Re: Best Practices IIS

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Kristofer Gafvert (kgafvert_at_NEWSilopia.com)
Date: 06/28/04


Date: Mon, 28 Jun 2004 20:38:13 +0200

Hello,

I recommend installing it on a stand-alone machine*.

The Domain Controller should not be connected directly to Internet, and if
you are running a webserver, you need to have it connected to Internet*.
If someone hacks the server (because it is connected directly to Internet),
the hacker will have control over the whole domain.

* If you plan on running this on the Intranet, in a controlled environment,
and have a tight budget, you can run IIS on the DC. But i still recommend to
not do it, if it is possible to avoid.

-- 
Regards,
Kristofer Gafvert - IIS MVP
http://www.ilopia.com - When you need help!
"Darshan Diora" <darshan.diora@infrasofttech.com> wrote in message
news:ui5pYlPXEHA.2964@TK2MSFTNGP09.phx.gbl...
> Hi,
>     For  better security  should IIS be installed on Win 2000 Domain
> Controller  or on a standalone Win 2000 server.
>
> Regards
> Darshan Diora
>
>


Relevant Pages

  • Re: Enabling logging on IPC$ share ?
    ... You should hope to see no access from the internet to a domain ... controller unless this is a intrusion detection project on a non production DC. ... events will give you the most information in conjunction with firewall logs. ... I have enabled all kinds of logging, ...
    (microsoft.public.win2000.security)
  • Re: Restart: VLAN question...
    ... We have several classrooms which need continous access to the domain ... controller subnet and in addition, internet access only when needed. ... How can we avoid connecting ALL classrooms to the internet once the ...
    (comp.dcom.lans.ethernet)
  • Re: How Do You Build Firewall Rules to Restrict RPC Traffic?
    ... > are not exposed to the Internet, so RPC is never exposed to the Internet. ... The worst security risks on most networks are not from the outside coming ... our network, the domain controller will be used to authenticate, perform DNS ...
    (microsoft.public.isa)
  • New User Help Please
    ... 6513: Internal Tape Device Controller ... 6140: Twinaxial Workstation Controller ... Can a display with the twinaxial connect directly to the system or do ... Anyone know of an install guide that I can get (Internet or hardcopy)? ...
    (comp.sys.ibm.as400.misc)
  • Re: Group policy problem
    ... It is best to avoid using more than one network adapter in a domain ... domain controller is pointing to itself as it's primary dns server by the IP ... > intranet and one for connecting to internet. ...
    (microsoft.public.win2000.group_policy)