Hi Collective,
We're looking to implement a forest with one domain in our DMZ into which there will be a number of applications, initially MS EPM with others to follow. Anyway there is a requirement for external partners and internal users (hence the trust) to access these resources.
To enable this we proposed a one way forest to forest trust with the DMZ trusting the internal forest, external partner accounts will be in the DMZ forest\domain. Only the required ports on the firewall would be opened to enable the trust and ldap.
This is a design option in an MS whitepaper and I also know of one large corporate doing the same.
Our security policy chap here is saying this is a no no and goes against good practice.... given the coporate I referred to generally adhere to good practice, I'm beginning to wonder...
So my question is, from your experiences have you seen this implemenatation before? does it really go against good practice?
Cheers,
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Reply to: DMZ Forest to Internal Forest Trust
Collapse
You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:
- You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
- You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
- If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.
Logging in...
Previously on "DMZ Forest to Internal Forest Trust"
Collapse
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- How EV tax changes of 2025-2028 add up for contractor limited company directors Yesterday 08:11
- Under the terms he was shackled by, Ray McCann’s Loan Charge Review probably is a fair resolution Jan 27 08:41
- Contractors, a £25million crackdown on rogue company directors is coming Jan 26 05:02
- How to run a contractor limited company — efficiently. Part one: software Jan 22 23:31
- Forget February as an MSC contractor seeking clarity, and maybe forget fairness altogether Jan 22 19:57
- What contractors should take from Honest Payroll Ltd’s failure Jan 21 07:05
- HMRC tax avoidance list ‘proves promoters’ nothing-to-lose mentality’ Jan 20 09:17
- Digital ID won’t be required for Right To Work, but more compulsion looms Jan 19 07:41
- A remote IT contractor's allowable expenses: 10 must-claims in 2026 Jan 16 07:03
- New UK crypto rules now apply. Here’s how mandatory reporting affects contractors Jan 15 07:03
