Groups | Blog | Home
all groups > iis ftp > september 2006 >

iis ftp : FTP Server in DMZ


Alan
9/12/2006 9:52:01 AM
I have been tasked with moving our current FTP server into a DMZ. Currently
the FTP server is setup on a member server in our domain and we use security
groups in Active Directory to restrict access to certain folders in the FTP
site. We do not allow anonymouse access.

My question is how do I configure a new server in the DMZ that would still
allow for the security groups to work? We would still need the users to
login with thier domain accounts.

Alan
9/14/2006 6:44:02 AM
Jeff,
Does that open up security risks that the DMZ would normally eliminate?

Should the FTP server be a stand alone server (workgroup) or would you set
it up as a member server in the domain?

Thanks for your help,
Alan

[quoted text, click to view]
jeff.nospam NO[at]SPAM zina.com
9/14/2006 10:42:44 AM
On Tue, 12 Sep 2006 09:52:01 -0700, Alan
[quoted text, click to view]

Configure your firewall to pass AD authentication between the DMZ and
LAN. See your firewall docs and an AD group for help there.

Bernard Cheah [MVP]
9/15/2006 12:00:00 AM
Yes, but if this is the requirement, then you have to live with it.

if you need AD auth, it has to be part of the domain.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

AddThis Social Bookmark Button