Firewall-1

Re: [FW-1] OWA Outlook Web Access in DMZ...need access to Active Directo

Subject: Re: [FW-1] OWA Outlook Web Access in DMZ...need access to Active Directory...
From: Hugo van der Kooij <hvdkooij AT VANDERKOOIJ DOT ORG>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Tue, 19 Dec 2006 11:12:14 +0100
On Mon, 18 Dec 2006, no-need to-list wrote:

Hello Everyone...
Has anyone deployed OWA  Outlook Web Access in DMZ ?,
 it need access to MS active directory, no errors are reported from the FW 
(r55-hfa18), but still is unable to talk to MS Active directory.
What is the best way to deploy this?

Frankly. I would (preferably) not deploy anything on a DMZ that needs to setup connections to the inside without a clear protocol definition that one can reliably verify. So this rules out any proprietary protocol like microsoft rpc or oracle.

In your case I would setup a front for OWA and put it in the DMZ and leave OWA on your LAN.

Hugo.

--
        hvdkooij AT vanderkooij DOT org http://hvdkooij.xs4all.nl/
            This message is using 100% recycled electrons.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>