Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Making my DC exposed to the internet ....??

Status
Not open for further replies.

bran2235

IS-IT--Management
Feb 13, 2002
703
0
0
US
Hello all,

We are about to implement a hosted email solution for my end-users. I have been asked (by the Co. hosting) to allow their trffic (by opening one port) into our netowrk (to my DC!!) so that they can perform querrys (LDAP) in order to get our GAL and Distribution Lists...

This will be basically sitting my DC on the interet!!
It is not using SSL, so I'm only protected by IP / Port Restrictions / and user credentials...

My Question:
Does this seem risky to anyone else?
Is there a better way to send my GAL and Distribution Lists ...?

Any advice or comments all welcome!!


Many thanks-
Brandon
 
If you limit access to the DC through the firewall to only the provider's IP address, you'll limit the vulnerability.

Pat Richard MVP
Plan for performance, and capacity takes care of itself. Plan for capacity, and suffer poor performance.
 
True...

Does anyone know if there is another way to allow them to query our AD for the GAL and DLs? (anytime someone uses the TO: field in the hosted mail app, it does a real-time querry of our AD for Email Addresses (GAL, etc.)...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top