Re: AD Authentication in a DMZ (up) ?
- From: "Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx>
- Date: Thu, 11 Oct 2007 12:20:58 +0100
Hi
- You'll need to open the necessary ports between DMZ and internal to allow
authentication.
--
===================================
I hope that the information above helps you.
Have a Nice day.
Jorge Silva
MCSE, MVP Directory Services
===================================
"Pascal" <pascal_t@xxxxxxxxxxxxxxxxxx> wrote in message
news:mn.5ac07d7ae674d1fa.70874@xxxxxxxxxxxxxxxxxxxxx
Hi,
anybody has ideas or documentations about this classical question please ?
Thank you
Hi,
we have an application in our DMZ that needs to use Active Directory
database for authentication.
Of course our AD domain controllers are in our LAN.
Is there a secure way to use AD Authentication for applications
localized in a DMZ ?
Thanks a lot.
Regards,
Pascal
One option is to use ADAM with userProxy objects which will forward
authentication requests to Your AD in LAN.
Other option is to use ADFS, but your application will have to be tested
if it will work with ADFS.
Third option is AD forest in Your DMZ which will have trust relationship
with Your main AD (I don't like such solution but this is also an
option)
Thank you Thomas,
Why the third option is less secure than ADFS or ADAM ?
Is there another solution with a radius in the DMZ that will forward the
authentication request to the DC in the LAN ?
Thanks
--
Pascal
.
- Follow-Ups:
- Re: AD Authentication in a DMZ (up) ?
- From: Pascal
- Re: AD Authentication in a DMZ (up) ?
- References:
- AD Authentication in a DMZ ?
- From: Pascal
- Re: AD Authentication in a DMZ ?
- From: Tomasz Onyszko
- Re: AD Authentication in a DMZ ?
- From: Pascal
- AD Authentication in a DMZ (up) ?
- From: Pascal
- AD Authentication in a DMZ ?
- Prev by Date: Re: AD Password Corruption - Is it possible, how does it happen and how do I stop it?
- Next by Date: Re: AD Password Corruption - Is it possible, how does it happen and how do I stop it?
- Previous by thread: AD Authentication in a DMZ (up) ?
- Next by thread: Re: AD Authentication in a DMZ (up) ?
- Index(es):
Relevant Pages
|
Loading