Kieran,
thanks for your reply.
DNS is listed there, 3rd from bottom on the 2nd list.
If domain traffic shouldn't be allowed in the DMZ then I will be happy with that and will lock all these ports back down again. I just thought that it was required and should work.
To be honest, I was looking at all the open ports and ranges and my DMZ was starting to look like a Swiss cheese with all those holes.
Main Topics
Browse All Topics





by: Kieran_BurnsPosted on 2009-07-01 at 03:51:47ID: 24753010
The whole point of a DMZ is that it is essentially untrusted (okay SEMI trusted) and you should not allow domain traffic into it.
Saying that I can see straight off that you have missed DNS from the list of allowed ports and AD will not work without it.
What you should be doing is seeing why you need authentication traffic through the firewall and design a solution that does not require it.