Re: AD Authentication in a DMZ ?




One option is to use ADAM with userProxy objects which will forward authentication requests to Your AD in LAN.

Other option is to use ADFS, but your application will have to be tested if it will work with ADFS.

Third option is AD forest in Your DMZ which will have trust relationship with Your main AD (I don't like such solution but this is also an option)

Thank you Thomas,

Why the third option is less secure than ADFS or ADAM ?

Is there another solution with a radius in the DMZ that will forward the authentication request to the DC in the LAN ?

Thanks

--
Pascal


.



Relevant Pages

  • AD Authentication in a DMZ (up) ?
    ... authentication requests to Your AD in LAN. ... Other option is to use ADFS, but your application will have to be tested if it will work with ADFS. ... Third option is AD forest in Your DMZ which will have trust relationship with Your main AD ... Is there another solution with a radius in the DMZ that will forward the authentication request to the DC in the LAN? ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Authentication in a DMZ ?
    ... Is there a secure way to use AD Authentication for applications localized in a DMZ? ... One option is to use ADAM with userProxy objects which will forward authentication requests to Your AD in LAN. ... Other option is to use ADFS, but your application will have to be tested if it will work with ADFS. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Authentication in a DMZ (up) ?
    ... when we want that an application in a DMZ zone can use AD authentication ... request from DMZ to DCs? ... Thomas told me about ADAM, ADFS or a specific forest only for Applications ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Authentication in a DMZ (up) ?
    ... ADFS or a specific forest only for Applications ressources. ... Can we use a RADIUS proxy in the DMZ that will sned authentication request from DMZ to DCs? ... Why the third option is less secure than ADFS or ADAM? ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Authentication in a DMZ (up) ?
    ... You'll need to open the necessary ports between DMZ and internal to allow ... database for authentication. ... Other option is to use ADFS, but your application will have to be tested ... Why the third option is less secure than ADFS or ADAM? ...
    (microsoft.public.windows.server.active_directory)

Loading