Solved

Widnows DCs Firewalled

Posted on 2004-09-18
2
266 Views
Last Modified: 2010-04-19
Hey All,

   I have a secure subnet (behind a firewall) in my network and both my DCs are in the outside portion.   We're having trouble authenticating shares (you might not have permission to access this network share), and I'm sure there will be other issues with AD....   The network setup is this:

Internet
  |
Firewall
192.168.1.xxx
  |
AD Controllers & some XP Clients 192.168.1.x
  |
192.168.1.xxx
Inside Firewall running RHEL 3 & iptables firewall\
192.168.210.x
  |
some XP Clients & some windows servers 192.168.210.x

   How can I use windows services without access to the DCs & my AD?
0
Comment
Question by:smithware
2 Comments
 
LVL 51

Accepted Solution

by:
Netman66 earned 500 total points
ID: 12093775
Place one DC inside the second firewall.  Create rules through the second firewall so that the other DC can connect to it point-to-point.

You'll need to understand what ports should be opened between these servers.

Here is a start at determining what is used:  http://support.microsoft.com/default.aspx?scid=kb;en-us;832017&Product=winsvr2003

The idea is to use the inside server to connect to and mount shares from the .1.xxx subnet as volumes in empty NTFS folders.  This will allow internal clients to only map to their local server for resources.

How to mount: http://support.microsoft.com/default.aspx?scid=kb;en-us;323424&Product=winsvr2003

0
 

Author Comment

by:smithware
ID: 12108198
Although I accepted this answer, it should be noted that the answer to the question was actually create an lmhosts file on the clients to point to the domain controllre.
0

Featured Post

How Do You Stack Up Against Your Peers?

With today’s modern enterprise so dependent on digital infrastructures, the impact of major incidents has increased dramatically. Grab the report now to gain insight into how your organization ranks against your peers and learn best-in-class strategies to resolve incidents.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin Within the dynamic life of an IT administrator, we hold many information in our minds like user names, passwords, IDs, phone numbers, incomes, service tags, bills and the order from our wives to buy milk when coming back to home.…
I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question