Question
April 7, 2008 at 02:03 PM
robo_dev

Firewall Rules: Keep AD out of the DMZ?

by robo_dev . Updated 18 years, 4 months ago

Looking at several Windows boxes in a DMZ, and the firewall rules let them talk back to DC using the usual AD ports.

If a Windows host in a DMZ were compromised, couldn’t this lead to further compromise since these boxes interact with Active Directory?

Or am I just being too paranoid?

My initial thought was to have these boxes not be part of a domain of any sort and disallow any Microsoft protocols at all. My thought is that port 53 or (obviously port 80) might be attack vectors.

This discussion is locked

All Comments