Jump to content

Recommended Posts

Posted (edited)

Hello,

 

I am looking at setting up a server to provide Direct Access and VPN. I am trying to get my head around the topology. Am I right in thinking that the secure way to do this is by having 2 nics, one on a DMZ and one in the production network? You then open ports from the firewall to the DMZ IP?

 

I have attached a diagram of how I think it will sit in our network. Is there a more secure way of doing this please? Im not a big fan of doing it like this really.

 

Thanks

 

 

VPN Topology (1).png

Edited by FN-GM
Posted
You would normally have a firewall between your DMZ and production network.

 

Well I do (actually 2!) but all the guides I have seen on the internet I have seen don't seem to do this. They use the topology above.

Posted (edited)

I set up a DMZ at last place for SharePoint and Skype

 

I'd ignore the link from the server back to Production and route it via Firewall & Filtering.

 

I'm not sure on the In's and Outs on how the servers were configured in the DMZ to route back to production but I know the only possible route was through a firewall as you'd expect the normal way for a DMZ.

 

In our case DMZ Dirty and DMZ clean were on same firewall as we had only one firewall.

 

We had set up a DMZ Clean and a DMZ Dirty which as names state DMZ Dirty allowing only required ports from Internet to DMZ server and DMZ Clean allowing only ports to specific servers in Production.

 

It is really confusing diagram.

 

Does the below help, sossy if you have already been there??

 

http://www.celestix.com/comparing-directaccess-dmz-and-edge-deployments/

 

http://windowsitpro.com/windows-server-2012/directaccess-windows-server-2012

 

http://jackstromberg.com/2013/12/tutorial-configuring-direct-access-on-server-2012-r2/

Edited by Davit2005
  • Thanks 1
Posted
Got mine setup using only 1 NIC.

 

On the last link I posted ( I think) they have scenarios where one card is used or 2

 

Two adapters—With two network adapters, Remote Access can be configured with one network adapter connected directly to the Internet, and the other is connected to the internal network. Or alternatively the server is installed behind an edge device such as a firewall or a router. In this configuration one network adapter is connected to the perimeter network, the other is connected to the internal network.

Single network adapter—In this configuration the Remote Access server is installed behind an edge device such as a firewall or a router. The network adapter is connected to the internal network.

 

Two adapters—With two network adapters, Remote Access can be configured with one network adapter connected directly to the Internet, and the other is connected to the internal network. Or alternatively the server is installed behind an edge device such as a firewall or a router. In this configuration one network adapter is connected to the perimeter network, the other is connected to the internal network.

 

Single network adapter—In this configuration the Remote Access server is installed behind an edge device such as a firewall or a router. The network adapter is connected to the internal network.

  • 2 months later...
Posted (edited)

sorry for the late reply, I am getting back on with this. Thanks to those who have replied.

 

Got mine setup using only 1 NIC.

 

in What network does that NIC live please?

 

I set up a DMZ at last place for SharePoint and Skype

 

I'd ignore the link from the server back to Production and route it via Firewall & Filtering.

 

I'm not sure on the In's and Outs on how the servers were configured in the DMZ to route back to production but I know the only possible route was through a firewall as you'd expect the normal way for a DMZ.

 

In our case DMZ Dirty and DMZ clean were on same firewall as we had only one firewall.

 

We had set up a DMZ Clean and a DMZ Dirty which as names state DMZ Dirty allowing only required ports from Internet to DMZ server and DMZ Clean allowing only ports to specific servers in Production.

 

It is really confusing diagram.

 

Does the below help, sossy if you have already been there??

 

Comparing DirectAccess DMZ and Edge Deployments - Celestix Networks

 

DirectAccess in Windows Server 2012 | Windows Server 2012 content from Windows IT Pro

 

[Tutorial] Configuring Direct Access on Server 2012 R2 | Jack Stromberg

 

Doesn't the server need to be joined to the domain? So if I have just one NIC and routed back to the production network via firewalls there would be a large number of ports that need allowing? Looking at the last link you posted, the tutorial suggests a topology I posted in the original post.

Edited by FN-GM
Posted (edited)

Just looking at this link at NAT Configuration 1

Server 2012 R2 DirectAccess Network Topologies | OutsideSys

 

"By placing the internal NIC in a DMZ, the DA server can be blocked from accessing the internal corporate resources by a network device (firewall)."

 

The diagram seems to indicate that all traffic is allowed between DMZ 2 and the corporate network by the wording "All IP". So how can this be more secure than the topology in the OP? The firewall will just be acting as a router and not stopping anything?

 

http://itpro.outsidesys.com/wp-content/uploads/2016/03/DA-NAT-Config1.png

Edited by FN-GM
Posted
in What network does that NIC live please?

 

I have a flat network so it's just on the network with a rule on the firewall to forward to it.

 

Stuart

Posted
I have a flat network so it's just on the network with a rule on the firewall to forward to it.

 

Stuart

 

I see. I wouldn't want to do this for security reasons. Thanks for replying :)

Posted
What security reasons as perhaps I don't want to be either!

 

Well you should never directly open ports for anything on your internal network, if it gets hacked they will have free run of your network. For example for ADFS I have a Web Application Proxy sat in the DMZ. The authentication is carried out on that server then only https is permitted into the production network.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...