention on this article: 
    > http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/activedirectory/deploy/confeat/adrepfir.mspx )
    >
    >
    >
    > Thanks In Advanced!
    >
    >
    >
    > Nir B
    >
    > 
    

  • Next message: Mike: "Certificate Services: controling CRL extensions."

    Relevant Pages

    • Re: Securing SQL
      ... How does having a 2nd dmz make it more secure ... >>access a SQL server. ... >>file replication or in the dmz and open up the firewall for sql traffic. ... > connections be established from your LAN to the DMZ. ...
      (microsoft.public.windows.server.security)
    • Re: Firewall and DMZ topology
      ... attacker cannot spread his influence across the network. ... If the DMZ resides between the public Internet and the ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
      (Security-Basics)
    • Re: Web portal security
      ... win2003 standard server with IIS, SSL enabled and will be placed on ... So I will be fwding port 443 in firewall to my DMZ port. ... Well, assuming you are going to use teh SQL database from SBS, you can ... subnet than my LAN and map one to one from firewall to dmz. ...
      (microsoft.public.windows.server.sbs)
    • Re: general question on design options
      ... Behind that I have my ISA, ... How do you get the VPN connections that terminate on the Cisco to get past ... DMZ and not the LAN. ...
      (microsoft.public.isa)
    • Re: Where to put the server
      ... Put the 2003 IIS Server in the DMZ. ... SBS box or another LAN server. ...
      (microsoft.public.backoffice.smallbiz2000)