Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Active Directory domain in DMZ. Firewall rules.

Deploying an Active Directory domain in a perimeter network (or DMZ) usually requires some changes in firewalls. But the question is: what ports and from what computers must be opened?

The answer is not obvious. To simplify the firewalls rules deployment and (very important!) to simplify communication with Network Support team I designed an Excel spreadsheet. The spreadsheet has only one page that includes all groups and rules that must be configured on a firewall. You can easily customize it and then share with the network administrators.

User Account Control issue

After applying security hardening CIS baselines to Windows Server you may notice an annoying window asking you to click Alt-Ctrl-End every time you try to perform some administrative task:


To fix the behaviour you must either change a Group Policy that contains the security baseline settings or the Local GPO (if the baseline was applied locally).

 
After the change all elevations will be performed without additional windows.