Question : Should DMZ servers be part of the company domain?

Hi All,

We have aroung 6 server exposed to the public via DMZ (of course behind a firewall). All our LAN servers are part of the domain and I was wanting to have the DMZ servers join the domain, but was told not to, that it was a bad idea as DMZ servers, if compromised, could then attack the rest of the domain.

Is this true? What is best practice in regards to this? Should servers in the DMZ be standalone member servers.

Answer : Should DMZ servers be part of the company domain?

I found this post:
Active Directory and DMZ design query: http://forums.techarena.in/active-directory/912878.htm

It should answer your question
Random Solutions  
 
programming4us programming4us