RE: Adding a Win2K member server

From: Jonathan Lotman [MSFT] (a-jonlot_at_online.microsoft.com)
Date: 10/08/04


Date: Fri, 08 Oct 2004 21:42:30 GMT

Here's one option for configuring your network, if you have SBS2003 Premium
and have ISA installed other options may be available. This solution will
require another /30 block of IPs from your ISP (4 IP addresses, 2 usable).
Configure the router with one of the IPs from the new block, and configure
the LAN side of the router to use your existing block of IP addresses. Now
you should be able to put both your Servers behind the router/firewall, and
the Win2k server can be joined to the domain. You will need to forward
ports 25, 80, 443, 1723 (if you are using VPN) and 4125 to the SBS2003
server, and 80 and 443 to the Win2k server. Once this configuration is in
place, you can set up your external DNS as needed.

As far as the public web site is concerned, external hosting is usually
preferable. If you are committed to hosting it locally, there are pros and
cons to either approach. You will need to weigh the considerations and
determine which is better for you. SBS2003 with IIS6 affords a higher
level of default security, but it is run on your domain controller, which
is a risk of greater damage should a compromise occur. Conversely, running
the public website on the Win2k Server is lower security, but may reduce
the collateral risk in the event of a compromise.

Thank you,
--------------------------
Jonathan Lotman
Microsoft Online Support Engineer

Microsoft Corporation
Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================

--------------------
| From: "Steve" <nospam@nospam.lan>
| Subject: Adding a Win2K member server
| Date: Thu, 7 Oct 2004 08:32:20 -0700
| Lines: 51
| Newsgroups: microsoft.public.windows.server.sbs
|
| We have a Win2k server that we used to use as our office server. It was
the
| only server on that network. It has users setup with the same user names
as
| our new SBS2003 network. The server has a SharePoint site that my board
of
| directors and staff use on a daily basis from their homes and places of
| business. The site is password protected.
|
| I have setup an SBS2003 network and things are working very well. I'd
like
| to add the Win2k server to the SBS2003 network for a few reasons:
|
| 1. We would like to use it's hard drive space.
| 2. It is already setup as a Symantec Antivirus Server (currently I just
| have the Symantec client software installed on my workstations and new
| server)
| 3. We might want to host our public web site on it.
|
| My office is setup like this: Currently I have a cable modem with a hub
| attached. I have two routers attached to the hub. I have the external
| network card on the SBS2003 server connected to one router and the one
and
| only network card in the Win2k server connected to the other router.
Each
| router has a static IP assigned to it and I use port forwarding on them.
I
| have purchased a package of 5 static IP addresses from my ISP. I
purchased
| SBS because it's easy to use and we have way too small of a staff (3) to
| warrant a dedicated IT department. So, like many small originations, I'm
it
| and I don't have a whole lot of experience with servers. I can learn
from
| reading and can follow directions. So I'm looking for some advice or
| articles on how to accomplish this. Once I accomplish adding it to the
SBS
| Domain I'm sure I'll have other questions regarding Domain registration
and
| IIS.
|
| Extra Information that may or may not be useful:
|
| Our public web site is hosted by our ISP www.companyname.org (we'd like
to
| host it here preferably on the SBS2003 server because of IIS6 and some
| FrontPage 2003 features. If the advice from this group says security is
a
| huge risk then we would like to host it on the Win2k server using IIS5
and
| some of the FrontPage 2002 extensions.)
|
| We registered a new name (different than our web site) for our SBS2003
| network so users can access the RWW by typing in the
| https://company_initials.org/remote.
|
| Our board of directors and staff type the IP address of the Win2k server
| network to access the SharePoint site. (we'd like to improve this some
how
| with maybe just have them type http://compnayinitials.org to hit it?
|
| Any help would be greatly appreciated.
|
| TIA
| Steve
|
|
|



Relevant Pages

  • Re: Fully parallel Scheme-based language w/ evaluator
    ... Windows Server 2003 and networks in simple - and irreverent - terms. ... If networking really is a big deal, ... Concepts and Terminology in Part I, and The Design and Deployment of Network ...
    (comp.lang.misc)
  • Re: Outgoing POP3 email missing/lost/not received
    ... Funny thing is that I have had this ISP for 8 years and it has always been ... It looks like when you last ran CEICW, you set the ISP's mail server to: ... Internet Connection Wizard. ... After the wizard completes, the following network connection ...
    (microsoft.public.windows.server.sbs)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.general)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.dns)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.networking)