PC Review


Reply
Thread Tools Rate Thread

Domain in the DMZ

 
 
m-bolds@comcast.net
Guest
Posts: n/a
 
      7th Jun 2006
I just recently worked with a vendor to upgrade a Windows NT domain
into a Windows 2003 Active Directory Domain. I currently have a empty
root for security purposes and a child domain with all of our
resources. A contractor will be arriving to move Active Directory into
the DMZ. I would like to get a head start on the AD move prior to his
arrival. I have very little experience with firewalls, so i'm at a
disadvantage. What all is needed to make this happen?
Any suggestions and or direction will be greatly appreciated.

Michael

 
Reply With Quote
 
 
 
 
Inukshuk
Guest
Posts: n/a
 
      9th Jun 2006
Hi,

http://www.interhack.net/pubs/fwfaq/

You should hire an other contractor if you are not sure what you are doing
with a firewall. It is not difficult setting it up, if you would like full
advantages you should consider an expert.

Greetings,


<m-(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>I just recently worked with a vendor to upgrade a Windows NT domain
> into a Windows 2003 Active Directory Domain. I currently have a empty
> root for security purposes and a child domain with all of our
> resources. A contractor will be arriving to move Active Directory into
> the DMZ. I would like to get a head start on the AD move prior to his
> arrival. I have very little experience with firewalls, so i'm at a
> disadvantage. What all is needed to make this happen?
> Any suggestions and or direction will be greatly appreciated.
>
> Michael
>



 
Reply With Quote
 
Ace Fekay [MVP]
Guest
Posts: n/a
 
      13th Jun 2006
In news:(E-Mail Removed),
m-(E-Mail Removed) <m-(E-Mail Removed)> stated, which I commented on
below:
> I just recently worked with a vendor to upgrade a Windows NT domain
> into a Windows 2003 Active Directory Domain. I currently have a empty
> root for security purposes and a child domain with all of our
> resources. A contractor will be arriving to move Active Directory into
> the DMZ. I would like to get a head start on the AD move prior to his
> arrival. I have very little experience with firewalls, so i'm at a
> disadvantage. What all is needed to make this happen?
> Any suggestions and or direction will be greatly appreciated.
>
> Michael


May I ask exactly why would you want to put a DC that is part of your
private internal protected network and domain and then expose it to the
Internet (firewall or not)?

There are about 29 ports, not to mention the dynamic emperical response
ports UDP 1024 and above, that AD requires for DC to DC communications, and
about 15, including those UDP ports, for client to DC communication. Do you
want to open them up? That would expose too much.

If you are trying to allow access from remote users, consider a 3rd party
VPN solution, such as a Cisco PIX (which I like, but of course I assume the
firewall you are installing has that feature) to create tunnels for your
users to access internal resources, rather than putting a DC outside.

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Having difficulty reading or finding responses to your post?
Instead of the website you're using, I suggest to use OEx (Outlook Express
or any other newsreader), and configure a news account, pointing to
news.microsoft.com. This is a direct link to the Microsoft Public
Newsgroups. It is FREE and requires NO ISP's Usenet account. OEx allows you
to easily find, track threads, cross-post, sort by date, poster's name,
watched threads or subject.

It's easy:
How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Directory Services
Microsoft Certified Trainer

Infinite Diversities in Infinite Combinations
Assimilation Imminent. Resistance is Futile
"Very funny Scotty. Now, beam down my clothes."

The only thing in life is change. Anything more is a blackhole consuming
unnecessary energy. - [Me]




 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
free domain de vu kostenlose homepage mit eigener domain domain registrierung schweiz domain bei web de email domain sdgvfwe@yahoo.is.com Microsoft Windows 2000 Networking 0 18th Jul 2008 03:58 AM
biz domain registrieren kostenlose eu domains domain alias weiß jemand wo ich eine guenstige domain bekommen kann internet domain sdgvfwe@yahoo.is.com Windows XP Messenger 0 18th Jul 2008 03:58 AM
eigene web domain kostenlose domain registrierung domain driven design homepage de domain samba domain sdgvfwe@yahoo.is.com Microsoft Excel Worksheet Functions 0 18th Jul 2008 03:56 AM
domain lookup guenstige de domain de domain sponsor kostenlose domain adresse de tc domain sdgvfwe@yahoo.is.com Microsoft Excel Discussion 0 18th Jul 2008 03:06 AM
domain reservieren kostenlos guenstige net domain de domain guenstig de domain erstellen kostenlose web domain sdgvfwe@yahoo.is.com Microsoft Windows 2000 Group Policy 0 8th Jul 2008 10:31 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 01:30 PM.