I could put all the IPSEC security on them i want but
Active directory needs port 445 open for
authentication.  This also happens to be the port for
file sharing.  Am i wrong?

However, you are correct in that I should put them in
a seperate OU.

Thanks


--- "Blair, James"
<[EMAIL PROTECTED]> wrote:

>  
> Sdgesa,
> 
> You could look at putting all the workstations on
> VLAN4 in a specific OU
> and roll a very restrictive IPSEC policy on them.
> Info and files you
> need are here:
> 
> http://www.analogx.com/contents/articles/ipsec.htm
> 
>  
> James     
> 
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On
> Behalf Of sdgesa gaeharth
> Sent: Friday, October 28, 2005 11:57 AM
> To: [email protected]
> Subject: RE: [ActiveDir] secure subnet; no sharing
> of files or internet
> access
> 
> Can you expand further? I am a little unsure on what
> you are trying to
> say. Do you mean to have two different
> domains(domain controllers)?
> 
> Checkpoint Firewall
> 
> --- Brian Desmond <[EMAIL PROTECTED]> wrote:
> 
> > Yes, there is a better solution.
> > 
> > Your firewall rules should look like this:
> > 
> > Src                 dest            service 
> > Secure Subnet       DC1 IP/32       AD Ports
> > Secure Subnet       DC2 IP/32       AD Ports
> > Secure Subnet       DC1 IP/32       UDP53
> > Secure Subnet       DC2 IP/32       UDP53
> > 
> > Etcetera. What brand of firewall is it anyway?
> > 
> > Thanks,
> > Brian Desmond
> > [EMAIL PROTECTED]
> >  
> > c - 312.731.3132
> >  
> >  
> > 
> > -----Original Message-----
> > From: [EMAIL PROTECTED]
> > [mailto:[EMAIL PROTECTED] On
> Behalf Of sdgesa 
> > gaeharth
> > Sent: Wednesday, October 26, 2005 9:30 AM
> > To: [email protected]
> > Subject: RE: [ActiveDir] secure subnet; no sharing
> of files or 
> > internet access
> > 
> > subnet ports are opened to the dmz, not to each
> other.
> > Am i going the rght way or is there a better
> solution?
> > 
> > thanks
> > 
> > --- Brian Desmond <[EMAIL PROTECTED]> wrote:
> > 
> > > Are you opening the ports between the subnets or
> between the subnet 
> > > and the dc host IPs? If you do the latter, the
> only place your users
> 
> > > could drop files and what have you is on the DCs
> and they'd need to 
> > > be domain admins or someone has to create a
> share on the DC that 
> > > they can access. You'll need to trust your
> admins or take away their
> 
> > > privs.
> > > 
> > > Your firewall rules should be permitting the
> > traffic
> > > from the secure subnet
> > > to host objects for the DCs not from the secure
> subnet to the subnet
> 
> > > with the DCs on them.
> > > 
> > > Thanks,
> > > Brian Desmond
> > > [EMAIL PROTECTED]
> > >  
> > > c - 312.731.3132
> > >  
> > >  
> > > 
> > > -----Original Message-----
> > > From: [EMAIL PROTECTED]
> > > [mailto:[EMAIL PROTECTED] On
> Behalf Of sdgesa 
> > > gaeharth
> > > Sent: Tuesday, October 25, 2005 9:31 PM
> > > To: [email protected]
> > > Subject: [ActiveDir] secure subnet; no sharing
> of files or internet 
> > > access
> > > 
> > > We have a single office with a single domain. 
> Our physical network 
> > > consists of a firewall with a set of managed
> switches behind it.  I 
> > > have partitioned
> > the
> > > network into multiple subnets using vlans.
> > > 
> > > Vlan 1:10.0.1.0/24: internal dmz(AD, DNS, DHCP)
> Vlan 2:10.0.2.0/24: 
> > > accounting Vlan 3:10.0.3.0/24: business
> development Vlan 
> > > 4:10.0.4.0/24: secured vlan
> > > 
> > > We need to restrict the Vlan 4, "secured vlan"
> so
> > no
> > > confidential files can get out. No Internet , no
> file sharing with 
> > > the other subnets, no printers, etc.
> > > 
> > > I opened dns, dhcp, and AD ports from Vlan 4 to
> > Vlan
> > > 1
> > > in order to facilitate authenticationa ganist
> the DC.
> > > 
> > > However, I am still worried that users could
> possible be able to get
> 
> > > files out.  For example, it seems port
> > > 445 is needed for authentication and file
> sharing.
> > > 
> > > Does anyone have any hints except the obvious
> one
> > of
> > > separating the subnet physically which is not an
> option?
> > > 
> > > thanks
> > > 
> > > 
> > >   
> > >           
> > > __________________________________
> > > Yahoo! Mail - PC Magazine Editors' Choice 2005
> http://mail.yahoo.com
> > > List info   : http://www.activedir.org/List.aspx
> > > List FAQ    :
> > http://www.activedir.org/ListFAQ.aspx
> > > List archive:
> > >
> >
>
http://www.mail-archive.com/activedir%40mail.activedir.org/
> > > 
> > > List info   : http://www.activedir.org/List.aspx
> > > List FAQ    :
> > http://www.activedir.org/ListFAQ.aspx
> > > List archive:
> > >
> >
>
http://www.mail-archive.com/activedir%40mail.activedir.org/
> > > 
> > 
> > 
> > 
> >             
> > __________________________________
> > Start your day with Yahoo! - Make it your home
> page!
> > 
> > http://www.yahoo.com/r/hs
> > List info   : http://www.activedir.org/List.aspx
> > List FAQ    :
> http://www.activedir.org/ListFAQ.aspx
> > List archive:
> >
>
http://www.mail-archive.com/activedir%40mail.activedir.org/
> > 
> > List info   : http://www.activedir.org/List.aspx
> > List FAQ    :
> http://www.activedir.org/ListFAQ.aspx
> > List archive:
> >
>
http://www.mail-archive.com/activedir%40mail.activedir.org/
> > 
> 
=== message truncated ===



                
__________________________________ 
Yahoo! FareChase: Search multiple travel sites in one click.
http://farechase.yahoo.com
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to