Solved

how insecure is it to leave ldap ports open to the world

Posted on 2013-01-30
6
395 Views
Last Modified: 2013-02-19
I have a server 2008 with Exchange and a cheap router that won't allow me enough config settings to pin ldap ports to a range of external ips.

Am I being foolishif I leave ldap open to the world?
Can I leave it open to the world & forward to my email server can I then pin exchange down further behind it ?
0
Comment
Question by:eddiewickens
6 Comments
 
LVL 77

Expert Comment

by:arnold
ID: 38838160
Why do you need to expose your AD/LDAP to the outside world?
One option is to setup a PPTP VPN server if you must access it.
Alternative get a better router. Depending on the router you have, an option might be to convert it if available I.e. a linksys, asus, etc. see if your router can run dd-wrt.com.
0
 

Author Comment

by:eddiewickens
ID: 38838923
I am trying to set up a permanent sync my ad accounts/passwords with an online anti spam/av solution that has 10 or so servers/ips and I do not have room in my router setup to  allow access from 10 ips - so I have to allow from everyone.

I am trying to find a way not to buy a new router if I don't need to - one way would be to feel I do not have a security risk by leaving it open to all
0
 
LVL 36

Expert Comment

by:ArneLovius
ID: 38838952
Unless you can use with either a VPN tunnel, or use LDAPS (LDAP over SSL on port 636), do not use the service, otherwise your usernames and passwords with be going across the internet in plain text.

I would also only allow access to LDAP (LDAPS) from specific IP addresses, leaving it open is leaving your AD open, it is a security risk

At bare minimum you could use the Windows firewall to restrict access, but if you do not already use the Windows firewall, this could involve more configuration than replacing the router with a more capable one.
0
Are your corporate email signatures appalling?

Is it scary how unprofessional your email signatures look? Do users create their own terrible designs and give themselves stupid job titles? You can make this a lot easier for yourself by choosing an email signature management solution from Exclaimer today.

 
LVL 77

Expert Comment

by:arnold
ID: 38839259
A router or a firewall that will be the device between the router and the LAN
0
 
LVL 62

Accepted Solution

by:
btan earned 500 total points
ID: 38839665
Really don't see that ldap should be exposed to internet and if need to it is isolated and not to public. It will be inviting more trial and scanning attempts to bring service down like brute force, recon to see what is the internal structure domain, etc. You may want to look at this...

http://unixwiz.net/techtips/security-ldap-ad.html

Minimally there is need for proxy to do the first layer checks where possible...maybe going into LDS or ADAM to restrict but it may not meet your needs. I saw that when contractor need access to end user resource site but didn't want to expose whole ad but only specific to the user application resource needs....can be out of context for your case though
0
 
LVL 36

Expert Comment

by:ArneLovius
ID: 38906824
I thought I covered the same points in more actual detail, but you awarded the points to somebody else.

Was there something that I missed ?
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Migrate Cisco ASA 5510 and 5515 K9? 12 64
Sendmail STARTTLS error 37 84
Cisco ASA policy-map not matching the specific traffic 3 52
RDP Sonicwall 8 67
Workplace bullying has increased with the use of email and social media. Retain evidence of this with email archiving to protect your employees.
Easy CSR creation in Exchange 2007,2010 and 2013
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now