Putting a Windows DC, Exchange in a DMZ

Posted by blsub6 on Server Fault See other posts from Server Fault or by blsub6
Published on 2010-12-21T19:11:34Z Indexed on 2010/12/21 19:55 UTC
Read the original article Hit count: 251

I have one guy at my company telling me that I should put FF:TMG in between my main Internet-facing firewall (Cisco 5510) and put my Exchange server and DC on the internal network.

I have another guy telling me that I should put the Exchange server and DC in a DMZ

I don't particularly like the idea of having my mailboxes and DC's usernames/passwords in a DMZ and I think that Windows authentication would require me opening up so many ports between my DMZ and my internal network that it would be a moot point to have it out there anyways.

What are some thoughts? How do you have it set up?

© Server Fault or respective owner

Related posts about security

Related posts about active-directory