OK. I assumed you have more than one domain controller (you should), it's not required, though.
I don't know too much about checkpoint, but, I think the terminology below is what they use, if not, it's easily translated. You should have a couple of host groups here: Host-group DCs should contain the IP addresses of all your domain controllers Host-group Clients should contain all the client subnets Service-group AD should contain all the ports that AD uses, DNS, LDAP, RPC/SMB, etc. You can then have a rule permitting this traffic from the clients to the DCs. Deny any other traffic from the clients to the DCs. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of sdgesa gaeharth Sent: Thursday, October 27, 2005 9:57 PM To: [email protected] Subject: RE: [ActiveDir] secure subnet; no sharing of files or internet access Can you expand further? I am a little unsure on what you are trying to say. Do you mean to have two different domains(domain controllers)? Checkpoint Firewall --- Brian Desmond <[EMAIL PROTECTED]> wrote: > Yes, there is a better solution. > > Your firewall rules should look like this: > > Src dest service > Secure Subnet DC1 IP/32 AD Ports > Secure Subnet DC2 IP/32 AD Ports > Secure Subnet DC1 IP/32 UDP53 > Secure Subnet DC2 IP/32 UDP53 > > Etcetera. What brand of firewall is it anyway? > > Thanks, > Brian Desmond > [EMAIL PROTECTED] > > c - 312.731.3132 > > > > -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On > Behalf Of sdgesa gaeharth > Sent: Wednesday, October 26, 2005 9:30 AM > To: [email protected] > Subject: RE: [ActiveDir] secure subnet; no sharing > of files or internet > access > > subnet ports are opened to the dmz, not to each > other. > Am i going the rght way or is there a better > solution? > > thanks > > --- Brian Desmond <[EMAIL PROTECTED]> wrote: > > > Are you opening the ports between the subnets or > > between the subnet and the > > dc host IPs? If you do the latter, the only place > > your users could drop > > files and what have you is on the DCs and they'd > > need to be domain admins or > > someone has to create a share on the DC that they > > can access. You'll need to > > trust your admins or take away their privs. > > > > Your firewall rules should be permitting the > traffic > > from the secure subnet > > to host objects for the DCs not from the secure > > subnet to the subnet with > > the DCs on them. > > > > Thanks, > > Brian Desmond > > [EMAIL PROTECTED] > > > > c - 312.731.3132 > > > > > > > > -----Original Message----- > > From: [EMAIL PROTECTED] > > [mailto:[EMAIL PROTECTED] On > > Behalf Of sdgesa gaeharth > > Sent: Tuesday, October 25, 2005 9:31 PM > > To: [email protected] > > Subject: [ActiveDir] secure subnet; no sharing of > > files or internet access > > > > We have a single office with a single domain. Our > > physical network consists of a firewall with a set > > of > > managed switches behind it. I have partitioned > the > > network into multiple subnets using vlans. > > > > Vlan 1:10.0.1.0/24: internal dmz(AD, DNS, DHCP) > > Vlan 2:10.0.2.0/24: accounting > > Vlan 3:10.0.3.0/24: business development > > Vlan 4:10.0.4.0/24: secured vlan > > > > We need to restrict the Vlan 4, "secured vlan" so > no > > confidential files can get out. No Internet , no > > file > > sharing with the other subnets, no printers, etc. > > > > I opened dns, dhcp, and AD ports from Vlan 4 to > Vlan > > 1 > > in order to facilitate authenticationa ganist the > > DC. > > > > However, I am still worried that users could > > possible > > be able to get files out. For example, it seems > > port > > 445 is needed for authentication and file sharing. > > > > Does anyone have any hints except the obvious one > of > > separating the subnet physically which is not an > > option? > > > > thanks > > > > > > > > > > __________________________________ > > Yahoo! Mail - PC Magazine Editors' Choice 2005 > > http://mail.yahoo.com > > List info : http://www.activedir.org/List.aspx > > List FAQ : > http://www.activedir.org/ListFAQ.aspx > > List archive: > > > http://www.mail-archive.com/activedir%40mail.activedir.org/ > > > > List info : http://www.activedir.org/List.aspx > > List FAQ : > http://www.activedir.org/ListFAQ.aspx > > List archive: > > > http://www.mail-archive.com/activedir%40mail.activedir.org/ > > > > > > > __________________________________ > Start your day with Yahoo! - Make it your home page! > > http://www.yahoo.com/r/hs > List info : http://www.activedir.org/List.aspx > List FAQ : http://www.activedir.org/ListFAQ.aspx > List archive: > http://www.mail-archive.com/activedir%40mail.activedir.org/ > > List info : http://www.activedir.org/List.aspx > List FAQ : http://www.activedir.org/ListFAQ.aspx > List archive: > http://www.mail-archive.com/activedir%40mail.activedir.org/ > __________________________________ Yahoo! FareChase: Search multiple travel sites in one click. http://farechase.yahoo.com List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
