Networking Forums

Networking Forums > Computer Networking > Windows Networking > Project Domain - Firewall

Reply
Thread Tools Display Modes

Project Domain - Firewall

 
 
GAZ
Guest
Posts: n/a

 
      07-07-2006, 02:58 PM
Hi,

I am just wondering if anyone can offer some advice / experience on the
scenario below :-

We would like to create a "Project Domain" as a sub domain off our existing
domain. This is so that’s some of our engineers can add pc's to this project
domain for testing and carry out other tasks. We would like to then firewall
this domain off from our normal domain as a security measure. But still allow
domain replication etc. to filter through.

Is this just a case of putting a firewall between the existing network and
the project network and opening ports on the firewall to allow the domain
replication or is there another way we can create the Project Domain but
block this off from the normal network so no one can use there normal
credentials or gain access to the existing domain at all.

I hope I have explained this ok,

Thanks for your help,

Gaz
 
Reply With Quote
 
 
 
 
Phillip Windell
Guest
Posts: n/a

 
      07-07-2006, 05:38 PM
"GAZ" <(E-Mail Removed)> wrote in message
news:BACE3F07-B564-4F14-BBCB-(E-Mail Removed)...
> We would like to create a "Project Domain" as a sub domain off our
> existing
> domain. This is so that's some of our engineers can add pc's to this
> project
> domain for testing and carry out other tasks. We would like to then
> firewall
> this domain off from our normal domain as a security measure. But still
> allow
> domain replication etc. to filter through.


90% of the things you would want to block are the very same things you have
to allow for AD to work. So a "firewall" becomes almost pointless.

BTW - you only need a LAN router running ACLs,...you do not want a
"traditional firewall" which is a NAT box,...because you don't want NAT.

> Is this just a case of putting a firewall between the existing network and
> the project network and opening ports on the firewall to allow the domain
> replication or is there another way we can create the Project Domain but
> block this off from the normal network so no one can use there normal
> credentials or gain access to the existing domain at all.


Just create a separate Lab Domain that has nothing to do with the regular
Domain. That's what I have here. You can have it on a separate IP Segment
and use ACLs on the router between them all you want since neither side
would depend on the other.

--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com


 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
08 domain firewall mark Windows Networking 2 10-19-2008 10:58 PM
Server 2008 with Hyper-V - domain controller - Firewall GUI's show firewall ON, but netsh reports firewall OFF Bruce Sanderson Windows Networking 7 10-07-2008 09:57 AM
Windows Firewall Domain Policy Mark Windows Networking 12 11-08-2007 04:04 PM
Domain Trust across firewall Lonnie Windows Networking 0 04-02-2007 06:12 PM
joining a domain through firewall J Duff Windows Networking 3 10-22-2005 02:34 PM



1 2 3 4 5 6 7 8 9 10 11