We are in the process of moving to a new 3rd party externally hosted spam filter. The new spam filter will allow our users to manage their own spam via a portal which they will log on to via a secure LDAP connection.
We have 3 x Domain Controllers.
In order to make the secure LDAP connection we would need to give one of our DC's a public IP address and then allow the spam filters IP addresses through the firewall and open port 636 (secure LDAP). I don't feel particularly comfortable with making one of our DC's public facing (even if it is locked down to specific IP's) and would like to look at alternatives.
My initial thought was to perhaps create a Read Only DC and use this instead. However, while researching this I came across the possibility of using AD Lightweight Directory Services.
I am not too familiar with AD LDS so I am not 100% sure if I can use it in this scenario. If I install AD LDS on server, will I be able to use this server for secure LDAP to the third party and will it keep replicating/updating from my production AD environment?