DMZ boxes in the domain

From: Gene (btraquer@att.net)
Date: 02/26/03

  • Next message: Shackleford, Dave: "RE: Utility to determine who deteled files"
    Date: Wed, 26 Feb 2003 13:37:10 +0700
    From: Gene <btraquer@att.net>
    To: focus-ms@securityfocus.com
    
    

            We're considering adding the DMZ Win2K/IIS servers to the
    internal domain. This sounds like a rather dangerous thing to do, but
    while discussing this we came up with an idea of giving the box 2 NICs,
    one a DMZ address and the other an internal address and disabling all
    routing between the 2 NICs. Hopefully, in this scenario we can still
    manage the Win2K normally via the domain while permitting the box to
    serve out our site. If the box is compromised from the DMZ side, in
    theory, this wouldn't allow the compromise to affect the internal network.

         Ideas/thoughts/concerns...

    All helps appreciated!!



    Relevant Pages

    • Re: ISA 2006 placement - looking for advice
      ... Thanks for the reply - wasn't looking to replace my existing firewall, ... Put it in DMZ with both NICs in the DMZ? ... "Bridge" between the DMZ segment and the internal segment? ...
      (microsoft.public.isa)
    • Re: ISA 2006 placement - looking for advice
      ... Thanks for the reply - wasn't looking to replace my existing firewall, ... Put it in DMZ with both NICs in the DMZ? ... "Bridge" between the DMZ segment and the internal segment? ...
      (microsoft.public.isa)
    • Edge Server 2 Nics vs 1 Nic
      ... He plans to use two NICs. ... connected to the DMZ. ... "This is the recommeded configuration by MS" he said. ...
      (microsoft.public.exchange.design)
    • Re: Edge Server 2 Nics vs 1 Nic
      ... How about a case in which an ET have two NICs, each homed on a different ISP ... really written that MS IT use 2 NICs per edge server within one perimeter ... server using only one NIC with the recommended configuration (open ports ... And what about a second DMZ? ...
      (microsoft.public.exchange.design)
    • Re: Win3k Forest Trusts
      ... Can you list users from internal domain on DC in DMZ for test? ... > We are trying to setup a trust between our DMZ and Internal network. ... > (firewall disabled). ...
      (microsoft.public.windows.server.setup)