Re: Remote site w/o VPN?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




"Fritz" <fritz@xxxxxxxxxxxx> wrote in message
news:OCdOGjIRHHA.3812@xxxxxxxxxxxxxxxxxxxxxxx
Herb,
Thanks for the response. Would you mind explaining or pointing me to an
article that explains how DCs "sort of" encrypt traffic?

I don't know that there is one that goes beyond the following:

DCs setup a (supposedly) secure channel for doing replication.
The replication traffic is usally also compress between sites (but
no guarantee on the compression part since it kicks in at a minimum
size of transfer.)

In a private discussion with one of the AD developers at a TechEd,
he warned me that the traffic was merely "obfuscated" but not
technically encrypted in such a way as to make it fully secure.

--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)



.



Relevant Pages

  • Re: Trust between two Forests Fail
    ... This tells you that name resolution AND authentication is working in one ... OR "Site that doesn't not work" DCs will FAIL DCDiag in some way. ... (phone on web site) ...
    (microsoft.public.windows.server.active_directory)
  • Re: Is it possible to totally crash AD?
    ... your DCs to other offsite DCs even if you don't naturally have ... offsite live and offsite storage of backups alleviates most ... presentations all over their web site. ... Accelerated MCSE ...
    (microsoft.public.windows.server.active_directory)
  • RE: To disable SMB packet and secure channel signing enforcement on Windows Server 2003-based domain
    ... Secure Channel is used by domain member ... computers to pass user authentication information to DCs. ... To disable SMB packet and secure channel signing enforcement on ...
    (Focus-Microsoft)
  • Re: Win2000 DC Question
    ... They have been offline for 2 months now ... As long as you can get the DCs IP address* properly registered (and ... domain forest every DC should be a GC. ... (phone on web site) ...
    (microsoft.public.win2000.active_directory)
  • Re: Kerberos errors after swapping domain controller IPs
    ... I'm not sure if Al agrees but, You can try to stop the KDC service on all ... the DCs and reset the secure channel on each DC using the netdom command. ... After resetting the secure channel password, you can reboot the server. ...
    (microsoft.public.windows.server.active_directory)