Authentication on a web server via AD



I am looking for some info regarding how to authenticate to a web server with
an active directory username and password.
But I have som rules that I have to follow.

1. The web server is located on a dmz
2. The active directory controller is located on lan
3. I can not open any port from dmz to lan
4. I can open ports from Lan to dmz

How can I still get the web server to autenticate with AD without breaking
rule nr 3?

I see only one senario:
Put another AD controller on the dmz
somehow replicate AD info from "lan AD controller" to "dmz AD controller"
Let the web server authenticate with "dmz AD controller"
I can not have "dmz AD controller" contact "lan AD controller" inn any way
All communication has to be from Lan to dmz not the other way around.

Does anyone know if this is possible?

Regards
K

.



Relevant Pages

  • Re: Joining web server to SBS domain - any pre-cautions?
    ... I'm trying to plan for joining our web server (Server 2003 Std. ... You should have a REAL FIREWALL APPLIANCE, ... A single public IP can provide HTTP access for the DMZ Network and also ... If you firewall has a DMZ and it's in the same Subnet as the LAN, ...
    (microsoft.public.windows.server.sbs)
  • Re: DMZ and file sharing
    ... Never ever use DMZ, a) its an open unlocked door with a big sign saying your ... save/retreive files to/from a restricted area on the LAN. ... and only server. ... You need to consider the safety of the LAN when the web server gets ...
    (microsoft.public.windows.server.sbs)
  • RE: DMZ - Question
    ... FW-2 to a different brand that has stateful inspection. ... DMZ to communicate with the inside LAN by NATting in the ... On the DMZ we will have a Web Server that needs access back ...
    (Security-Basics)
  • Re: Adding a web server to my network
    ... I have a LAN behind a hardware firewall connecting to the web by DSL. ... I would like to keep my LAN safe from hackers, and my web server safe ... region is called the DMZ, which is where you put your web ...
    (comp.os.linux.misc)
  • Re: Firewall and DMZ topology
    ... attacker cannot spread his influence across the network. ... If the DMZ resides between the public Internet and the ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)

Loading