OK. I assumed you have more than one domain controller (you should), it's
not required, though.

I don't know too much about checkpoint, but, I think the terminology below
is what they use, if not, it's easily translated.

You should have a couple of host groups here:

Host-group DCs should contain the IP addresses of all your domain
controllers

Host-group Clients should contain all the client subnets

Service-group AD should contain all the ports that AD uses, DNS, LDAP,
RPC/SMB, etc. You can then have a rule permitting this traffic from the
clients to the DCs. Deny any other traffic from the clients to the DCs. 

Thanks,
Brian Desmond
[EMAIL PROTECTED]
 
c - 312.731.3132
 
 

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of sdgesa gaeharth
Sent: Thursday, October 27, 2005 9:57 PM
To: [email protected]
Subject: RE: [ActiveDir] secure subnet; no sharing of files or internet
access

Can you expand further? I am a little unsure on what
you are trying to say. Do you mean to have two 
different domains(domain controllers)?

Checkpoint Firewall

--- Brian Desmond <[EMAIL PROTECTED]> wrote:

> Yes, there is a better solution.
> 
> Your firewall rules should look like this:
> 
> Src                   dest            service 
> Secure Subnet DC1 IP/32       AD Ports
> Secure Subnet DC2 IP/32       AD Ports
> Secure Subnet DC1 IP/32       UDP53
> Secure Subnet DC2 IP/32       UDP53
> 
> Etcetera. What brand of firewall is it anyway?
> 
> Thanks,
> Brian Desmond
> [EMAIL PROTECTED]
>  
> c - 312.731.3132
>  
>  
> 
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On
> Behalf Of sdgesa gaeharth
> Sent: Wednesday, October 26, 2005 9:30 AM
> To: [email protected]
> Subject: RE: [ActiveDir] secure subnet; no sharing
> of files or internet
> access
> 
> subnet ports are opened to the dmz, not to each
> other.
> Am i going the rght way or is there a better
> solution?
> 
> thanks
> 
> --- Brian Desmond <[EMAIL PROTECTED]> wrote:
> 
> > Are you opening the ports between the subnets or
> > between the subnet and the
> > dc host IPs? If you do the latter, the only place
> > your users could drop
> > files and what have you is on the DCs and they'd
> > need to be domain admins or
> > someone has to create a share on the DC that they
> > can access. You'll need to
> > trust your admins or take away their privs.
> > 
> > Your firewall rules should be permitting the
> traffic
> > from the secure subnet
> > to host objects for the DCs not from the secure
> > subnet to the subnet with
> > the DCs on them. 
> > 
> > Thanks,
> > Brian Desmond
> > [EMAIL PROTECTED]
> >  
> > c - 312.731.3132
> >  
> >  
> > 
> > -----Original Message-----
> > From: [EMAIL PROTECTED]
> > [mailto:[EMAIL PROTECTED] On
> > Behalf Of sdgesa gaeharth
> > Sent: Tuesday, October 25, 2005 9:31 PM
> > To: [email protected]
> > Subject: [ActiveDir] secure subnet; no sharing of
> > files or internet access
> > 
> > We have a single office with a single domain.  Our
> > physical network consists of a firewall with a set
> > of
> > managed switches behind it.  I have partitioned
> the
> > network into multiple subnets using vlans.
> > 
> > Vlan 1:10.0.1.0/24: internal dmz(AD, DNS, DHCP)
> > Vlan 2:10.0.2.0/24: accounting
> > Vlan 3:10.0.3.0/24: business development
> > Vlan 4:10.0.4.0/24: secured vlan
> > 
> > We need to restrict the Vlan 4, "secured vlan" so
> no
> > confidential files can get out. No Internet , no
> > file
> > sharing with the other subnets, no printers, etc.
> > 
> > I opened dns, dhcp, and AD ports from Vlan 4 to
> Vlan
> > 1
> > in order to facilitate authenticationa ganist the
> > DC.
> > 
> > However, I am still worried that users could
> > possible
> > be able to get files out.  For example, it seems
> > port
> > 445 is needed for authentication and file sharing.
> > 
> > Does anyone have any hints except the obvious one
> of
> > separating the subnet physically which is not an
> > option?
> > 
> > thanks
> > 
> > 
> >     
> >             
> > __________________________________ 
> > Yahoo! Mail - PC Magazine Editors' Choice 2005 
> > http://mail.yahoo.com
> > List info   : http://www.activedir.org/List.aspx
> > List FAQ    :
> http://www.activedir.org/ListFAQ.aspx
> > List archive:
> >
>
http://www.mail-archive.com/activedir%40mail.activedir.org/
> > 
> > List info   : http://www.activedir.org/List.aspx
> > List FAQ    :
> http://www.activedir.org/ListFAQ.aspx
> > List archive:
> >
>
http://www.mail-archive.com/activedir%40mail.activedir.org/
> > 
> 
> 
> 
>               
> __________________________________ 
> Start your day with Yahoo! - Make it your home page!
> 
> http://www.yahoo.com/r/hs
> List info   : http://www.activedir.org/List.aspx
> List FAQ    : http://www.activedir.org/ListFAQ.aspx
> List archive:
>
http://www.mail-archive.com/activedir%40mail.activedir.org/
> 
> List info   : http://www.activedir.org/List.aspx
> List FAQ    : http://www.activedir.org/ListFAQ.aspx
> List archive:
>
http://www.mail-archive.com/activedir%40mail.activedir.org/
> 



                
__________________________________ 
Yahoo! FareChase: Search multiple travel sites in one click.
http://farechase.yahoo.com
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to