<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain Controller on DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692370#M1035381</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;If u have allowed any any in ur acl then it should work now i am suspecting ur DC for testing purpose u can take one client and assign IP of ur DMZ and place this client on DMZ and then u try to add this client to ur domain if this works fine then we hav to look at ur config again  if this does not works then u can check ur DC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Nov 2006 07:57:13 GMT</pubDate>
    <dc:creator>vadi_ag</dc:creator>
    <dc:date>2006-11-29T07:57:13Z</dc:date>
    <item>
      <title>Domain Controller on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692366#M1035369</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem with Domain Controller when its on dmz and client of DC on inside,i ve configured an access-list to permit conversation between DC and Clients but they cant join to domain.&lt;/P&gt;&lt;P&gt;The DC ip address is 172.16.1.9 which i nat it to 10.9.0.15 ,and users subnet is 10.9.0.0/16 ,i also define dhcp server on DC and clients can take their ip address from dhcp but they can't join to domain.&lt;/P&gt;&lt;P&gt;please help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692366#M1035369</guid>
      <dc:creator>mrmozaffari</dc:creator>
      <dc:date>2019-03-11T08:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Controller on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692367#M1035373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I cannot see any acl entry for port 53 udp/tcp this port is for DNS and  allow port 500  and 50 and u hav to allow ports 88 tcp/udp for kerberos for time being u can allow tcp/udp echo port check out if this works then rate my reply if not we will try somethinf else&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Nov 2006 13:37:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692367#M1035373</guid>
      <dc:creator>vadi_ag</dc:creator>
      <dc:date>2006-11-21T13:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Controller on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692368#M1035376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vadi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply but after i saw your comments I've changed my access-list and add permit ip any any to my access list but again i saw that the clients could not join to domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2006 08:10:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692368#M1035376</guid>
      <dc:creator>mrmozaffari</dc:creator>
      <dc:date>2006-11-22T08:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Controller on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692369#M1035379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please someone help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2006 08:43:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692369#M1035379</guid>
      <dc:creator>mrmozaffari</dc:creator>
      <dc:date>2006-11-23T08:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Controller on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692370#M1035381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;If u have allowed any any in ur acl then it should work now i am suspecting ur DC for testing purpose u can take one client and assign IP of ur DMZ and place this client on DMZ and then u try to add this client to ur domain if this works fine then we hav to look at ur config again  if this does not works then u can check ur DC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2006 07:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692370#M1035381</guid>
      <dc:creator>vadi_ag</dc:creator>
      <dc:date>2006-11-29T07:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Controller on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692371#M1035383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't have an access-list applied to your inside interface, going to the DMZ should be allowed on all ports/protocols, so it shouldn't be an access list issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you've disabled nat unless you need it :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no nat-control&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default, you need nat from a high--&amp;gt;low interface unless you turn it off.  The static doesn't really cover that (you have to tell the pix what the ip addresses on the inside will be when they are on the dmz).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, make sure when they are getting their DHCP address from the server that they are getting the *translated* address as the WINS server, not the real one.  I don't know if this would be an issue - are you not routing the DMZ network internally?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this message if it answered some or all of your question/issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Nov 2006 00:59:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/domain-controller-on-dmz/m-p/692371#M1035383</guid>
      <dc:creator>jgervia_2</dc:creator>
      <dc:date>2006-11-30T00:59:27Z</dc:date>
    </item>
  </channel>
</rss>

