using domain controller in front of a firewall router

Edward

Distinguished
Apr 22, 2004
115
0
18,680
Archived from groups: microsoft.public.win2000.general,microsoft.public.win2000.networking,microsoft.public.win2000.setup (More info?)

I have a Domain Controller with a public IP address and a PC behind a
firewall router with a private IP address.

How can I log on to the Domain Controller from behind the firewall router?

Must I take the Domain Controller behind the firewall and give it a private
IP before the rest of the network behind the firewall can use the domain
controller.

Thanks.

---
Ed
 
Archived from groups: microsoft.public.win2000.general,microsoft.public.win2000.networking,microsoft.public.win2000.setup (More info?)

The first question that pops into my mind is ... WHY do you have a domain
controller exposed to the public? That is an incredibly risky
configuration.

But anyway, yes, you will need to have the DC in the same address segment as
the rest of the network for clients to be able to log onto it. Depending on
the firewall/router hardware you might be able to route traffic through it
to the DC and back but if you do then what's the point of having it?

--
Richard G. Harper [MVP Shell/User] rgharper@gmail.com
* PLEASE post all messages and replies in the newsgroups
* for the benefit of all. Private mail is usually not replied to.
* My website, such as it is ... http://rgharper.mvps.org/
* HELP us help YOU ... http://www.dts-l.org/goodpost.htm


"Edward" <hsmmsc@hotmail.com> wrote in message
news:us4WACJqFHA.3204@TK2MSFTNGP10.phx.gbl...
>I have a Domain Controller with a public IP address and a PC behind a
> firewall router with a private IP address.
>
> How can I log on to the Domain Controller from behind the firewall router?
>
> Must I take the Domain Controller behind the firewall and give it a
> private
> IP before the rest of the network behind the firewall can use the domain
> controller.
>
> Thanks.
>
> ---
> Ed
>
>
>
 
Archived from groups: microsoft.public.win2000.general,microsoft.public.win2000.networking,microsoft.public.win2000.setup (More info?)

Thanks Richard.

I am trying to explore how best to deploy my network because I try to limit
the number of machines that I need to power on 24/7. My ISP forward all my
e-mail to a fixed public IP and I want also to have webmail running for MS
exchange. Hence, I am trying to explore the options possible.

Any suggestion welcome.

Regards

---
Ed


"Richard G. Harper" <rgharper@email.com> wrote in message
news:eAezjKJqFHA.1028@TK2MSFTNGP09.phx.gbl...
> The first question that pops into my mind is ... WHY do you have a domain
> controller exposed to the public? That is an incredibly risky
> configuration.
>
> But anyway, yes, you will need to have the DC in the same address segment
> as the rest of the network for clients to be able to log onto it.
> Depending on the firewall/router hardware you might be able to route
> traffic through it to the DC and back but if you do then what's the point
> of having it?
>
> --
> Richard G. Harper [MVP Shell/User] rgharper@gmail.com
> * PLEASE post all messages and replies in the newsgroups
> * for the benefit of all. Private mail is usually not replied to.
> * My website, such as it is ... http://rgharper.mvps.org/
> * HELP us help YOU ... http://www.dts-l.org/goodpost.htm
>
>
> "Edward" <hsmmsc@hotmail.com> wrote in message
> news:us4WACJqFHA.3204@TK2MSFTNGP10.phx.gbl...
>>I have a Domain Controller with a public IP address and a PC behind a
>> firewall router with a private IP address.
>>
>> How can I log on to the Domain Controller from behind the firewall
>> router?
>>
>> Must I take the Domain Controller behind the firewall and give it a
>> private
>> IP before the rest of the network behind the firewall can use the domain
>> controller.
>>
>> Thanks.
>>
>> ---
>> Ed
>>
>>
>>
>
>
 
Archived from groups: microsoft.public.win2000.general,microsoft.public.win2000.networking,microsoft.public.win2000.setup (More info?)

Sorry, I don't know much about mail servers and configuration but I'd
suggest that you consider routing and forwarding the incoming mail - the
router gets it at public address xx.yy.zz.aa and forwards it to the mail
server inside the firewall, ditto outgoing mail gets routed from the
internal mail server to the external public address.

You should probably also consider the possibility that if that server has
been sitting and facing the public for any length of time, it may not be
'your' server any longer. Someone may have hacked it and I'd be very
worried about that possibility especially with a DC.

--
Richard G. Harper [MVP Shell/User] rgharper@gmail.com
* PLEASE post all messages and replies in the newsgroups
* for the benefit of all. Private mail is usually not replied to.
* My website, such as it is ... http://rgharper.mvps.org/
* HELP us help YOU ... http://www.dts-l.org/goodpost.htm


"Edward" <hsmmsc@hotmail.com> wrote in message
news:ur2znVJqFHA.2364@tk2msftngp13.phx.gbl...
> Thanks Richard.
>
> I am trying to explore how best to deploy my network because I try to
> limit the number of machines that I need to power on 24/7. My ISP forward
> all my e-mail to a fixed public IP and I want also to have webmail running
> for MS exchange. Hence, I am trying to explore the options possible.
>
> Any suggestion welcome.
>
> Regards
>
> ---
> Ed
>
>
> "Richard G. Harper" <rgharper@email.com> wrote in message
> news:eAezjKJqFHA.1028@TK2MSFTNGP09.phx.gbl...
>> The first question that pops into my mind is ... WHY do you have a domain
>> controller exposed to the public? That is an incredibly risky
>> configuration.
>>
>> But anyway, yes, you will need to have the DC in the same address segment
>> as the rest of the network for clients to be able to log onto it.
>> Depending on the firewall/router hardware you might be able to route
>> traffic through it to the DC and back but if you do then what's the point
>> of having it?
>>
>> --
>> Richard G. Harper [MVP Shell/User] rgharper@gmail.com
>> * PLEASE post all messages and replies in the newsgroups
>> * for the benefit of all. Private mail is usually not replied to.
>> * My website, such as it is ... http://rgharper.mvps.org/
>> * HELP us help YOU ... http://www.dts-l.org/goodpost.htm
>>
>>
>> "Edward" <hsmmsc@hotmail.com> wrote in message
>> news:us4WACJqFHA.3204@TK2MSFTNGP10.phx.gbl...
>>>I have a Domain Controller with a public IP address and a PC behind a
>>> firewall router with a private IP address.
>>>
>>> How can I log on to the Domain Controller from behind the firewall
>>> router?
>>>
>>> Must I take the Domain Controller behind the firewall and give it a
>>> private
>>> IP before the rest of the network behind the firewall can use the domain
>>> controller.
>>>
>>> Thanks.
>>>
>>> ---
>>> Ed
>>>
>>>
>>>
>>
>>
>
>
 
Archived from groups: microsoft.public.win2000.general,microsoft.public.win2000.networking,microsoft.public.win2000.setup (More info?)

Thanks for your advise Richard.

"Richard G. Harper" <rgharper@email.com> wrote in message
news:%23u3PGmJqFHA.2960@TK2MSFTNGP10.phx.gbl...
> Sorry, I don't know much about mail servers and configuration but I'd
> suggest that you consider routing and forwarding the incoming mail - the
> router gets it at public address xx.yy.zz.aa and forwards it to the mail
> server inside the firewall, ditto outgoing mail gets routed from the
> internal mail server to the external public address.
>
> You should probably also consider the possibility that if that server has
> been sitting and facing the public for any length of time, it may not be
> 'your' server any longer. Someone may have hacked it and I'd be very
> worried about that possibility especially with a DC.
>
> --
> Richard G. Harper [MVP Shell/User] rgharper@gmail.com
> * PLEASE post all messages and replies in the newsgroups
> * for the benefit of all. Private mail is usually not replied to.
> * My website, such as it is ... http://rgharper.mvps.org/
> * HELP us help YOU ... http://www.dts-l.org/goodpost.htm
>
>
> "Edward" <hsmmsc@hotmail.com> wrote in message
> news:ur2znVJqFHA.2364@tk2msftngp13.phx.gbl...
>> Thanks Richard.
>>
>> I am trying to explore how best to deploy my network because I try to
>> limit the number of machines that I need to power on 24/7. My ISP forward
>> all my e-mail to a fixed public IP and I want also to have webmail
>> running for MS exchange. Hence, I am trying to explore the options
>> possible.
>>
>> Any suggestion welcome.
>>
>> Regards
>>
>> ---
>> Ed
>>
>>
>> "Richard G. Harper" <rgharper@email.com> wrote in message
>> news:eAezjKJqFHA.1028@TK2MSFTNGP09.phx.gbl...
>>> The first question that pops into my mind is ... WHY do you have a
>>> domain controller exposed to the public? That is an incredibly risky
>>> configuration.
>>>
>>> But anyway, yes, you will need to have the DC in the same address
>>> segment as the rest of the network for clients to be able to log onto
>>> it. Depending on the firewall/router hardware you might be able to route
>>> traffic through it to the DC and back but if you do then what's the
>>> point of having it?
>>>
>>> --
>>> Richard G. Harper [MVP Shell/User] rgharper@gmail.com
>>> * PLEASE post all messages and replies in the newsgroups
>>> * for the benefit of all. Private mail is usually not replied to.
>>> * My website, such as it is ... http://rgharper.mvps.org/
>>> * HELP us help YOU ... http://www.dts-l.org/goodpost.htm
>>>
>>>
>>> "Edward" <hsmmsc@hotmail.com> wrote in message
>>> news:us4WACJqFHA.3204@TK2MSFTNGP10.phx.gbl...
>>>>I have a Domain Controller with a public IP address and a PC behind a
>>>> firewall router with a private IP address.
>>>>
>>>> How can I log on to the Domain Controller from behind the firewall
>>>> router?
>>>>
>>>> Must I take the Domain Controller behind the firewall and give it a
>>>> private
>>>> IP before the rest of the network behind the firewall can use the
>>>> domain
>>>> controller.
>>>>
>>>> Thanks.
>>>>
>>>> ---
>>>> Ed
>>>>
>>>>
>>>>
>>>
>>>
>>
>>
>
>
 
Archived from groups: microsoft.public.win2000.general,microsoft.public.win2000.networking,microsoft.public.win2000.setup (More info?)

You're welcome.

--
Richard G. Harper [MVP Shell/User] rgharper@gmail.com
* PLEASE post all messages and replies in the newsgroups
* for the benefit of all. Private mail is usually not replied to.
* My website, such as it is ... http://rgharper.mvps.org/
* HELP us help YOU ... http://www.dts-l.org/goodpost.htm


"Edward" <hsmmsc@hotmail.com> wrote in message
news:eujGDDKqFHA.3424@TK2MSFTNGP14.phx.gbl...
> Thanks for your advise Richard.
>
> "Richard G. Harper" <rgharper@email.com> wrote in message
> news:%23u3PGmJqFHA.2960@TK2MSFTNGP10.phx.gbl...
>> Sorry, I don't know much about mail servers and configuration but I'd
>> suggest that you consider routing and forwarding the incoming mail - the
>> router gets it at public address xx.yy.zz.aa and forwards it to the mail
>> server inside the firewall, ditto outgoing mail gets routed from the
>> internal mail server to the external public address.
>>
>> You should probably also consider the possibility that if that server has
>> been sitting and facing the public for any length of time, it may not be
>> 'your' server any longer. Someone may have hacked it and I'd be very
>> worried about that possibility especially with a DC.
>>
>> --
>> Richard G. Harper [MVP Shell/User] rgharper@gmail.com
>> * PLEASE post all messages and replies in the newsgroups
>> * for the benefit of all. Private mail is usually not replied to.
>> * My website, such as it is ... http://rgharper.mvps.org/
>> * HELP us help YOU ... http://www.dts-l.org/goodpost.htm
>>
>>
>> "Edward" <hsmmsc@hotmail.com> wrote in message
>> news:ur2znVJqFHA.2364@tk2msftngp13.phx.gbl...
>>> Thanks Richard.
>>>
>>> I am trying to explore how best to deploy my network because I try to
>>> limit the number of machines that I need to power on 24/7. My ISP
>>> forward all my e-mail to a fixed public IP and I want also to have
>>> webmail running for MS exchange. Hence, I am trying to explore the
>>> options possible.
>>>
>>> Any suggestion welcome.
>>>
>>> Regards
>>>
>>> ---
>>> Ed
>>>
>>>
>>> "Richard G. Harper" <rgharper@email.com> wrote in message
>>> news:eAezjKJqFHA.1028@TK2MSFTNGP09.phx.gbl...
>>>> The first question that pops into my mind is ... WHY do you have a
>>>> domain controller exposed to the public? That is an incredibly risky
>>>> configuration.
>>>>
>>>> But anyway, yes, you will need to have the DC in the same address
>>>> segment as the rest of the network for clients to be able to log onto
>>>> it. Depending on the firewall/router hardware you might be able to
>>>> route traffic through it to the DC and back but if you do then what's
>>>> the point of having it?
>>>>
>>>> --
>>>> Richard G. Harper [MVP Shell/User] rgharper@gmail.com
>>>> * PLEASE post all messages and replies in the newsgroups
>>>> * for the benefit of all. Private mail is usually not replied to.
>>>> * My website, such as it is ... http://rgharper.mvps.org/
>>>> * HELP us help YOU ... http://www.dts-l.org/goodpost.htm
>>>>
>>>>
>>>> "Edward" <hsmmsc@hotmail.com> wrote in message
>>>> news:us4WACJqFHA.3204@TK2MSFTNGP10.phx.gbl...
>>>>>I have a Domain Controller with a public IP address and a PC behind a
>>>>> firewall router with a private IP address.
>>>>>
>>>>> How can I log on to the Domain Controller from behind the firewall
>>>>> router?
>>>>>
>>>>> Must I take the Domain Controller behind the firewall and give it a
>>>>> private
>>>>> IP before the rest of the network behind the firewall can use the
>>>>> domain
>>>>> controller.
>>>>>
>>>>> Thanks.
>>>>>
>>>>> ---
>>>>> Ed
>>>>>
>>>>>
>>>>>
>>>>
>>>>
>>>
>>>
>>
>>
>
>