Welcome to HostingForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Web Server in DMZ

 
   Web Hosting Problem Solving Community! (Home) -> IIS RSS
Next:  2 Servers IIS on one and data on the other???  
Author Message
user940

External


Since: Oct 09, 2003
Posts: 4



(Msg. 1) Posted: Thu Mar 18, 2004 12:10 am
Post subject: Web Server in DMZ
Archived from groups: microsoft>public>inetserver>iis (more info?)

Hello All:

Is it advisable to have your web server a member of your domain and residing
in the DMZ. Does this pose a greater risk than if it was not? What are the
minimum port(s) needed to allow authetication from DMZ.

Thanks

 >> Stay informed about: Web Server in DMZ 
Back to top
Login to vote
user658

External


Since: Aug 26, 2003
Posts: 1525



(Msg. 2) Posted: Thu Mar 18, 2004 5:03 pm
Post subject: Re: Web Server in DMZ [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Wed, 17 Mar 2004 21:10:20 -0500, "stan" <no.DeleteThis@email.com> wrote:

 >Is it advisable to have your web server a member of your domain and residing
 >in the DMZ.

No. Make it a standalone server in a wrokgroup.

 >Does this pose a greater risk than if it was not?

A compromised domain member server has more access than a compromised
stand alone server.

 > What are the
 >minimum port(s) needed to allow authetication from DMZ.

How are you authenticating and is the system in a DMZ a DC? A better
option would be authenticating to a local account and if needed
passing that to the internal system for access, but all this really
deoends on what you really need to accomplish.

Jeff<!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: Web Server in DMZ 
Back to top
Login to vote
user1532

External


Since: Mar 18, 2004
Posts: 1



(Msg. 3) Posted: Thu Mar 18, 2004 5:03 pm
Post subject: Re: Web Server in DMZ [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thanks for the reply

Have a web server already part of our domain (not a dc) and want to move it
out to the DMZ. The web guy is having a fit because there are numerous apps
etc running on it that rely on domain accounts. He would rather it remain a
member, and open those ports necessary on the friewall to allow this. I say
it's not worth the security that will be sacraficed.


"Jeff Cochran" <jcochran.nospam.RemoveThis@naplesgov.com> wrote in message
news:405ca733.82408627@msnews.microsoft.com...
 > On Wed, 17 Mar 2004 21:10:20 -0500, "stan" <no.RemoveThis@email.com> wrote:
 >
  > >Is it advisable to have your web server a member of your domain and
residing
  > >in the DMZ.
 >
 > No. Make it a standalone server in a wrokgroup.
 >
  > >Does this pose a greater risk than if it was not?
 >
 > A compromised domain member server has more access than a compromised
 > stand alone server.
 >
  > > What are the
  > >minimum port(s) needed to allow authetication from DMZ.
 >
 > How are you authenticating and is the system in a DMZ a DC? A better
 > option would be authenticating to a local account and if needed
 > passing that to the internal system for access, but all this really
 > deoends on what you really need to accomplish.
 >
 > Jeff<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Web Server in DMZ 
Back to top
Login to vote
user658

External


Since: Aug 26, 2003
Posts: 1525



(Msg. 4) Posted: Thu Mar 18, 2004 11:46 pm
Post subject: Re: Web Server in DMZ [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Thu, 18 Mar 2004 12:35:22 -0500, "stan" <no.DeleteThis@spam.com> wrote:

 >Have a web server already part of our domain (not a dc) and want to move it
 >out to the DMZ. The web guy is having a fit because there are numerous apps
 >etc running on it that rely on domain accounts. He would rather it remain a
 >member, and open those ports necessary on the friewall to allow this. I say
 >it's not worth the security that will be sacraficed.

You're sacrificing secuirty one way or the other anyway.

Jeff

 >"Jeff Cochran" <jcochran.nospam.DeleteThis@naplesgov.com> wrote in message
 >news:405ca733.82408627@msnews.microsoft.com...
  >> On Wed, 17 Mar 2004 21:10:20 -0500, "stan" <no.DeleteThis@email.com> wrote:
  >>
   >> >Is it advisable to have your web server a member of your domain and
 >residing
   >> >in the DMZ.
  >>
  >> No. Make it a standalone server in a wrokgroup.
  >>
   >> >Does this pose a greater risk than if it was not?
  >>
  >> A compromised domain member server has more access than a compromised
  >> stand alone server.
  >>
   >> > What are the
   >> >minimum port(s) needed to allow authetication from DMZ.
  >>
  >> How are you authenticating and is the system in a DMZ a DC? A better
  >> option would be authenticating to a local account and if needed
  >> passing that to the internal system for access, but all this really
  >> deoends on what you really need to accomplish.
  >>
  >> Jeff
 ><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Web Server in DMZ 
Back to top
Login to vote
Display posts from previous:   
   Web Hosting Problem Solving Community! (Home) -> IIS All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]