Re: Is total domain Isolation possible?



On 22 Aug., 19:10, "Steve Riley [MSFT]" <steve.ri...@xxxxxxxxxxxxx>
wrote:

When you understand how authentication works, it becomes apparent why the
domain controllers have to be exempt from your IPsec policies.

Hello Steve

Nice explanations - you should do some CBT videos when you get the
time.

One more question though:

I still dream of the total isolation of the domain scenario. As in, no
potential security risk by having the DHCP and DC servers excluded
from IPsec encryption. I know, that by enabling the firewall on the DC
and DHCP servers, they will be pretty secure by default, but they
still posses a security risk in my book. "Code Red"-like malware on un-
managed computers might infect the servers if an vulnerability exists.

Will the total isolation be possible by using pre shared keys instead
of Kerberos? DHCP can be solved by using a workgroup DHCP server.

Or is the total isolation just fiction so far on XP/2003?

Thanks for your time.

Kind regards, Soren

.



Relevant Pages

  • Re: Is total domain Isolation possible?
    ... If you introduce non-Kerberos authentication methods, then it's possible for non-domain clients to participate if they know the preshared key. ... So I guess it depends on which risk you perceive to be greater: unauthorized machines circumventing your isolation policy or attacks against domain controllers. ... I still dream of the total isolation of the domain scenario. ... and DHCP servers, they will be pretty secure by default, but they ...
    (microsoft.public.windows.server.security)
  • Re: DHCP server authorization - how does it work?
    ... > the network stack and domain controllers, ... authorization is invoked ... Win2000+ DHCP servers will respect IF they receive ...
    (microsoft.public.win2000.active_directory)
  • DHCP Server Delegation
    ... I have several DHCP servers running on domain controllers, ... would like to allow the remote site administrators to manage the DHCP server ...
    (microsoft.public.win2000.active_directory)