active directory over firewalls

  • Thread starter Thread starter allenj
  • Start date Start date
A

allenj

I have an environment where I need to have DC's in seperate "burbs"
segmented off from the rest of the network by firewalls. We are
investigating using IPSec to make DC to DC communication operate. I
have read several posts and articles on this, but cannot determine
whether I need to build IPSec between 2 DC's (one in burb and one in
production) or whether I need to build IPSec between ALL DC's??? It
appears in testing that it must be all DC's, or we start getting 1864
errors in event logs of DC's and when researching by doing DCDiags, I
see that I am getting REPLICATION RECEIVED LATENCY WARNINGS related to
the DC's in the "burb" which do not have connectivity built in via
IPSec.

any help would be appreciated

thanks
 
Hello,
Here is a few good articles as well to start with, Hope it helps.
Active Directory in Networks Segmented by Firewalls:
http://www.microsoft.com/downloads/...46-43f0-4caf-9767-a9166368434e&DisplayLang=en

Restricting Active Directory Replication Traffic to a Specific Port:
http://support.microsoft.com/default.aspx?scid=kb;en-us;224196

How to Configure a Global Catalog Server to Use a Specific Port When
Servicing MAPI Clients:
http://support.microsoft.com/default.aspx?scid=kb;en-us;298369


How to Restrict FRS Replication Traffic to a Specific Static Port:
http://support.microsoft.com/default.aspx?scid=kb;en-us;319553

How to Configure a Firewall for Domains and Trusts:
http://support.microsoft.com/defaul...port/kb/articles/q179/4/42.asp&NoWebContent=1
 
If I'm not mistaken, if you require your dc's to perform IPSec and you
aren't multi-homed ALL (Clients too) communications will need to be IPSec.
Multi-homed is not recommended for DC's.

--
Paul Bergson
MCT, MCSE, MCSA, Security+, BS CSi
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
 
Back
Top