Re: Joining web server to SBS domain - any pre-cautions?



In article <Orqdb534IHA.776@xxxxxxxxxxxxxxxxxxxx>, "Mike" <none> says...
Hi All,

We are running SBS 2003 Standard SP2 with exchange.

I'm trying to plan for joining our web server (Server 2003 Std. installed)
to our SBS domain. The web server is live and hosting our website at the
moment.

I don't know enough about IIS to foresee any prolems that may arise with the
account profile changeover. Any thoughts to consider or suggestions would be
much appreciated. Thanks so much in advance.

Putting ANY webserver on the same network as your company files is a
very bad idea and is a very good way to get hacked and then compromised.

You should have a REAL FIREWALL APPLIANCE, not just a NAT Router.

Real firewalls provide multiple physical networks that are isolated from
each other and only permit traffic by user created rules.

A single public IP can provide HTTP access for the DMZ Network and also
provide HTTPS access to the LAN without the outsiders knowing the
difference.

If you firewall has a DMZ and it's in the same Subnet as the LAN, then
it's not a firewall.

A typical LAN would be 192.168.3.1/24 with
a typical DMZ being 192.168.8.1/24

They are isolated from each other by default.

The only rule would be:

Allow HTTP LAN > DMZ (web erver IP)
Disallow ANY DMZ > LAN



--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@xxxxxxxxxx (remove 999 for proper email address)
.



Relevant Pages

  • Re: DMZ and file sharing
    ... Never ever use DMZ, a) its an open unlocked door with a big sign saying your ... save/retreive files to/from a restricted area on the LAN. ... and only server. ... You need to consider the safety of the LAN when the web server gets ...
    (microsoft.public.windows.server.sbs)
  • Re: Joining web server to SBS domain - any pre-cautions?
    ... Yes, I have a REAL FIREWALL and i know what a DMZ is, thank you very much. ... A single public IP can provide HTTP access for the DMZ Network and also ... If you firewall has a DMZ and it's in the same Subnet as the LAN, ...
    (microsoft.public.windows.server.sbs)
  • Re: Adding a web server to my network
    ... I have a LAN behind a hardware firewall connecting to the web by DSL. ... I would like to keep my LAN safe from hackers, and my web server safe ... region is called the DMZ, which is where you put your web ...
    (comp.os.linux.misc)
  • RE: DMZ - Question
    ... FW-2 to a different brand that has stateful inspection. ... DMZ to communicate with the inside LAN by NATting in the ... On the DMZ we will have a Web Server that needs access back ...
    (Security-Basics)
  • Authentication on a web server via AD
    ... But I have som rules that I have to follow. ... The web server is located on a dmz ... The active directory controller is located on lan ... I can not open any port from dmz to lan ...
    (microsoft.public.isa)