Re: Active Directory in DMZ - security



Hi
Probably because DCs shouldn't be placed on DMZ, but if you want to take the risk and because the only purpose is to serve DMZ servers the best that I can think of at the moment is to use IPSec to restrict communications only between the DC and the servers that need AD access, don't forget to closely monitor those servers and define actions in case of security risk or failure, also have a look at:
http://www.microsoft.com/security/default.mspx
http://www.microsoft.com/technet/security/tools/mbsa1/wp.mspx
http://www.microsoft.com/technet/network/ipsec/default.mspx

--
I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MCSE, MVP Directory Services
"Missy Isaacson" <misaacs@xxxxxxxx> wrote in message news:OvrLp2spHHA.2044@xxxxxxxxxxxxxxxxxxxxxxx
We are in the process of implementing an Win2K3 Active Directory forest
(separate from our internal forest with no trusts) in our DMZ strictly for
the purpose of managing security across the 50+ servers currently in the
DMZ. I have found plenty of documentation related to securing domain
controllers, but I am not finding much specific to domain controllers in the
DMZ. I'm sure there must be additional things I should/could do to these
servers.

Any information about this would be appreciated.



.



Relevant Pages

  • Re: Open Ftp on AS/400
    ... In the end I suppose it comes down to how much risk you want to take ... Being able to put an LPAR in the DMZ sounds good until you calculate ... You mention that SSL requires certificates. ... As for the DMZ issue for servers, ...
    (comp.sys.ibm.as400.misc)
  • RE: Question about DMZ Domain Member and Virus Membership
    ... test and audit the servers regularly. ... Question about DMZ Domain Member and Virus Membership ... Tailor your education to your own professional goals with degree ... Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)
  • RE: antivirus software for DMS computers???
    ... Say you're running an Web+FTP server in your DMZ... ... > All of my servers in the DMZ have AV protection. ... > Ethical Hacking at the InfoSec Institute. ... > pen testing experience in our state of the art hacking lab. ...
    (Security-Basics)
  • Re: internal domain credentials to access DMZ resources
    ... Create a new forest in DMZ, and let DMZ forest trust LAN forest 1 way. ... join web, NAS, and SQL servers to DMZ forest ...
    (microsoft.public.windows.server.active_directory)
  • Question about a trust relationship and terminal serices
    ... one on my internal network and one on a dmz. ... two servers on the dmz.org, one a domain controller and one member server. ... The domain controller is Windows 2003, the member server is Windows 2000. ... the int.org Domain Admins are set as members of the ...
    (microsoft.public.windows.server.active_directory)