Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Microsoft Support > Windows NT/2000/2003 Server/2008 Server
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Windows NT/2000/2003 Server/2008 Server Find support for Windows NT/2000/2003 Server/2008 Server editions.

Reply
 
LinkBack Thread Tools
Old 04-21-2006, 06:36 AM   #1 (permalink)
Registered User
 
Join Date: Apr 2006
Posts: 1
OS: windows 2000


windows 2000/2003 security

Development Support Finance
PC 192.168.2.1 PC 192.168.3.1 PC 192.168.4.1
| | |
| SERVER 192.168.1.1 |
| Windows 2003 AD server
| |
| | |
| | |
| | |
| | |
|_____________________Layer 3 SWITCH____________________|
| |With InterVlan |
| | |
| Firewall Device With VPN module |
| | |
MAIL SERVER | |
Internet ANTIVIRUS
SERVER



PROSPOSED NETWORK

Presently we have a workgroup environment with 25 systems on win2k proff and win xp proff.A Linux firewall is setup for interent access with Iptables and nating.
Hence all the users have internet access.Some policy changes are needed and I want do a setup with the following groups and the security features needed are as below.

Groups

Research
Development
Support
Mktg
Finance

1)No group should be able to access the resources of each other ,except the users in its respective group.

2)Internet access only for support and mktg.
3)Other groups to have mail access only ,but no internet access(How should i go about this ,was thinking of installing Mdaemon mail server OR Can I go in for a firewall which has the capapbilty of creating groups which will only allow pop3 and smtp ports for a particular group)

4)Each group will probably have its own file server
5)A person from one group may have permission to access resources of other groups(if such an option is possible)

OR


Windows 2003 Active directory parent domain (tech.com )in the 192.168.1.0 network.

Pcs are in the group as shown above.

If a Vlan is created to sepearte the groups in diff Netwroks say 192.168.2.0 ;3.0;4.0.....

Is it possible for me to create a Additional domain controller or a child domain to the tech.com network or can i create just one domain (tech.com) and can the users from subnet 192.168.2.0 be an user of that domain.

Kindly let me know.


I have attached 2 files
Attached Images
File Type: jpg diag1.jpg (48.0 KB, 2 views)
File Type: jpg diag.jpg (91.5 KB, 4 views)
s_hcl is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 11:56 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85