Re: Steps to setup app allowing offsite network access using IIS Authe



Hi,

I'm not sure what you're asking?? The first paras imply you want them to be able to _run_ a web app on an IIS server? You keep using the word "run". Obviously anyone can "run" a web app just be browsing to it.

Do you mean you want them to be able to collaboratively develop a web app. If so, you may want to look at source control over HTTP and a means of publishing over HTTP such as FrontPage or WebDav.

Do you mean you want them to be able to compile and debug on the live server? If so, that's another (long) story.

Regardless of all that, one problem to look out for is that they won't have Active Directory if it's in a DMZ, so Integrated Authentication won't work, nor will Impersonation, You'd need to use plain text with SSL, nasty, and you'd need to pass the passwords as plain text if you want them to be able to start a process, unless you can get Kerberos working in the DMZ and able to pass the tickets over two hops. If they really are "partners", you might be better off with a VPN.

Ever thought of using Linux instead?

thejamie wrote:
In order to create an application our partner's can run from a website in our DMZ, there will be several steps involved - from compiling the application with a strong name, to setting up IIS (framework 2.0 and vs 2005) and finally access to the application which will need to run on a server from the DMZ for our partners. Question:
Can anyone outline each step required to set this up on an IIS server in the network or DMZ along with the assembly requirements of the application to run on this network?

Or is there a link to a web page that shows, step by step, (or outline) of the process that creates an application, creates the IIS that exposes the application in the DMZ (or even in the network) securely, and allows the application to run from this location?

Even just a list of all the steps required that allow the application to run on the network would be appreciated (ie inside the network rather than from the DMZ).

Network is already established and secure and DMZ has been available via FTP for several years (we want to retire our use of STX). The problem is primarily permission setup in NET Framework 2.0 (CAS) permission end. Click once works fine but it is not what we are looking for. Instead we need a method that specifically assigns an "application" to be run only from the network [not as a service on the server and not as an application that installs on someone's local machine from a network location]. Our partners will only be able to come in through IIS authentication. Our partners need the ability to kick off specific processes on our server when they deem it necessary.


--
Gerry Hickman (London UK)
.



Relevant Pages

  • Linux, New Corporate Network, Cisco Routers, T1 Ethernet Handoff, DMZ...
    ... I am setting up a network for a company that I am part owner of. ... internet go into my Cisco 2621 router that has 3 10/100Mbs FE interfaces. ... the same switch creating the "sandwich" DMZ setup with the public devices in ... PBX server that uses a straight VoIP connection all the way to our service ...
    (comp.os.linux.networking)
  • New Corporate Network, Cisco Routers, T1 Ethernet Handoff, DMZ...
    ... I am setting up a network for a company that I am part owner of. ... internet go into my Cisco 2621 router that has 3 10/100Mbs FE interfaces. ... the same switch creating the "sandwich" DMZ setup with the public devices in ... PBX server that uses a straight VoIP connection all the way to our service ...
    (comp.security.firewalls)
  • Re: Is Remote Desktop Web Connection secure?
    ... 80 or 443 to an IIS Server. ... I'd opt for the SSL VPN in DMZ Option, i.e. using AEP Networks NSP or Citrix ... open up your internal network directly to the internet is just asking ...
    (microsoft.public.windows.terminal_services)
  • Re: SBS2000 and a DMZ
    ... This network is my HOME network that I use as a test bed to learn things ... the systems in the DMZ are my sons desk tops and laptops. ... but could not get CDDB(an internet service that is used to identify music ... The W2K3 server is a recent addition and wanted it for storage of the boys ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Remote Web Workplace not working properly
    ... Another possibility is alterations to the IIS Application Pool ... take control of the server in the room right next to ... over the internet or from any one desktop within the network). ... back to the login window. ...
    (microsoft.public.windows.server.sbs)