Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Firewalls
[Top] [All Lists]

Re: authenticating admins in DMZ

Subject: Re: authenticating admins in DMZ
Date: Tue, 22 Feb 2005 09:40:07 -0800
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Have you looked into using securid or similar token based
authentication? If you already have an ace server, it is a great way
to protect the accounts on your DMZ hosts.

dmz

sven.de.jonghe@kindengezin.be wrote:

|
| Hi,
|
| We have a bunch of admins that need to administer servers in the
| DMZ using Terminal Services. Up till now, they are all logging in
| using the same administrator account on the server. I would prefer
| having them log in using their domain account but obviously, the
| DMZ servers are not domain members. What would be the most secure
| way to set up authentication in the DMZ? Should I create a new
| domain in the DMZ and make all servers member of this new domain
| and provide a one way trust to our LAN Domain? Would it be good to
| have both DC's communicate via IPSEC? I don't want any replication
| of LAN accounts to the DMZ. I also don't need authentication
| between servers in the DMZ or webusers logging in a website. I just
| need admins logging on remotely via TS to be authenticated by our
| LAN DC. Is all this a good idea? What are the possible threats
| involved?
|
| thanx
|
|
|


- --
/----------------------------------------------------------\
~ David M. Zendzian * dmz@dmzs.com ~ D3FF FD6F 9DB6 C74B E14A 0D19 9730 1513 6B59 B9BD
~ (415) 867-7812 - phone (510) 549-9187 - fax
~ ------------- ~ Imagination is greater than knowledge * Albert Einstein
~ Every day is a good day, whether you like it or not! * DMZ
\----------------------------------------------------------/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)


iD8DBQFCG252lzAVE2tZub0RAi7JAKCQHDsQzpgAmjrHNoVNnDe1JPkfHACgz1xG
4o1OlaY8EL/EDYRDUgdeE+I=
=Xjhg
-----END PGP SIGNATURE-----

<Prev in Thread] Current Thread [Next in Thread>