Disable internet access to 2012 domain controllers

Due to security reason I dont want internet access in my domain controllers, I need help to know the best practices to disable internet in Domain Controllers.
LVL 26
Sekar ChinnakannuStaff EngineerAsked:
Who is Participating?
 
MaheshArchitectCommented:
The network firewall works on default rule /  principal that block everything except .....
u need to add domain controller ips in default internet block rule which should take care of everything
0
 
Shaun VermaakTechnical Specialist/DeveloperCommented:
Network or host-based Firewall (like Windows Firewall) will be able to block internet access

Blocking it from a Network layer is best
0
 
MaheshArchitectCommented:
create root zone on domain controller, it will stop internet access  and internet name resolution from all domain controller

but is this your intention ?
0
Simple Misconfiguration =Network Vulnerability

In this technical webinar, AlgoSec will present several examples of common misconfigurations; including a basic device change, business application connectivity changes, and data center migrations. Learn best practices to protect your business from attack.

 
Shaun VermaakTechnical Specialist/DeveloperCommented:
That will stop internet name resolution, not internet access
0
 
MaheshArchitectCommented:
it depends on how internet is accessed
After creating root zone On domain controllers, if proxy is used to access internet and if that proxy is not dependent on domain controller for name resolution, you can access internet,
otherwise if proxy is dependent on domain controllers for name resolution, you cannot access internet no matter if you have internet access on proxy or not and then this will be applicable to clients as well.

If there is no proxy defined, and domain controller only responsible for name resolution, still you cannot access internet, note that all clients will not be able to access internet as well
0
 
Shaun VermaakTechnical Specialist/DeveloperCommented:
If there is no proxy defined, and domain controller only responsible for name resolution, still you cannot access internet
Of course you can, just not by name
0
 
MaheshArchitectCommented:
it's too difficult to access internet by entering public ip addresses
0
 
Sekar ChinnakannuStaff EngineerAuthor Commented:
Thanks Guys, All i need is just want to disable internet access only to DC's. Also we don't have a proxy.
0
 
MaheshArchitectCommented:
then disable it on network level as suggested by shaun
0
 
Sekar ChinnakannuStaff EngineerAuthor Commented:
Is there any specific configuration we need to consider?
0
 
MaheshArchitectCommented:
u need to block outbound 80 & 443 from domain controller s towards extra net / internet
0
 
Shaun VermaakTechnical Specialist/DeveloperCommented:
Is there any specific configuration we need to consider?
You need to block all except private ranges, internet is more than just port 80/443
0
 
Sekar ChinnakannuStaff EngineerAuthor Commented:
Thanks
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.