Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: Domain & AD in the DMZ

Reply
Thread Tools Display Modes

Re: Domain & AD in the DMZ

 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      09-11-2009

Hello Sam,

Check out this one about using RODCs in a DMZ, applies on 2008 or higher:
http://technet.microsoft.com/en-us/l...34(WS.10).aspx

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi,
>
> I wonder if any of you can help me out with what is now the best
> practice for configuring a DMZ?
>
> I have always been of the opinion that it's best not to have a domain
> in the DMZ if possible (just use a workgroup with all servers having
> their file & printer sharing and Microsoft networking client disabled)
> as this would seem to be the most secure configuration. At the moment
> I have followed this arrangement: we have several servers in the DMZ
> but we log into them all locally when we need to administer them and
> they all only pull information from an FTP site, a SQL server and an
> application server inside our LAN. Sometimes this has been a pain but
> we've always worked around it for the sake of security.
>
> I am now looking into migrating to using IIS7 for our web servers and
> the Shared Configuration feature is very appealling (where you can
> store the config centrally where it is referenced by all of the
> servers in your web farm) but it's proving very difficult to get it to
> work reliably without a domain as it needs shares and certain
> permission levels.
>
> From looking around the web I get the impression that making a domain
> inside the DMZ is not as much of a "don't you dare" thing to do as it
> used to be, especially if it's a standalone domain i.e. doesn't talk
> to your internal domain. So I'm thinking that I might make a domain
> in my DMZ to help me out with this sort of thing. I've not been able
> to find any articles online that talk about this sort of situation so
> was wondering whether you guys would still be saying "don't you dare"
> to this idea or whether this is now commonplace.
>
> Just to be clear: I am not wanting my new domain in the DMZ to
> communicate with my internal domain at all. Hopefully this makes it a
> simpler decision. The domain controller would not be one of the web
> servers, it would not be accessible by the public at all as it
> wouldn't be hosting anything for them; but it would be in the DMZ.
>
> Thanks,
>
> Sam
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
an domain anmelden kostenlose domain einrichten freie de domains domain driven design domain name sdgvfwe@yahoo.is.com Windows Small Business Server 0 07-18-2008 01:19 AM
Re: DNS Config for Windows domain w/ same Domain Name as Public Domain Ace Fekay [MVP] DNS Server 0 08-23-2007 02:00 AM
Re: Making a server on one domain the domain controller of a new domain Miha Pihler [MVP] Windows Server 0 09-11-2006 04:39 PM
rename AD 2003 Domain from domain.org to domain.local SSDSMike Active Directory 3 09-05-2005 10:25 PM
Peer Root domain, single domain or Placeholder domain sAnTos Active Directory 2 02-10-2005 03:21 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59