Re: 3rd Party Firewalls on Domain Controllers.



Bill,

Not an expert on Networking Hardware Security devices so take this with a
grain of salt!

I would - were money not an issue - opt for a Hardware solution. Both
SonicWall and Cisco have outstanding Firewalls. As do many others ( there
are too many to name and I am somewhat familiar with those two that I did
name.... ). I would also consider using IPCop or SmoothWall - both Linux
Distribution solutions.

I would be very hesitant to run any Firewall on a Domain Controller. Now,
the SBS guys and gals are probably going to shoot me for this as ISA is a
pretty good solution. I would prefer to run that sort of software - were I
to use it over a hardware solution - on a dedicated machine. And it can be
a low end workstation class machine...a nice PIII-450 with 128MB of RAM
would do the trick nicely.

Not sure if this helps any.

And I am not that familiar with WIN2003. I know that SP1 'breaks' some
things.....have read a couple of posts but have not done any investigating
just yet.

--
Cary W. Shultz
Roanoke, VA 24012
Microsoft Active Directory MVP

http://www.activedirectory-win2000.com
http://www.grouppolicy-win2000.com



"Bill-MT" <BillMT@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:59A0346E-899F-45FD-8B3C-1ECD09E285C6@xxxxxxxxxxxxxxxx
> I've been looking into the features of the firewall now included with W2K3
> sp1 and while I think its great MS is now including a firewall on it's
> server
> software. I'm not sure their 'first iteration' firewall has a rich enough
> feature set to do specialized rule logging or selectivitly block problem
> machines.
>
> So, I'm wondering what 3rd party firewalls people have been installing on
> their Windows AD Domain Controllers, specifically on Windows 2000 server
> Domain Controllers right now, but eventually on Windows 2003 server Domain
> Controllers.
>
> Anyone who has an opinion on or experience with this issue please
> reply to this thread. I'd be curious to know the following....
>
> - What 3rd party firewall software has worked on Domain Controllers.
> - And any DC specific configuration issues I should be aware of.
>
> - What 3rd party firewall software is a problem (has not worked well) on
> Domain Controllers.
>
> - What firewall features are important with reguard to firewall software
> installed on Domain Contollers.
>
> Thanks in advance for any info you can offer on this topic.
> --
> Bill


.



Relevant Pages

  • Re: How To Force LDAP Queries Through One Domain?
    ... In any case, my focus wasn't on whether a firewall was necessary, but more ... Other white papers on the topic of isolating domain controllers behind ... Windows 2003 that documents behavior between two forests in a trust, ... >> When you login to a domain on a computer that is a member server in the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Windows firewall for domain controllers
    ... So, if the Windows Firewall on the Domain Controllers is blocking the authentication requests, you will get the symptoms your users report. ... It is quite possible that the Firewall Policy you configured for the Domain has different settings for the Standard Profile than for the Domain Profile in the Windows Firewall part of the GPO. ...
    (microsoft.public.windows.group_policy)
  • Re: Stand Alone DHCP Servers and Windows 2000
    ... but I stand by the statement that a firewall limits ... client network from domain controllers by an ISA Server 2004 firewall, ... RPC, and that is solved by ISA Server 2004. ... Every virus I have ever been hit with would not have even been slowed down ...
    (microsoft.public.windows.server.networking)
  • Re: XP Firewall setting for AD
    ... Generally you don't configure the Windows Firewall on the domain controllers ... computers used for domain administration and domain controllers if you are ... > Without configuration, Group Policies aren't being applied, WSUS also ...
    (microsoft.public.windowsxp.security_admin)
  • Re: How well does the Windows Vista Firewall work?
    ... It even calls the firewall software. ... I think people who try to differentiate between hardware and software ... Gary S. Terhune ...
    (microsoft.public.windows.vista.general)