Re: Active Directory Authentication and DMZ server

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello Sukhwinder,
If you can't open up any ports, how can you expect to communicate? This isn't a reasonable approach, if you need access to internal info then there are ports that will have to be opened.


--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4


http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This posting is provided "AS IS" with no warranties, and confers no rights.



Dear All,

We have a requirement in our organisation that all the application and
internet facing servers in the organisation should be the part of
Active Directory Domain. We have many servers in DMZ zones and the
Domain controllers are there in LAN zone. We need to have all the DMZ
servers to be authenticated to Active Directory but we cannot open and
Firewall port. So we cannot go for IPSEC.

I would request all to help me in this regard as to if ADFS or ADAM
can help me with the same. If any other solution is there please let
me know.

Thanks and Regards

Sukhwinder Singh



.



Relevant Pages

  • Re: Servers in two Vlans
    ... A good old Active Directory Replication Across Firewalls whitepaper ... Refer to the "Limited RPC" section for a reasonable port list ... What ports am i going to have to open ... > up between those vlans so the two servers can talk to each other and ...
    (microsoft.public.windows.server.security)
  • Servers in two Vlans
    ... What ports am i going to have to open ... different Vlan then the server it authenticates with. ... Cisco 3550's and all servers are compaq DL series of one flavor or ... each other and keep Active Directory working, ...
    (microsoft.public.windows.server.security)
  • Re: Windows 2000 Server pings and scan ports on the network
    ... SysInternals to view what network related processes are running on ... the servers including what ports and application they map to. ... I don'y believe it is Active Directory related.--- Steve ... > Hi we have servers that sometimes ping and scan ports of some PC's. ...
    (microsoft.public.win2000.security)
  • Re: Visa PCI Firewall Requirements and Windows Networks
    ... GP without the risk of open ports or a DC in the DMZ. ... Outbound access should be minimized but if windows update is your ... alternative tools on trusted servers to patch your machine. ... > behind the second firewall. ...
    (Focus-Microsoft)
  • Re: HACKING SOFTWARE
    ... You know there is more to just running nmap on people's servers. ... ICMP requests and I have no open ports what so ever (not just firewalled - ... That's CIA crap!" ...
    (alt.2600)