Re: modify the SRV weightings

From: Simon Geary (simon_geary_at_hotmail.com)
Date: 09/13/04


Date: Mon, 13 Sep 2004 08:57:50 +0100

Although if you did this you would have to change the IP subnet of the DMZ
which would require routing between the DMZ and LAN. Correct me if I'm wrong
but I don't think you can associate the same subnet with two different
sites?

I would go a step further and suggest a dedicated AD forest within the DMZ.
This is recommended in order to isolate your corporate AD from the more
exposed DMZ. Frits, do you really need AD in the DMZ? Would ADAM be
sufficient for any DMZ authentication, maybe in conjunction with the new
ADAM Sync tool?

However, if you do decide to go against the best practice of a new forest
then you can adjust the SRV weight records by changing the LdapSrvWeight
entry in this registry key of the DC. The range is from 0-100 and the
default is 100. I have never tried this, but I assume if you change the
value to 0 no clients will use it for authentication.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters

"Tim Springston [MS]" <tspring@online.microsoft.com> wrote in message
news:Oy%23mMOTmEHA.2340@TK2MSFTNGP11.phx.gbl...
> Hi Frits-
>
> You can certainly do this, but I woudl suggest placing the different DCs
> in different Active Directory sites instead. Perhaps a site named
> SiteName DMZ and one named SiteName.
>
> The reason this will work better for you is that the clients do a
> DSGETSITE lookup to try and locate a DC specific to their site, based on
> the IP subnet the client workstations (or server or DC) has and the IP
> subnet(s) associated with a specific AD site.
>
> Please repost if we can help further.
>
> --
> Tim Springston
> Microsoft Corporation
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
>
> "Frits Blankenzee" <f.blankenzee@sinegroup.nl> wrote in message
> news:%23CupT8ylEHA.3392@TK2MSFTNGP15.phx.gbl...
>> Hi,
>>
>> There is a possibilty to change the SRV Weightings via a Reg key but.
>> When I go to link http://support.microsoft.com/?id=306602 I can find a
>> lot of reg keys but I can't find the solution I would like to find.
>> I have 2 DC's (win 2000) one in my lan and one in my DMZ. Both are in the
>> same domain.
>> Now I want that the clients only connect to the ad from the dc in my lan.
>> And not in the DMZ.
>> Now I heard the via SRV Weigthings I can make a sort of preffered server.
>> Can anyone give me an example what to do.
>>
>> Greetings Frits Blankenzee
>> The Netherlands
>>
>
>



Relevant Pages

  • Re: Windows 2003 Server Web Edition Installation
    ... external web site with files for our clients to download. ... Do not open up any ports from DMZ to LAN. ...
    (microsoft.public.windows.server.setup)
  • Re: Where to put the server
    ... the the clients from the LAN. ... With the webserver in the DMZ and netbios running over tcp how safe is it ... > If you have an SBS running as the DC of a domain with LAN clients, ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: dmz access out
    ... you definately want to use a different subnet off a different ... router interface, if a machine on your dmz becomes comprised (which is ... machines on your LAN from the machine on the dmz (within the same ...
    (comp.dcom.sys.cisco)
  • Re: Where to put the server
    ... If you have an SBS running as the DC of a domain with LAN clients, ... can't put the SBS in DMZ without putting the clients in DMZ as well, ...
    (microsoft.public.backoffice.smallbiz2000)
  • RE: ipfw, natd and routing question
    ... The first case diverts incoming packets for the DMZ, ... The second case fails to divert response packets for the inside, ... connected to our DMZ subnet, ... The information contained in this communication is confidential and is ...
    (FreeBSD-Security)