I could put all the IPSEC security on them i want but Active directory needs port 445 open for authentication. This also happens to be the port for file sharing. Am i wrong?
However, you are correct in that I should put them in a seperate OU. Thanks --- "Blair, James" <[EMAIL PROTECTED]> wrote: > > Sdgesa, > > You could look at putting all the workstations on > VLAN4 in a specific OU > and roll a very restrictive IPSEC policy on them. > Info and files you > need are here: > > http://www.analogx.com/contents/articles/ipsec.htm > > > James > > -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On > Behalf Of sdgesa gaeharth > Sent: Friday, October 28, 2005 11:57 AM > To: [email protected] > Subject: RE: [ActiveDir] secure subnet; no sharing > of files or internet > access > > Can you expand further? I am a little unsure on what > you are trying to > say. Do you mean to have two different > domains(domain controllers)? > > Checkpoint Firewall > > --- Brian Desmond <[EMAIL PROTECTED]> wrote: > > > Yes, there is a better solution. > > > > Your firewall rules should look like this: > > > > Src dest service > > Secure Subnet DC1 IP/32 AD Ports > > Secure Subnet DC2 IP/32 AD Ports > > Secure Subnet DC1 IP/32 UDP53 > > Secure Subnet DC2 IP/32 UDP53 > > > > Etcetera. What brand of firewall is it anyway? > > > > Thanks, > > Brian Desmond > > [EMAIL PROTECTED] > > > > c - 312.731.3132 > > > > > > > > -----Original Message----- > > From: [EMAIL PROTECTED] > > [mailto:[EMAIL PROTECTED] On > Behalf Of sdgesa > > gaeharth > > Sent: Wednesday, October 26, 2005 9:30 AM > > To: [email protected] > > Subject: RE: [ActiveDir] secure subnet; no sharing > of files or > > internet access > > > > subnet ports are opened to the dmz, not to each > other. > > Am i going the rght way or is there a better > solution? > > > > thanks > > > > --- Brian Desmond <[EMAIL PROTECTED]> wrote: > > > > > Are you opening the ports between the subnets or > between the subnet > > > and the dc host IPs? If you do the latter, the > only place your users > > > > could drop files and what have you is on the DCs > and they'd need to > > > be domain admins or someone has to create a > share on the DC that > > > they can access. You'll need to trust your > admins or take away their > > > > privs. > > > > > > Your firewall rules should be permitting the > > traffic > > > from the secure subnet > > > to host objects for the DCs not from the secure > subnet to the subnet > > > > with the DCs on them. > > > > > > Thanks, > > > Brian Desmond > > > [EMAIL PROTECTED] > > > > > > c - 312.731.3132 > > > > > > > > > > > > -----Original Message----- > > > From: [EMAIL PROTECTED] > > > [mailto:[EMAIL PROTECTED] On > Behalf Of sdgesa > > > gaeharth > > > Sent: Tuesday, October 25, 2005 9:31 PM > > > To: [email protected] > > > Subject: [ActiveDir] secure subnet; no sharing > of files or internet > > > access > > > > > > We have a single office with a single domain. > Our physical network > > > consists of a firewall with a set of managed > switches behind it. I > > > have partitioned > > the > > > network into multiple subnets using vlans. > > > > > > Vlan 1:10.0.1.0/24: internal dmz(AD, DNS, DHCP) > Vlan 2:10.0.2.0/24: > > > accounting Vlan 3:10.0.3.0/24: business > development Vlan > > > 4:10.0.4.0/24: secured vlan > > > > > > We need to restrict the Vlan 4, "secured vlan" > so > > no > > > confidential files can get out. No Internet , no > file sharing with > > > the other subnets, no printers, etc. > > > > > > I opened dns, dhcp, and AD ports from Vlan 4 to > > Vlan > > > 1 > > > in order to facilitate authenticationa ganist > the DC. > > > > > > However, I am still worried that users could > possible be able to get > > > > files out. For example, it seems port > > > 445 is needed for authentication and file > sharing. > > > > > > Does anyone have any hints except the obvious > one > > of > > > separating the subnet physically which is not an > option? > > > > > > thanks > > > > > > > > > > > > > > > __________________________________ > > > Yahoo! Mail - PC Magazine Editors' Choice 2005 > http://mail.yahoo.com > > > List info : http://www.activedir.org/List.aspx > > > List FAQ : > > http://www.activedir.org/ListFAQ.aspx > > > List archive: > > > > > > http://www.mail-archive.com/activedir%40mail.activedir.org/ > > > > > > List info : http://www.activedir.org/List.aspx > > > List FAQ : > > http://www.activedir.org/ListFAQ.aspx > > > List archive: > > > > > > http://www.mail-archive.com/activedir%40mail.activedir.org/ > > > > > > > > > > > > > __________________________________ > > Start your day with Yahoo! - Make it your home > page! > > > > http://www.yahoo.com/r/hs > > List info : http://www.activedir.org/List.aspx > > List FAQ : > http://www.activedir.org/ListFAQ.aspx > > List archive: > > > http://www.mail-archive.com/activedir%40mail.activedir.org/ > > > > List info : http://www.activedir.org/List.aspx > > List FAQ : > http://www.activedir.org/ListFAQ.aspx > > List archive: > > > http://www.mail-archive.com/activedir%40mail.activedir.org/ > > > === message truncated === __________________________________ Yahoo! FareChase: Search multiple travel sites in one click. http://farechase.yahoo.com List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
