Re: How I spent my Christmas vacation - Email found in subject

Hi Danny,

We'll have to agree to disagree. As long as you allow LDAP traffic from
an anonymous access DMZ to your DC, you're asking for bad things to
happen and people like me with ready and willing fingers to point at
you.

My design is much more secure, hands-on. The NDR issue is a problem with
my relay's platform. RFC or not ( and you haven't mentioned which RFC
you're referring to) I'm using security best practices by isolating my
low security zone hosts from my highest security zone hosts.

Tom

Thomas W Shinder, M.D.
Site: www.isaserver.org
Blog: http://spaces.msn.com/members/drisa/
Book: http://tinyurl.com/3xqb7
MVP -- ISA Firewalls
**Who is John Galt?**

 

> -----Original Message-----
> From: Danny [mailto:nocmonkey@xxxxxxxxx] 
> Sent: Tuesday, January 03, 2006 4:44 PM
> To: [ISAserver.org Discussion List]
> Subject: [isalist] Re: How I spent my Christmas vacation - 
> Email found in subject
> 
> http://www.ISAserver.org
> 
> On 1/3/06, Thomas W Shinder <tshinder@xxxxxxxxxxx> wrote:
> > Hi Danny,
> >
> > So, you allow LDAP queries from hosts on an anonymous access DMZ.
> 
> No - my SMTP server has an up-to-date (on demand or scheduled every X
> minutes) list of valid recipients.  There are no anonymously initiated
> LDAP connections.
> 
> > How do you mitigate the security issues involved with that.
> 
> Firewall is default deny, but allows 1) SMTP traffic from the MX
> gateway to the Exchange server 2) Allows LDAP traffic during schedule
> intervals or on demand.
> 
> > Yes, I know the convention wisdom in some circles say don't 
> accept mail to non-
> > existing accounts, but then you have to allow LDAP from a 
> very low security
> > zone.
> 
> If you mean RFC's when you refer to "some circles say", then I guess
> can translate your lingo, however, there are no anonymous LDAP queries
> occurring.
> 
> > A very poor compromise.
> 
> No compromises; only the essentials.
> 
> ...D
> 
> ------------------------------------------------------
> List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
> ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
> ------------------------------------------------------
> Visit TechGenix.com for more information about our other sites:
> http://www.techgenix.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org Discussion 
> List as: tshinder@xxxxxxxxxxxxxxxxxx
> To unsubscribe visit 
> http://www.webelists.com/cgi/lyris.pl?enter=isalist
> Report abuse to listadmin@xxxxxxxxxxxxx
> 
> 


Other related posts: