Re: TS in a DMZ

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Edmund Davis (edmund_davis_at_nospam.hotmail.com)
Date: 02/05/04


Date: Thu, 5 Feb 2004 15:45:29 -0000

Hi Keith,

My opinion is that it's certainly possible but probably isn't secure -
especially if you are running a web server on the same system.

In order to do it, you would have to create a rule in the firewall to allow
traffic (Netbios, kerberos etc) from the terminal server to the internal
network which would obviously also allow traffic from the web server to the
internal network so, if the web server was compromised, it could be used to
attach the internal network.

Security is not an exact science so there may be other opinions but I
suggest that you can publish a terminal server (using just port 3389) but
you would want to make sure that it wasn't accessible in any other way -
http or otherwise.

Regards,

"Keith" <@.> wrote in message news:O7AAed86DHA.2056@TK2MSFTNGP10.phx.gbl...
> I have a spare server here that I was going to install 2k on and put it in
> my DMZ to use as a web server.
>
> I just got to thinking whether it would be possible without breaching DMZ
> security to put Terminal Services on this machine in such a way that a
user
> logging into TS could access their resources (files/email/printers)
located
> on a server on our LAN.
>
> Any one know if this is (a) possible and (b) secure?



Relevant Pages

  • Re: Good Read for Web Server Admins
    ... distribution and how anyone can be part of the problem. ... my opinion. ... They don't have to compromise your web server for you to be ...
    (Fedora)
  • Re: Best way of developing simple PPC apps for Unix types?
    ... which I would like to be the same on the web server and the PPC), ... display data in a tabular form, allow selection of an item and display ... The truth is the truth, and opinion just opinion. ...
    (microsoft.public.pocketpc.developer)
  • Re: Web Server
    ... What's your opinion? ... > Jack Daniels wrote: ... > The risk is proportional to the web server and the modules you run. ... > packet filter will protect your web server if you open port 80. ...
    (comp.security.firewalls)
  • Re: Web Server
    ... What's your opinion? ... > Jack Daniels wrote: ... > The risk is proportional to the web server and the modules you run. ... > packet filter will protect your web server if you open port 80. ...
    (comp.security.firewalls)
  • pass only bind plus redirect web
    ... web server that explains why they are not seeing the real ... So I have been playing with ipnat maps and ipf filters to just let ... With ae1 the internal network and ae0 ...
    (comp.security.firewalls)