Re: IIS Web Server and Firewall

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Herb Martin (news_at_LearnQuick.com)
Date: 12/26/04


Date: Sat, 25 Dec 2004 19:55:44 -0600


"Dave" <Dave@discussions.microsoft.com> wrote in message
news:9AB5B118-90F8-474F-B38E-53670E621D2D@microsoft.com...
> I have a web server (personnal) and I want to setup a firewall. If I am
> running a router do I need to?

"Need" is a (very) relative term, but if you mean are
you generally well protected by a router the answer
is "No."

Even a translation router (NAT) is offers no real
security -- except that usually the outside world
cannot INITIATE contact.

A lot also depends on your definition of "firewall."
(There are at least a half a dozen main categories
and differences of opinion on what constitutes a
firewall.)

> If so what are some software firewalls that
> can be used with IIS 5?

Yes.

Notice that IIS (or any web server) must accept
connections from SOMEONE or it is not going
to be very useful as a server -- in fact this is true
of any server.

Firewalls block or filter certain types of messages
but by their very nature they must also allow
certain (types) of messages to penetrate or else
one would just disconnect the network cable to
ensure security.

What do you wish to filter? All incoming messages
director to machines (addresses) other than your
IIS machine? Perhaps directed to any other port
than the (customary) Web server port (i.e., 80)?

Do you wish to try to filter the CONTENT of those
messages or just the source and destinations?

Firewalls start with the simple idea of a filtering
router, one which only allows connections to or
from certain addresses or ports, and grow in
complexity to very smart devices and software
that can make decisions based not just on the
contents of ONE packet but on the basis of
other packets previously received as well.

Note, that SOME (very smart people) don't even
think of the "the firewall" as being one machine
or piece of software but rather as the entire SET of
devices and processes which protect you network
where it connects from the internal to the external
world, which would enclude any intermediate
networks frequently referred to as DMZ or "screened
networks."

-- 
Herb Martin


Relevant Pages

  • Re: Host Computer with ICS cannot be accessed
    ... You read my mind on the router thing. ... My home network is a piece of cake... ... >>firewall settings, not that I've found so far, but I'll keep looking. ... and we couldn't get file sharing working until ...
    (microsoft.public.windowsxp.network_web)
  • Re: share my printer between 2 computers and surf with 2 computers at same time
    ... The main choice you have to make is whether to have the router include wireless capability or not. ... Because wireless routers for home use are relatively inexpensive these days, I'd suggest buying a wireless router even if you don't initially intend to use that capability. ... If you already have a UTP cable going between upstairs and downstairs, you can use that to have a wired network. ... caused by 1) a misconfigured firewall; ...
    (microsoft.public.windowsxp.network_web)
  • Re: share my printer between 2 computers and surf with 2 computers at same time
    ... The main piece of hardware you need to buy is a router. ... Because wireless routers for home use are ... you can use that to have a wired network. ... caused by 1) a misconfigured firewall; ...
    (microsoft.public.windowsxp.network_web)
  • RE: [Full-Disclosure] Re: January 15 is Personal Firewall Day, help the cause
    ... the>outside world which are in response to packets originating from ... to drop in a little Trojan, your whole network can be compromised. ... NAT router works at Layer 3. ... You still need a personal firewall or ...
    (Full-Disclosure)
  • Re: MSN WORKGROUP
    ... before my router is excess the folder very quickly suddenly it excess the ... Pls guide me how can i make it again this network. ... xp or firewall., secondly i can not find my wirefall optopn in control panel ... Problems sharing files between computers on a network are generally ...
    (microsoft.public.windowsxp.network_web)