Firewall Wizards mailing list archives

Domain Login Problem Thru Netscreen


From: "Nilanjan Sengupta" <nilanjan.sengupta () paladion net>
Date: Thu, 30 Oct 2003 14:56:30 +0530

Hi,
I need some help from you guys. I will describe the scenario:

I am going to install a  Netscreen firewall and that will have 4 Zones.
Two of them are not relevant in this context. The other two are. The
names of the Zones are Utility and DMZ. Now in Utility I am going to
place a WinNT PDC. People from DMZ will log in to the Box. In DMZ the
LAN users are there with some WAN users too. The WAN connects to
different other locations which have other Domains too.
The PDC is also a Exchange Server which will be replicating with another
Exchange Server in the WAN. Over that it is a Trend Micro Anti Virus
Server which will update Antivirus to the Desktops and the Servers at
other Zones. It will download signatures from Internet through the WAN
(DMZ ZONE).

The Requirement is to enable Domain Login for users from DMZ (LAN and
WAN) and enable Trust Relationship between domain at WAN and this
server. 
My Question is: 
Can this domain Login be done if I configure the DMZ interface as DHCP
Relay Agent pointing to the PDC? I case of Layer 3 Devices (Routers)
this can be done by using the command ip helper-address <ip address>
which is nothing but enabling DHCP Relay. Does this apply to a Netscreen
also? Can you please instruct me what all is required to facilitate this
communication. I do not want to use WINS.

Regards,
Nilanjan Sengupta



_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: