Avatar of ifred
ifred
Flag for Canada asked on

DMZ box logon to DC

I have a windows box on the DMZ interface of my Cisco asa 5510. This windows box needs to be able to authenticate against a domain controller on the inside interface.

Clients on the inside interface need to be able to access file sharing on this dmz box.

Can somebody assist with the tcp/udp ports required to do that and the access lists ?

Currently I have the domain controller/dns on a static nat mapped to the dmz
CiscoActive DirectoryNetworking

Avatar of undefined
Last Comment
Pete Long

8/22/2022 - Mon
Mike Kline

Have you seen the document "AD in the perimeter network"

http://www.microsoft.com/en-us/download/details.aspx?id=3957

There is a section there that discusses ports.   They also go into using RODCs in the DMZ which is not a bad option.

Thanks

Mike
ifred

ASKER
I will likely move into a RODC in the DMZ later on, for now i just need to make this as transparent as possible.
ASKER CERTIFIED SOLUTION
Pete Long

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
ifred

ASKER
I am not doing this yet, but i verified this worked in lab. Thanks
Your help has saved me hundreds of hours of internet surfing.
fblack61
Mike Kline

Good post by Pete, one caveat in 2008 the high ports  are from

49152 - 65535²

Still a lot of ports but not as bad as 1024+

Thanks

Mike
Pete Long

Nice one Mike I'll amend my notes - I wrote that about 7 years ago!

ThanQ