Re: AD Authentication on a DMZ ?



Thanks Paul but again I dont think it is the right KB for my problem (perhaps my english is not good enough, sorry :D)

I am asking about a general security architecture conception.

How can I publish an application that is on my DMZ and that is using Active Directory authentication ?

Thanks :)


Look at the ports defined as client in the link below. I though I detailed them but I didn't sorry.

http://support.microsoft.com/kb/179442/en-us

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.


"Eric" <Eric_m@xxxxxxxxxxxxxxxxxx> wrote in message news:mn.0b827d94d2c74f5f.70874@xxxxxxxxxxxxxxxxxxxxx
Hello Paul,

thanks for your answer.

Unfortunately, we are not running 2008, so the RODC solution is not possible.

The ports listed in our article only refers to ports needed to be open for replication, right ?

In my situation, I dont want to put a domain controller on the DMZ for security reason. I would prefer to let the DC on the LAN and to configure my IIS Webserver (for example) in the DMZ to use "AD Authentication".

But my question is "which ports do I need to open to permit only the authentication from a server in a DMZ to a DC in my LAN" ?

Thanks

Microsoft is supposed to release their blueprints for an rodc in the dmz (Hopefully) within the month (At least that is what I heard at TEC last week). If you are running 2008 that would be the way to go.

Otherwise, check out an article I have on what specifically the client needs to log on at:
http://www.pbbergs.com/windows/articles.htm
Select Firewall ports needed for replication

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.


"Eric" <Eric_m@xxxxxxxxxxxxxxxxxx> wrote in message news:mn.0b077d94e8fe9676.70874@xxxxxxxxxxxxxxxxxxxxx
Hello,

we have some applications that are using our Active directory for the user authentication.

Those applications are in our DMZ and our DCs are in our LAN.

My questions are :
1. Is it secure to use AD authentication for applications located in DMZ ? (ADAM (with an AD Sync) should be better ?)
2. if "I dont have the choice" for this architecture, which ports do I need to open from my applications servers to my DCs ?

Thanks ! :)

-- Eric



-- Eric



--
Eric


.



Relevant Pages

  • Re: Firewall between memberserver and DC
    ... The common thing in all guides is that neither provides information about ... absolute minimum of ports required. ... infrastructure becomes exposed to the DMZ, authentication is required. ...
    (microsoft.public.security)
  • Re: AD Authentication on a DMZ ?
    ... I would have the applications use LDAP or LDAPS to authenticate to the DC. ... Or use ADAM in the DMZ. ... the last article proposed by Paul is talking about ports needed for replication between one DC in a DMZ and the other in the LAN. ... You understand me correctly and indeed, I would like to use AD authentication for applications located in my DMZ. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Authentication on a DMZ ?
    ... the last article proposed by Paul is talking about ports needed for replication between one DC in a DMZ and the other in the LAN. ... You understand me correctly and indeed, I would like to use AD authentication for applications located in my DMZ. ... If i understand you correct, you have an application that need's to contact the DC in the LAN, therefore you have to open the ports in the firewall. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Authentication on a DMZ ?
    ... Look at the ports defined as client in the link below. ... I would prefer to let the DC on the LAN and to configure my IIS Webserver in the DMZ to use "AD Authentication". ... Those applications are in our DMZ and our DCs are in our LAN. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Setting up 2 domains with one way trust to dmz
    ... What you refer to as the client ports are probably due to the RPC ... why does the DMZ exist? ... a batch process gets started that will survive the accounts logoff. ... I have no problem with the server ports its the client ports that I ...
    (microsoft.public.security)

Loading