Title: Message
Do you have a DMZ you can put the FTP server into? This would allow the low security "Outside" interface to reach the medium security DMZ interface and the DMZ interface could then validate usernames via LDAP (AD) to the high security "Inside" interface, right? 
-----Original Message-----
From: Noah Eiger [mailto:[EMAIL PROTECTED]
Sent: Friday, January 28, 2005 4:23 PM
To: [email protected]
Subject: RE: [ActiveDir] FTP Server In or Out

That sounds miserable. If I put it outside the firewall and out of the domain, does that mean that I’d need to setup individual local accounts on the ftp server? The idea was to set up certain folders that only a specific business client and certain in-house staff would have access to. We would have a folder for each business client and then only their in-house reps could have access.

 

What about some sort of one-way trust from the inside out? Is there some standard way (besides simply replicating the AD user directory to the local accounts) to do this?

 

(in the end it is simply not a lot of users – 50 or 60)

 

-- nme

 


From: joe [mailto:[EMAIL PROTECTED]
Sent: Friday, January 28, 2005 3:22 PM
To: [email protected]
Subject: RE: [ActiveDir] FTP Server In or Out

 

I don't think I would do it but it isn't entirely crazy. I assume you are reverse proxying 20/21 to the server?

 

The main thing I see wrong would be if someone knows one of your internal userids and assuming you have a lockout policy, she could do a D.O.S. on that user by sending bad passwords for that account. Alternatively, it is a vector in to try and hack passwords overall. Also if someone somehow compromises the machine with an FTP overflow exploit of some sort, they then have control of a machine inside your firewall and a part of your forest. At the very least they could possibly work out a way to enumerate user account information from the entire forest and such.

 

  joe

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Noah Eiger
Sent: Friday, January 28, 2005 6:11 PM
To: [email protected]
Subject: [ActiveDir] FTP Server In or Out

Hello:

 

Is it crazy to place a publicly accessible FTP server 1) inside the firewall and 2) on a domain? We want to control domain users’ access to certain directories as well as partners connecting from the outside. Only one directory would be available to the world and then as read only.

 

Thanks.

 

-- nme

 

Reply via email to