|
I agree with Phil – I think using an
ISA (or other reverse proxy solution) is the best way to go given your
constraints. Using a reverse proxy solution allows you
the following:
BTW - this scenario is becoming extremely
common. The next common addition you will see to this will likely be the use
of ADFS to provide an identity trust bridge between the internal forest and a
partner forest (or other identity system). Regards, Aric Bernard From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Phil Renouf I would look at putting the Sharepoint server on the internal network
and deploy an ISA server in the DMZ and use Web Publishing or Server Publishing
to get your external clients access to the site. If you want to open access from
the DMZ to your AD If you absolutely HAVE to then I would prefer to look at using IPSec
for communication between the Sharepoint box and your DC's. That leaves you only
needing the IPSec port open and not the very large number of ports to support
AD communication. Phil On 9/7/05, Jason B
<[EMAIL PROTECTED]>
wrote: Because this will be a sharepoint server for
clients. Regardless, that |
- RE: [ActiveDir] Which ports to open in the DMZ to communicat... Bernard, Aric
- RE: [ActiveDir] Which ports to open in the DMZ to commu... Al Mulnick
- Re: [ActiveDir] Which ports to open in the DMZ to c... Jason B
- RE: [ActiveDir] Which ports to open in the DMZ ... Brian Desmond
- Re: [ActiveDir] Which ports to open in the ... Jason B
- RE: [ActiveDir] Which ports to open in... Brian Desmond
- Re: [ActiveDir] Which ports to ope... Jason B
- RE: [ActiveDir] Which ports to... Brian Desmond
- Re: [ActiveDir] Which ports to open in... Phil Renouf
- Re: [ActiveDir] Which ports to ope... Jason B
- RE: [ActiveDir] Which ports to... Brian Desmond
