Home All Groups Group Topic Archive Search About

Domain authentification in a DMZ

Author
26 May 2009 5:21 PM
r14edge
Hello,

  I'm building a DMZ and I'm having a tough time using my remote storage in
my domain. My servers in the DMZ are standalone, have no access to the domain
and they are using IIS6. Both network are separate by a firewall. I already
open up the necessary port and I know that my IIS server is capable of
getting the files.

I've setup a website using a UNC path on my remote storage. I'm using a
domain account to access my remote storage and I've enable anonymous with
using that same domain account. I've also check the integrated Windows
authentification.

That setup works great inside my network. My websites are working great.
When I'm applying that setup on my DMZ machines, I'm getting 401.3 error
messages. I also notice while auditing that for some reason, my domain
account  is being transform for another account, NT AUTHORITY\ANONYMOUS
LOGON. I believe this translation is causing my headache and I don't know
what to do at this point. How can I make my DMZ servers properly
authentificate without having them in my domain?

Thank you for answer,

Fred Rajotte