AD Authentication in a DMZ (up) ?



Hi,

anybody has ideas or documentations about this classical question please ?

Thank you

Hi,

we have an application in our DMZ that needs to use Active Directory database for authentication.

Of course our AD domain controllers are in our LAN.

Is there a secure way to use AD Authentication for applications localized in a DMZ ?

Thanks a lot.

Regards,

Pascal


One option is to use ADAM with userProxy objects which will forward authentication requests to Your AD in LAN.

Other option is to use ADFS, but your application will have to be tested if it will work with ADFS.

Third option is AD forest in Your DMZ which will have trust relationship with Your main AD (I don't like such solution but this is also an option)

Thank you Thomas,

Why the third option is less secure than ADFS or ADAM ?

Is there another solution with a radius in the DMZ that will forward the authentication request to the DC in the LAN ?

Thanks

--
Pascal


.



Relevant Pages

  • Re: AD Authentication in a DMZ ?
    ... authentication requests to Your AD in LAN. ... Other option is to use ADFS, but your application will have to be tested if it will work with ADFS. ... Is there another solution with a radius in the DMZ that will forward the authentication request to the DC in the LAN? ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Authentication in a DMZ ?
    ... Is there a secure way to use AD Authentication for applications localized in a DMZ? ... One option is to use ADAM with userProxy objects which will forward authentication requests to Your AD in LAN. ... Other option is to use ADFS, but your application will have to be tested if it will work with ADFS. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Firewall and DMZ topology
    ... attacker cannot spread his influence across the network. ... If the DMZ resides between the public Internet and the ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • Re: Web portal security
    ... win2003 standard server with IIS, SSL enabled and will be placed on ... So I will be fwding port 443 in firewall to my DMZ port. ... Well, assuming you are going to use teh SQL database from SBS, you can ... subnet than my LAN and map one to one from firewall to dmz. ...
    (microsoft.public.windows.server.sbs)
  • Re: general question on design options
    ... Behind that I have my ISA, ... How do you get the VPN connections that terminate on the Cisco to get past ... DMZ and not the LAN. ...
    (microsoft.public.isa)

Loading