Great Circle Associates Firewalls
(October 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Windows NT domain through Gauntlet firewall
From: Colin Linahan <cfl @ parkville . molsci . csiro . au>
Date: Thu, 16 Oct 1997 16:42:29 +1000 (EST)
To: firewalls @ GreatCircle . COM
In-reply-to: <199710120733 . AAA27846 @ honor . greatcircle . com>
Reply-to: Colin Linahan <Colin . Linahan @ parkville . molsci . csiro . au>

Hi everyone,
	We want to do what many may consider a security risk - allow Windows
NT ports 137,138 and 139 between initially three geographically separate sites.
	We are wanting to run a Windows NT domain over our TCP/IP based
WAN ( which is connected to the Internet ) - through CISCO routers and a
 Gauntlet 3.2 firewall running on SunOS 4.1.4 based host ( which will later 
 this year be running Gauntlet 4.0 for Solaris ).
Our site is the only one with a proxy-based firewall.

	The plan is to have ip-helper and forward running on the gateway CISCO
at each site. On the firewall we will configure packet screening to 
allow ports137,138 and 139 from our internal NT servers to 137, 138 and 139
on the external NT servers and also to the same ports on our gateway router.

	Has anyone sucessfully done just this, or know if it can be done ?
Basically - will someone at another of our sites be able to join or log
in to our domain if the PDC is at our site, behind our firewall ?

Thanks for any help,
 Colin .
 Linahan @
 molsci .
 CSIRO .
 AU		Network & Systems Administrator
 Biomolecular Research Institute	Computing Section
 343 Royal Parade, Parkville, 		tel: +61 3 9662 7372
 Victoria 3052		Australia	fax: +61 3 9662	7346 







References:
Indexed By Date Previous: RE: firewalls with linux OS
From: "Sameer R. Manek" <manek @ challenger . atc . fhda . edu>
Next: Firewalls: www & high port numbers
From: Doug Bridgens <Doug . Bridgens @ 3Dlabs . com>
Indexed By Thread Previous: Re: DNS on the Firewall - security problem
From: Darren Reed <avalon @ coombs . anu . edu . au>
Next: Re: DNS on the Firewall - security problem
From: Bernd Eckenfels <lists @ lina . inka . de>

Google
 
Search Internet Search www.greatcircle.com