Link to home
Start Free TrialLog in
Avatar of sysnimda
sysnimda

asked on

DMZ and syncing AD

What’s the best and secure way to setup a web server within a DMZ? A couple of simple external sites and sql server. Should I put a DC RODC inside DMZ or just open up ports to sync AD? or should I not have it connected to AD?
Avatar of Shabarinath TR
Shabarinath TR
Flag of India image

Hello Sysnimda,

DMZ strategy needs to be really looked at from the security perspective and the requirements.

There are multiple options available which are commonly used.

  1. No Domain - Easiest solution. If the number of machines are less in DMZ - its an overhead to keep a dedicated domain or domain controller in DMZ Segment. 
  2. Dedicated Isolated Forest - If more machines needs to be managed in DMZ segment, Its good to have an isolated domain only for DMZ segment which doesn't talk with internal network.
  3. Extending production domain to DMZ - I dont recommend this as its more vulnerable. If this needs to be considered, Look for the possibility for placing RODCs in this segment.

Good luck
Shaba

Avatar of sysnimda
sysnimda

ASKER

Great info Shaba! What about a SQL server I currently have internally which is tied to IIS/webserver and will be put in DMZ? Should I move entire DB into DMZ? One more thing...should I have a WAF in front of DMZ? Thank you!
ASKER CERTIFIED SOLUTION
Avatar of Shabarinath TR
Shabarinath TR
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Awesome! Detailed information and fast response.