Re: Hardware VPN: 2 NICS --> 1 NIC - Non-Profit Needs HELP!



Thank you to everyone who posted. The computers have been successfully
setup at the new Boys & Girls Club and I plan to setup a Server 2003
box their to keep WAN traffic down. I have 1 issue with true
connectivity, but I am going to post that as a new topic since it is a
different from what we have talked about in this posting. THANKS ALL.
Joe wrote:
bkbgc1@xxxxxxxxx wrote:
DUALLY NOTED. Took it off DMZ.

What is the difference between doing a DMZ to a sbs2k3 and having a 2
NIC static ip. Oh. LOL. I just answered my own question.

Thank you Joe!

Any other tips would be great!


There would be no real problem with keeping your original
layout, but adding the router between modem and SBS. Two
levels of NAT are not a problem, and the router (with only
the necessary ports open) will keep most of the basic
automated probes away from the SBS, reducing the software
load on it and also the chances of being compromised by
a security bug. Two different firewalls, even if one is
fairly primitive, offer more protection than one.

Specifically, most 'firewall' problems are caused either
by their being left off or misconfigured, and this gives
an extra safety net. And while it's rare for a commercial
firewall/router to have a security vulnerability, it isn't
unknown.

The problem with what you did was that, while the LAN services
of the SBS have some protection against attack, they are not
sufficiently hardened to be safely exposed to the Internet.
The misnamed 'DMZ' feature of some firewalls simply forwards
all incoming connections to one machine on the LAN, which is
not usually capable of defending itself. While the outer NIC
of a 2-NIC SBS has a fairly useful firewall, the inner one
cannot.

.



Relevant Pages

  • Re: Hardware VPN: 2 NICS --> 1 NIC - Non-Profit Needs HELP!
    ... What is the difference between doing a DMZ to a sbs2k3 and having a 2 ... but adding the router between modem and SBS. ... The problem with what you did was that, while the LAN services ... The misnamed 'DMZ' feature of some firewalls simply forwards ...
    (microsoft.public.windows.server.sbs)
  • Re: The chicken or the egg?
    ... Different scenarios to reinstall Companyweb after the SBS 2003 SP1 setup ... After SBS 2003 SP1 Standard installation, if Companyweb is uninstalled by ...
    (microsoft.public.windows.server.sbs)
  • Re: Inherited botched w2k3 SBS install, is this recoverable?
    ... continue installing rest of the SBS Components. ... Server Setup. ... Microsoft Windows Small Business Server Setup, ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: Setting up exchange server
    ... If you ever decide to try again with SBS then come back to this ... backup, the server came with Symantec Backup Exec 10d Small Business Server ... your SBS setup but get it done right. ...
    (microsoft.public.windows.server.sbs)
  • RE: upgrade from sbs 2000 setup hangs?
    ... Thank you for posting in SBS newsgroup. ... checked setup requirements. ... If you encounter any error or warning message during the upgrade, ...
    (microsoft.public.windows.server.sbs)