tailieunhanh - configuring isa server phần 2

Đăng nhập bằng cách sử dụng mã phím này: KT95QJFD95 bản quyền Syngress xuất bản năm 2001, IncAn ninh là một mối quan tâm đáng kể cho bất kỳ tổ chức nào. Nếu tổ chức phải có một sự hiện diện hoặc kết nối với Internet, | balance on the fine line between accessibility and security although that scenario will work with a relatively simple domain structure that has a single domain in each forest administration becomes incredibly complex if your existing network has multiple domains at various levels in one or more domain trees. In that case in order to provide ISA functionality to clients in all the domains multiple explicit one-way trusts must be created and managed between the ISA Server domain and each of the other individual domains see Figure . Figure Placing ISA Servers in a Separate Forest Requires Creating Explicit One-Way Trusts between the ISA Domain and All Other Domains that Contain ISA Clients forest forest Ultimately it s a trade-off. Placing the ISA servers in a separate forest does provide more security but it also requires a higher cost in administrative time and effort. What about placing the ISA servers in their own domain but in the same forest or tree as your existing domains Is there any advantage to this solution Regardless of where in the forest your ISA domain is placed it still has an implicit two-way trust with the other domains in the forest so you lose the security advantage of the one-way trust. One reason you might place the ISA servers in their own domain in the same forest is to create an administrative boundary. That is if you want to assign a specific administrator or group to manage the ISA Servers this is an option. If we were working with an NT network that would be a good reason to create a separate domain for the ISA Servers. However because Windows 2000 provides for organizing resources into OUs and delegating administrative authority over individual OUs you can place the ISA servers in an OU and assign administrative privileges to the selected users without giving them administrative control over the entire domain. However keep in mind that the domain administrator will have administrative authority over all the OUs .

TỪ KHÓA LIÊN QUAN