FTP server in DMZ and authentication to/from internal AD



All,

I was hoping to get some advice on how others deal with having internal AD
users connect to an FTP server located in the DMZ. This is a legacy system
that worked fine before we required users to change their passwords in AD
every 60 days. Now, we have to change the local account on the FTP server so
they can reconnect their mapped drives. There are about 30 uses who connect
in this way and they use it for putting financials, vendor contracts, specs,
etc..... on the FTP box that the external users grab and vice versa.

I'm thinking of having a Virtual Directory on the FTP server that points to
an internal (inside of the DMZ) share where the users put/get their stuff.
Besides security concerns, are there known issues with this?

I've also thought of just having our internal folks access the FTP box via
FTP instead of mapped drives and such. However, I believe that there are jobs
that actually put the data directly to the FTP box via mapped drives instead
of through FTP. This is totally controlled by the departments so we have a
bit of research left.

Are there any tools available that can securely replicate the internal AD
accounts (Roughly 50 accounts and all are just Domain Users) to the FTP
server?

Thanks for any advice.

Craig

.



Relevant Pages

  • Re: Microsoft FTP Server problem on W2K?
    ... It is a UNISYS ClearPath mainframe system that is trying to FTP using ... passive mode to a MS FTP server. ... Currently the mainframe FTPs in ACTIVE mode. ... Since the mainframe pushes files to our customers over a WAN connection, ...
    (microsoft.public.inetserver.iis.security)
  • Re: FTP server in DMZ and authentication to/from internal AD
    ... Authentication in a DMZ is just one of those problems with no simple answer: ... staging folder on internal domain, copied as a task up to the DMZ folder ... DMZ proxy that publishes your internal folder over FTP ... we have to change the local account on the FTP server ...
    (microsoft.public.windows.server.active_directory)
  • RE: FTP Upload
    ... FTP server to the following specified size. ... //set or get the remote path of the FTP server that you want to connect. ... //set the class MessageString. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: FTP Upload
    ... FTP server to the following specified size. ... //set or get the remote path of the FTP server that you want to connect. ... //set the class MessageString. ...
    (microsoft.public.dotnet.framework.aspnet)
  • RE: vsftpd beginners tutorial?
    ... # This file was created to illustrate the steps needed to create a new FTP ... Why vsftpd as this FTP Server? ... System software customization considerations. ... User and Group Configuration ...
    (RedHat)