Security Basics mailing list archives
Re: AD in the DMZ . . . OK?
From: Tomasz Onyszko <T.Onyszko () w2k pl>
Date: Thu, 29 Jul 2004 10:34:28 +0200
karl wrote:
I will not recommend such configuration, this is not good from the security point of view and also it may caouse some problems with Your firewall configuration an produce another "exception" in firewall policy. Instead of this I will recommend using ADAM (AD in Application Mode) and if this application needs to get data from AD You can replicte data from AD to ADAM using MIIS (Feature Pack) or ADAM Synchronizer which are avilable for free form micrsofot siteHelloOne of the developers I work with has come up with a wild and crazy notion to write a .NET app that sits on a DMZ Web server but gets user information from the Active Directory on the other side of the firewall..I'm inexperienced with this, so did some research and found that this kind of thing is possible (plenty of articles on putting Exchange servers in the DMZ), but found myself wondering if this ever happens, i.e. do people actually have their networks set up this way? Do folk expose/replicate AD to the DMZ in practice?It's all very well that this stuff is possible, but if it's perceived as insecure and not implementable in the real world . . . . . . .Thanks for any advice . . . . .
-- Tomasz Onyszko [MVP] T.Onyszko () w2k pl http://www.w2k.pl ---------------------------------------------------------------------------Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------
Current thread:
- AD in the DMZ . . . OK? karl (Jul 28)
- Re: AD in the DMZ . . . OK? Pierre A. Cadieux (Jul 29)
- Re: AD in the DMZ . . . OK? Oleg K . Artemjev (Jul 29)
- Re: AD in the DMZ . . . OK? Tomasz Onyszko (Jul 29)
- <Possible follow-ups>
- RE: AD in the DMZ . . . OK? Roger A. Grimes (Jul 29)
- Re: AD in the DMZ . . . OK? Ivan Coric (Jul 30)
- RE: AD in the DMZ . . . OK? Dieter Sarrazyn (Jul 30)
- Re: AD in the DMZ . . . OK? Ansgar -59cobalt- Wiechers (Jul 31)
- Re: AD in the DMZ . . . OK? Peter Van Eeckhoutte (Jul 31)
- RE: AD in the DMZ . . . OK? Handy, Mark (IT) (Jul 30)
- RE: AD in the DMZ . . . OK? Ferino Mardo (Jul 30)