Re: How to decide on which network interface domain controller is available



RAP wrote:
Hi,

I have two domain controllers, both are connected to an internal (LAN
with clients) and an external (a DMZ) network.

How can I configure the servers in a way that the domain controller
functionality is only available on the internal network?

My current problem is that the DNS server has both IP addresses for
each server under one name. I cannot remove the external one, Windows
automatically re-creates the entry. Now, when I resolve the name of
server2 on server1 with nslookup it results in both IP addresses. For
some reason the external address is choosen and any communication (e.
g. ping or mount network drive) goes via the external network. This is
not what I want, it should go via the internal (much faster) network.

I was hoping that when I deactivate the domain controller functionality
on the external interface it will not re-create the entry in the DNS,
however I'd be happy about any other solution for my problem as well.

Multi-homed DCs are always a bad idea, unless you cannot think of any other way of doing it. The way that you are doing it is essentially nullifying the security of having a DMZ, since if the DC on the DMZ (which is not absolutely trusted) is compromised, the attacker has a machine on your LAN!

Of course you may have reasons for doing it that way that I know nothing about, in which case my comments may help others. Just please disregard them.

Cheers,

Cliff
.



Relevant Pages

  • Re: IPSec / domain isolation: confusing MS documents
    ... workstation, he is able to attach to server ressources again, but for our ... The user right for access this computer from the network ... will not work for computer accounts unless ipsec is being used. ... securing a domain controller. ...
    (microsoft.public.windows.server.security)
  • PIX ,and Domain Controller errors to the DMZ
    ... I have a PIX 515e running 7.02, and for the most part, it works great. ... We're putting a file server into the DMZ so that outside users will ... a domain controller on the INSIDE of the PIX. ...
    (comp.dcom.sys.cisco)
  • Re: How to connect the NT4 PCD from windows 2003 server
    ... internal is on top of external on the network connection ... for lmhosts files on NT4 server, ... >> type glcdom, which is my NT4 domain controller name, it ...
    (microsoft.public.win2000.security)
  • Linux, New Corporate Network, Cisco Routers, T1 Ethernet Handoff, DMZ...
    ... I am setting up a network for a company that I am part owner of. ... internet go into my Cisco 2621 router that has 3 10/100Mbs FE interfaces. ... the same switch creating the "sandwich" DMZ setup with the public devices in ... PBX server that uses a straight VoIP connection all the way to our service ...
    (comp.os.linux.networking)
  • New Corporate Network, Cisco Routers, T1 Ethernet Handoff, DMZ...
    ... I am setting up a network for a company that I am part owner of. ... internet go into my Cisco 2621 router that has 3 10/100Mbs FE interfaces. ... the same switch creating the "sandwich" DMZ setup with the public devices in ... PBX server that uses a straight VoIP connection all the way to our service ...
    (comp.security.firewalls)