AD Proxy



We are creating a secure DMZ area (VPN access only) and would like to have AD
services in this network. This "SecureNet" will be firewalled off from the
internal network. Rather than putting a domain controller in the SecureNet,
we would prefer to put an LDAP proxy server that would accept LDAP requests
from systems in the SecureNet and forward those requests through the firewall
to the internal domain controllers. Specifically, I said "AD" proxy instead
of "LDAP" proxy because I need Kerberos services to be proxied as well.
Thus, I need the proxy server to appear and act just like an AD domain
controller for the purposes of authentication. Any thoughts on whether this
is possible and, if so, how to accomplish it?

--
Hugh
.



Relevant Pages

  • ISA Server as LDAP Proxy
    ... services in this network. ... Rather than putting a domain controller in the SecureNet, ... we would prefer to put an LDAP proxy server that would accept LDAP requests ... from systems in the SecureNet and forward those requests through the firewall ...
    (microsoft.public.isa.configuration)
  • Re: AD Proxy
    ... Have you already looked at what ISA server can do for you? ... This "SecureNet" will be firewalled off from ... > we would prefer to put an LDAP proxy server that would accept LDAP ...
    (microsoft.public.windows.server.active_directory)
  • Re: Newbie Questions
    ... with the HOWTOs - and then graduate to the "Linux Network Administrator's ... and the firewall is doing NAT. ... when they REALLY need the proxy server? ... there must be written policies in place BEFORE the ...
    (comp.os.linux.networking)
  • Re: How to allow for programs through ISA 2000
    ... Network Proxy Server such as ISA Server. ... firewall or proxy server to perform Smart Update, ...
    (microsoft.public.isa)
  • RE: Proxy & Firewall Implementation
    ... go through the firewall from that machine. ... if it's a decent size network they are ... outside the network in a dmz, is to protect the rest of the network ... circumstances when placing their proxy server inside a protected network ...
    (Security-Basics)

Loading