Server Placement

anonymous_at_discussions.microsoft.com
Date: 05/12/04


Date: Tue, 11 May 2004 22:42:39 -0700

Answers are inline.

Mohamed Imran Vilcassim - Sri Lanka
imranv@cntconnect.com
MCP,MCSE,MCT

>-----Original Message-----
>Good Morning,
>
>I had posted a question and I believe it was probably to
broad to get any
>good answers. I will keep it simple in this one. I will
be setting up a new
>network. In this network I will be using ISA as my
firewall. I will like to
>have your opinions on where would you place the
following boxes.
>
>- Exchange Server for corporate use (DMZ, External,
Internal? ) Why? Host it on the internal Network with a
private IP and configure a publishing rules on the ISA
Server to receive mails for your domain which would be
redirected to your internal mail server. ensure DNS
Records point to the external IP Address of the ISA Server
>
>- Exchange Server for hosting 3rd party emails (DMZ,
External, Internal? )Host it on the DMZ Network and
configure Packet Filter Rules for security on the
Firewall. this eliminates external communications to the
internal network.
>Why?
>
>- W2K3 Web edition web server for corporate use (DMZ,
External, Internal? )Host it on the Internal Network if
no external access is required by expternal partners
>Why?
>
>- W2K3 Web edition web server for hosting 3rd party web
sites and ASP.NET
>apps (DMZ, External, Internal? ) Why? host it on the DMZ
and configure load balancing for performance. if access
required to data on a SQL Server, hos the SQL Server on
the internal network and create a rule which allows only
the web server(s) access to the internal SQL Server.
>
>- SQL Server for corporate use (DMZ, External,
Internal? ) Why? Host it on the Internal Network.
>
>- SQL Server for 3rd party apps (DMZ, External,
Internal? ) Why? see earlier answer
>
>
>
>With the goal being, to have a balance between
performance and security.
>
>
>.
>



Relevant Pages

  • Re: Merge replication security
    ... I know port 1433 needs to be open for OUTBOUND traffic, ... By having a separate SQL server in the DMZ I can use Windows ... > connect to your SQL Server which is on your internal network. ...
    (microsoft.public.sqlserver.replication)
  • Server Placement
    ... >- Exchange Server for corporate use (DMZ, External, ... Host it on the internal Network with a ... required to data on a SQL Server, ...
    (microsoft.public.isa)
  • Re: What is DMZ?
    ... DMZ is in computer security terms a network ... nor the internal network, but somewhere in between. ... using two firewalls you add another layer of security. ... between the internal network and the compromised host. ...
    (comp.security.firewalls)
  • Re: Issue connecting through firewall using jdbc connector.
    ... Web applicationin DMZ ... SQL Server on internal network ... Not a solution for us, though, since the web master has set up a Microsoft network within the DMZ. ...
    (microsoft.public.sqlserver.jdbcdriver)
  • Publishing MS SQL problem, isa 2000
    ... Need to sql server sitting on the dmz from the internal network. ... 68.117.204.62), need odbc access to it from the internal network, ...
    (microsoft.public.isaserver)