What Brian was getting at was that it would be best to only open those ports to the DC's specifically and not a whole subnet.
 
Phil

 
On 10/26/05, sdgesa gaeharth <[EMAIL PROTECTED]> wrote:
subnet ports are opened to the dmz, not to each other.
Am i going the rght way or is there a better solution?

thanks

--- Brian Desmond <[EMAIL PROTECTED]> wrote:

> Are you opening the ports between the subnets or
> between the subnet and the
> dc host IPs? If you do the latter, the only place
> your users could drop
> files and what have you is on the DCs and they'd
> need to be domain admins or
> someone has to create a share on the DC that they
> can access. You'll need to
> trust your admins or take away their privs.
>
> Your firewall rules should be permitting the traffic
> from the secure subnet
> to host objects for the DCs not from the secure
> subnet to the subnet with
> the DCs on them.
>
> Thanks,
> Brian Desmond
> [EMAIL PROTECTED]
>
> c - 312.731.3132
>
>
>
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto: [EMAIL PROTECTED]] On
> Behalf Of sdgesa gaeharth
> Sent: Tuesday, October 25, 2005 9:31 PM
> To: [email protected]
> Subject: [ActiveDir] secure subnet; no sharing of
> files or internet access
>
> We have a single office with a single domain.  Our
> physical network consists of a firewall with a set
> of
> managed switches behind it.  I have partitioned the
> network into multiple subnets using vlans.
>
> Vlan 1:10.0.1.0/24: internal dmz(AD, DNS, DHCP)
> Vlan 2:10.0.2.0/24: accounting
> Vlan 3:10.0.3.0/24: business development
> Vlan 4:10.0.4.0/24: secured vlan
>
> We need to restrict the Vlan 4, "secured vlan" so no
> confidential files can get out. No Internet , no
> file
> sharing with the other subnets, no printers, etc.
>
> I opened dns, dhcp, and AD ports from Vlan 4 to Vlan
> 1
> in order to facilitate authenticationa ganist the
> DC.
>
> However, I am still worried that users could
> possible
> be able to get files out.  For example, it seems
> port
> 445 is needed for authentication and file sharing.
>
> Does anyone have any hints except the obvious one of
> separating the subnet physically which is not an
> option?
>
> thanks
>
>
>
>
> __________________________________
> Yahoo! Mail - PC Magazine Editors' Choice 2005
> http://mail.yahoo.com
> List info   : http://www.activedir.org/List.aspx
> List FAQ    : http://www.activedir.org/ListFAQ.aspx
> List archive:
>
http://www.mail-archive.com/activedir%40mail.activedir.org/
>
> List info   : http://www.activedir.org/List.aspx
> List FAQ    : http://www.activedir.org/ListFAQ.aspx
> List archive:
>
http://www.mail-archive.com/activedir%40mail.activedir.org/
>




__________________________________
Start your day with Yahoo! - Make it your home page!
http://www.yahoo.com/r/hs
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to