DMZ Authentication

From: SMFX (anonymous_at_discussions.microsoft.com)
Date: 09/13/04


Date: Mon, 13 Sep 2004 11:51:16 -0700

Well, it seems like such a simple thing that was actually
nice about NT4, but I can't seem to find a way to do it
with Win2k or Win2k3: Falling back to local DC.

Basically, in NT4, if a member server couldn't contact a
trusted domain it would fall back to its own PDC for
authenticating the user. This was nice for DMZ type
setups because you could have one server (the DMZ PDC) as
a point that could authenticate against the internal
domain.

Now in Win2k, if the member server cannot contact the DC
of the trusted domain, it doesn't try its own PDC but just
assumes the domain is unreachable.

I know its not the best security idea in the world to have
anything authenticate in your DMZ to your internal
systems, but sometimes there are pratical applications esp
for signle-sign-on implementations.

Rather than having to have EVERY web server in the DMZ
have to be able to reach my internal DC (gak!), is there
anyway to make the external member servers authenticate a
foreign user via its own DC?

TIA,
SMFX



Relevant Pages

  • Re: Port open for Microsoft
    ... > the DMZ must authenticate to the W2k Sp3 DC in the trusted. ... > authenticate the member server to the DC server?? ...
    (comp.security.firewalls)
  • Re: Port open for Microsoft
    ... performing such a configuration negates the purpose of implementing the DMZ. ... it will have the ability to establish a connection into the internal LAN. ... > the DMZ must authenticate to the W2k Sp3 DC in the trusted. ... > authenticate the member server to the DC server?? ...
    (comp.security.firewalls)
  • Re: DMZ Authentication
    ... Make it Global Catalog Server. ... This was nice for DMZ type ... > a point that could authenticate against the internal ... > of the trusted domain, it doesn't try its own PDC but just ...
    (microsoft.public.win2000.active_directory)
  • Re: RPC Dynamic Ports? Windows 2003 with Checkpoint firewall.
    ... > Just to confirm to setup of my DMZ.. ... I only have a member server in the ... > DMZ and this is to authenticate end users on the internet to access ... > users are allowed to log on locally at this member server in the DMZ so ...
    (comp.security.firewalls)
  • Re: External trust and a member server
    ... I can ping the the trusted domains DC and nslookup also gives the correct ... I tried the connection from an ancient Windows NT member server that is used ... account is disabled in the trusted domain. ...
    (microsoft.public.win2000.active_directory)

Quantcast