Charlie Ting schrieb:
> Hi Peter,
>
> The web server is sitting in the DMZ server. How could it access the domain
> name on the trusted LAN ?. And also what firewall rule is it to be
> implemented?
>
for this scenario you need to open the following ports:
Kerberos ports (88/tcp, 88/udp) used to perform mutual authentication
DNS ports (53/tcp, 53/udp)
LDAP ports (389/udp, 389/tcp or 636/tcp for SSL)
Microsoft-DS traffic (445/tcp, 445/udp)
I think it is better to move the Webserver in the internal LAN and to
publish the Website through an ISA 2004 Server.
http://www.microsoft.com/technet/pro...ebservers.mspx
--
Viele Grüße
Frank Röder
MVP Windows Server System - Directory Services
"Ex oriente lux"