Re: Noob question: ISA and IIS on the same server?

From: Thomas W Shinder [MVP] (tshinder_at_hotmail.com)
Date: 07/02/04


Date: Thu, 1 Jul 2004 19:11:09 -0500

Hi Gary,

This sounds like a back to back DMZ, the most secure config.

Just curious, what real security do you think you derive from the pix? Does
it do anything other than packet filtering and NAT?

Thanks!

--
Tom
www.isaserver.org/shinder
Get the book!
Tom and Deb Shinder's Configuring ISA Server 2004
http://tinyurl.com/3xqb7
MVP -- ISA Firewalls
"Gary" <gary123@123iplynx123.com123> wrote in message
news:cVXEc.2965$876.1834@fed1read07...
: Using these links:
:
: http://support.microsoft.com/default.aspx?scid=kb;en-us;323387
: http://support.microsoft.com/default.aspx?scid=kb;en-us;290113
: http://support.microsoft.com/default.aspx?kbid=238131
:
: I am configuring an ISA server on an existing Win2k3 server that currently
: performs web hosting and DNS in a DMZ (medium security interface--50)
behind
: a PIX 515. The purpose for this ISA server is to provide proxy access to
the
: corporate web mail server that is on the high security interface (100) of
: the PIX. I am fairly certain that there is no configuration that will
permit
: me to proxy the web mail on the outside interface of the ISA server, but
am
: open to any suggestions anyone has on this matter.
:
: My Solution (as much as I disapprove of how it breaks the philosophy of a
: good firewall configuration) is to place the internal interface of the ISA
: server on the high security corporate network and leave the public
interface
: in the PIX DMZ. I would ordinarily never do this but I see no way to proxy
: using ISA without 2 physical interfaces, and since ISA IS a firewall (MS
: would have me believe--rather convincingly too judging by its capabilities
: and documentation which are rather impressive, even to a skeptic like me),
I
: have little reservation in allowing the DMZ network and the corporate high
: security network to met, physically, though 2 firewalls.
:
: My Question is, how do you configure the Win2k3 server to serve a website
: through its own IIS server, but also to proxy to another website using
ISA?
: I have duplicated my sandbox configuration in the production environment
: using the Step-by-step guides provided by MS and while my sandbox
: configuration continues to function properly, my production environment is
: not functioning in a proxy capacity (DNS and local IIS serving work, but
: proxy web mail does not). I have determined that the only difference (that
I
: can recognize as possibly causing a problem) is that my production
: environment Win2k3 server is running IIS, while my sandbox environment is
: not. Anyone running IIS and ISA together to both serve and proxy websites?
: If so, what deviations from the MS Step-by-step guides are there? Any
: assistance would be greatly appreciated!!
:
: The Step-by-step guides I refer to are (in the order in which i used them
: are):
:
: http://support.microsoft.com/default.aspx?scid=kb;en-us;323387
: http://support.microsoft.com/default.aspx?scid=kb;en-us;290113
: http://support.microsoft.com/default.aspx?kbid=238131
:
: Thanks in advance!
:
: -Gary
:
:
:


Relevant Pages

  • RE: Front End/Back End communication
    ... MVP -- ISA Firewalls ... There is no such thing as security perfection. ... single front-end/back-end Exchange Server will find this setup to be ...
    (Focus-Microsoft)
  • RE: SBS 2003 SP1 Upgrade - MSDE 2000 Service Pack 4 did not instal
    ... C:\Program Files\Microsoft SQL Server ... you can directly insert the ISA 2004 installation CD ... import the ISA configuration information to restore back all configurations. ... following registry subkey on the server, ...
    (microsoft.public.windows.server.sbs)
  • Re: Forest/Domain in the "DMZ" to accomodate web, front-end servers
    ... I don't know where you came up with the idea that ISA Server doesn't ... as it's been doing that since ISA 2000 debuted a number of years ago now. ... Who cares if untrusted hosts compromise ... My point is the network edge is not the place to have all your security. ...
    (microsoft.public.security)
  • RE: Publish Sharepoint behind SBS2000
    ... Clear your Web cache when testing for a new result, otherwise ISA might ... key in your external domain name for the internal SharePoint server. ... >>Despite all the security issues with this configuration, ...
    (microsoft.public.windows.server.sbs)
  • Re: Security experts criticize an SBS installation
    ... If I had a dime every time some two bit "security expert" thought Microsoft products were insecure I'd have a lot of dimes and a lot of folks that haven't looked at Microsoft products since WinNT. ... I have a GSEC security credential, volunteer for the Center for Internet Security and know that my security of my network is based more on the lack of control of my workstations than it is with that ISA box. ... I cannot, to the best of my knowledge, remember a SBS box that has been hacked when the passwords are long/strong/secure, the box is patched, and the workstations are configured based on the risk of each person. ... But a SBS server ..even with that "so called" hacked in umpteen minutes ISA server ...Get him to tell you in details how he hacked into ISA server. ...
    (microsoft.public.windows.server.sbs)

Quantcast