Re: Hosting public web site in SBS2003

From: Mark Mancini (info_at_NOSPAMmcse2000.com)
Date: 06/11/04


Date: Thu, 10 Jun 2004 23:16:15 -0400

AppLauncher is why my accounting firms use and ProSystems is looking into
endorsing as for TS it locks down the server. But to host on your SBS?!?!
No way, all my clients host on my colocated box that is professionally
managed for 99.9999% uptime. OWA is ok with https/ssl, RWW is just like TS
except that you are letting them access everything except what you want and
some firms may not want that freedom. Something to think of.

-- 
Sincerely,
Mark Mancini, CCA, CCNA, Master CIW&CI, CNE 4&5, MCSE+I 4&2000
www.MCSE2000.com
www.AppLauncher.com
"Buddy Greenshield" <gcsbend-at-bendcable-dot-com> wrote in message
news:uGN6fyyTEHA.2580@TK2MSFTNGP12.phx.gbl...
> Yeah, I hear you! Spyware has really been a pain lately.
>
> They are a small accounting firm. The apps are Creative Solutions
> Accounting, CBS and UltraTax.
> So some pretty personal stuff.
>
> My question was more of "Accept the risk" because with SBS2K3 and ISA
> server, the use of SSL and security improvements in general, is the level
of
> risk going down?  I'm telling him all about OWA and RWW and these other
web
> based features of SBS2K3. Are'nt these acceptable to deploy? I'm doing it
> already!
>
> If it were my site, I would probably outsource. But he wanted to do this,
so
> that's why I have posted to this NG.
>
> Buddy
>
> "Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]" <sbradcpa@pacbell.net>
> wrote in message news:%236XmlUyTEHA.972@TK2MSFTNGP10.phx.gbl...
> > Buddy?  What kind of firm data does he have on his server?  Client
> > resposibility?  Data responsibilty?
> >
> > The answer to whether he hosts a "local soccer club" web site on his box
> > is not "can it be done" as it can....but more of "what other data is he
> > putting into a potential for risk and can he mitigate that risk?
> >
> > Accept the risk
> > Mitigate the risk
> > Outsource the risk
> >
> > In my office I cannot accept the risk.
> >
> > To mitigate the risk in my firm I would put a separate server on the
> > side, set up a DMZ, ensure only web traffic went on that box... patch
> > immediately... watch the log file... for me it's way cheaper to
> >
> > Outsource the risk.
> >
> > What data does he have on the box.. and what level is he willing to do.
> >
> > That said, right now my server is the least of my worries.  They [the
> > nasties/spybots and what not] are going after my desktops.
> >
> > Buddy Greenshield wrote:
> > > I'm talking to a client who currently runs a W2K server as his DC and
TS
> in
> > > application mode about ugrading to SBS2003 premium. The main benefit
is
> to
> > > bring exchange into the mix.
> > >
> > > As part of the upgrade, he wants to host a web site for a local soccer
> club.
> > > I know that with SBS2000, the consensus is not to run an external web
> site
> > > from your SBS.  However, with SBS2003 and it's ease of setting up
> > > certificate based web access, has the consensus changed on the issue?
> > >
> > > Also, I have heard that SBS2003 no longer supports TS in app mode.
What
> are
> > > the alternatives?  I can see keeping the old W2K server demoted to
> member
> > > server. What other alternatives exist? (I'm not sure about the app
> running
> > > on the TS. It's client / server, but it might use database technology
> that
> > > would make things undesirable to run across a wan link.)
> > >
> > > Thank you
> > >
> > > Buddy G
> > >
> > >
> >
> > -- 
> > http://www.sbslinks.com/really.htm
> >
>
>


Relevant Pages

  • Re: Possible virus? But nothing detected
    ... Internet, you're running some risk. ... I don't host public webservers on my client's networks (all I open up is OWA ... mail server then anyone who sends e-mail will be able to lookup a MX ... antivirus/antispam software) with the POP connector. ...
    (microsoft.public.windows.server.sbs)
  • Re: Hosting public web site in SBS2003
    ... They are a small accounting firm. ... My question was more of "Accept the risk" because with SBS2K3 and ISA ... Buddy ... What kind of firm data does he have on his server? ...
    (microsoft.public.windows.server.sbs)
  • Re: The legal / illegal line?
    ... leaving you liable to pay the firm. ... there is the issue of risk. ... > Need to secure your web apps? ... > Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • RE: The legal / illegal line?
    ... I have no issue with you scanning with permission and if you can get ... leaving you liable to pay the firm. ... there is the issue of risk. ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Nessus & Webmin Security Questions
    ... *** Nessus reports this vulnerability using only ... and on the server side the nessusd with version 1.2.7. ... unknown High It is possible to read ... Risk factor: High ...
    (Debian-User)