Book now with code EOY2025
sprkymrk wrote: The Astaro Security Gateway 120 is a solid product
dynamik wrote: , but if I only allow http and ftp from the outside and then only let the AD traffic reach the DCs, I feel that's more than secure enough for our needs.
sprkymrk wrote: dynamik wrote: , but if I only allow http and ftp from the outside and then only let the AD traffic reach the DCs, I feel that's more than secure enough for our needs. Seriously, use IPSec to allow the AD traffic from your server in the DMZ to the DC. Otherwise you still need to open 1024-65535 just for RPC traffic. You could also create a limited RPC policy by editing the registry on your DC's, but still your best bet is IPSec.Active Directory Replication over Firewalls
JDMurray wrote: sprkymrk wrote: The Astaro Security Gateway 120 is a solid product Mark, you've been listening to Leo Laporte's Security Now! podcasts, haven't you?
Use code EOY2025 to receive $250 off your 2025 certification boot camp!