Re: Using with DMZ, etc.

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




"Richard" <Richard@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:7340C7A4-4EB5-4066-AA8A-5F5532602CB6@xxxxxxxxxxxxxxxx
Not sure if this is the right forum so here it goes.

We are moving to regular server from SBS 2003. I would like to know
thoughts about having an FTP server in a DMZ so it would be accessable
from
the Internet. Would that be asking for security trouble?

Anything you expose to the world is an increased security risk, but having
an FTP server is not usually a giant one compared to many other things.

As long as you run a (reasonably) secure system and take good care of the
machine (Hotfixes etc.) it can work safely -- many people do it safely.

(I typically turn my FTP server off when not in active use though, because
we don't need it 24/7 -- note, I would run it if I had too, but don't really
need to do so.)

Also, would the
main server from the internal network replicate AD to the server in the
DMZ?

Almost never.

DCs don't belong on the network except in certain special cases where the
domain itself it used to support users who are out there too -- and only
done
when the admins really understand security fully.

Must better to let your DMZ machines query the DC through an INTERNAL
firewall when they wish to authenticate someone.

--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)


.



Relevant Pages

  • RE: Question about dmz security
    ... I'm no security guru, just a humble engineer, but when you ... allow a host in a DMZ to have direct access to the production network. ... then I'd recommend rules on your firewall to just let FTP to this host ... an ftp server sitting in our dmz. ...
    (Security-Basics)
  • Re: XP PRO Hack Attack--How?
    ... There is an entry in the Serv-U ini file called ... I put the VMWARE machine's IP address in the DMZ. ... machine was indeed an FTP server. ...
    (comp.security.firewalls)
  • Re: Hosting a FTP server
    ... Why do you want to put it in a DMZ? ... My concern is that adminisration of the FTP server running Windows 2003 ... Are the 55 clients on the 'outside' or on your LAN? ...
    (microsoft.public.windows.server.networking)
  • Re: Hosting a FTP server using Windows 2003 server
    ... Running a DC in the DMZ defeats almost all the reasons for having a DMZ ... My concern is that adminisration of the FTP server running Windows ... part of the domain on the LAN? ...
    (microsoft.public.windows.server.networking)
  • Re: Question about dmz security
    ... > plugged into the dmz hub and one is plugged into our network. ... It is a security risk, ... your users can use scp to access the FTP server. ... setting up an internal-only FTP server which gets rsync'ed to the ...
    (Security-Basics)