Child Separated by Firewall

L

libadmin

I have successfully set up a child domain that is separated by a PIX
firewall. Everything is working perfect.. Except......

the child domain server has a single NIC. The address of that server is
not seen by the parent nor is it accessible. I do have a Parent Local
address that has a static translation through the firewall that is
accessible to the Parent Domain controllers. However, when i modify the
NS record and add the "other" address it sticks only for a short period
and then disappears. When the IP is there I can successfully access the
Child Domain server using Ping and NSLOOKUP.. When it is not the server
searches for the remote address which is not accessible. So, question
is how do I ensure the remote or Parent Domain servers are always fed
the local (to them) address that I have translated through the PIX? I
have tried hosts files with some success.. Do I need to add NIC and
assign the address to it (but leave it disconnected?) or can I force
the NS record to remain with the dual adderesses?

\bob
 
R

Ryan Hanisco

Hi Bob,

This is a little bit of a messy problem. I would suggest that you
establish an IPSec or GRE tunnel between your PIXs with your internal
router directing traffic at the tunnel interface. This way, the DC's
will be in routable subnets. In this case, you give the DCs the IP
address of the local subnet and let your PIXs/routers do their job.

I would strongly suggest that you do all your replication through a VPN
tunnel like this. If you have additional security concerns, you would
also want an ACL on the tunnel to allow only traffic between the
specific hosts of the DCs.

If you are looking at this as a connection to a DMZ, then you might want
to look at the article below. This is messy and a tunnel will be a
better solution. It's much better to do a tunnel than to open all of
those ports, though some security scenarios require that even over the
tunnel.

If you need help, let me know.

http://www.microsoft.com/technet/pr.../activedirectory/deploy/confeat/adrepfir.mspx

Ryan Hanisco
Sr. Project Lead
FlagShip Integration Services
(e-mail address removed)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top