Re: One domain controller for several dmzs



Hello:

That should work. You'll need to open up ports on the internal side of the
DMZ for Windows network traffic (DNS, WINS, NetBIOS, et al). This article is
for Exchange, but it's a good starting point:
http://support.microsoft.com/default.aspx?scid=kb;en-us;280132.

Regards,
Martin

"Markus R." <markusr@xxxxxxxxxxxxxxxxx> wrote in message
news:uU6CjQQ9FHA.636@xxxxxxxxxxxxxxxxxxxxxxx
> Hi,
>
> we want to run an internet application with several web servers and an sql
> server cluster in the backend. Physically I want to put the database
> servers into a different network (dmz) that the web servers.
>
> Is it usual to use the same Domain Controller for servers in different
> dmzs?
>
> Are there better approaches?
>
> Most books only describe large coroprate networks when it comes to
> implementing Active Directoy infrastructures. Is there a good book / web
> resource which covers this topic for small / mid-scale web applications?
>
> Regards,
>
> Markus
>


.



Relevant Pages

  • Re: Domain in ISA2004 dmz
    ... put services that are needed to 'listen' for incoming internet requests ... DMZ trusts Seattle.Demo but seattle.demo does ... > Would it just be better if we left nothing but the web servers in the dmz ...
    (microsoft.public.isa)
  • RE: newbie to DMZ
    ... Someone who breaks into a server on the DMZ cannot ... install a sniffer there and gain leverage toward your internal network. ... The DMZ is for servers accessible from the outside world. ... > the Internet the ither is for my Network. ...
    (Security-Basics)
  • Re: How to decide on which network interface domain controller is available
    ... We are having two servers and I decided that for us it is ... (DC and Internet Gateway/Servers). ... with clients) and an external network. ... nullifying the security of having a DMZ, since if the DC on the DMZ ...
    (microsoft.public.win2000.active_directory)
  • RE: Gurus: server on perimeter vs. corporate advice
    ... I personally have implemented SharePoint in both environments (DMZ & internal ... front-end servers. ... on their internal network and due ...
    (microsoft.public.security)
  • Re: DMZ design
    ... inbound traffic from the DMZ is blocked. ... In a small company with almost no servers that could be possible ... protects your company from IT'S OWN SERVERS. ... further (FW'ing the DB from the Inside network as well). ...
    (comp.security.firewalls)