Remote Support Software

Provide instant remote support to customers and employees:

Click here for a free trial

How to authenticate Extranet Web server access against AD

I know this type question has been asked a lot and I have found a lot of good information through web searches - however I still wanted to post to solicit advice from people who are currently working with these technologies - most of my knowledge of this
type project is dated so I want to make sure I know about the latest methods. Thanks in advance.
We are creating an extranet web site that will sit on our DMZ/IAS and I would like to authenticate it from our Active Directory on our private LAN. So I am looking for recommendations on a secure but not too technically complex method to authenticate
our extranet against our Active Directory. Each network segment is connected to a Sonicwall NSA240 firewall.
-
Single Win 2008 R2 IIS web server hosted on DMZ
-
Single forrest, single domain, AD located on LAN
-
AD is 2008 R2 level
-
Want to Authenticate users only to get in the front door of the extranet. Do not need to use groups to restrict certain content. Simply want to control access into the site.
-
FYI -- We do have a single exchange 2007 server located on our LAN. We allow SSL access to webmail and Outlook anywhere through our firewall.
I would like to entertain all possibilities at this point if there is software or hardware that I can purchase or upgrade to make this easier I will certainly consider. We have Hyper-V virtual platform with datacenter host licenses so
spinning up additional Windows 2008 servers is very low cost for us. I am curious if read only domain controllers play a role in this scenario and also if ISA server is still around and what role it would play.
Thanks much for any advice given.

Clay

There is an amazing pack of free network admin tools. click here to download it






June 7th, 2012 7:16am
Hiya,

You have allready "exposed" your AD to the internet, it is a problem, its just the extranet wont present anything new in the security context.

The scenarios we are deploying, usually consists of a LAN/Extranet based webserver(SharePoint), placed in the LAN segment, with a TMG placed in the DMZ which handles the authentication. Setup with SSL.
The TMG is build to handle exactly that, while the webserver is typically not.
Forefront Threath Management Gateway

http://www.microsoft.com/en-us/server-cloud/forefront/threat-management-gateway.aspx


Need to support users over the internet? click here try our remote control online beta






July 17th, 2012 11:52pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics