Re: Prividing Intranet Website Access To External Users

From: Gabriel Orozco (gabriel_orozco_at_mx.sumida.com)
Date: 02/07/05

  • Next message: Mike Sweeney: "RE: Transparent Anti spam and virus web/mail/ftp Proxying on a Bridge"
    To: "rusty chiles" <rustychiles@gmail.com>, <security-basics@securityfocus.com>
    Date: Mon, 7 Feb 2005 13:09:50 -0600
    
    

    I would install a reverse proxy, like apache, just connect to the internal
    web server and the firewall filter every other traffic.

    ----- Original Message -----
    From: "rusty chiles" <rustychiles@gmail.com>
    To: <security-basics@securityfocus.com>
    Sent: Friday, February 04, 2005 6:16 PM
    Subject: Prividing Intranet Website Access To External Users

    > Greetings,
    >
    > I'm asking for reccomendations with the following Scenario:
    >
    > We have a internal intranet site. Users are authenticated using their
    > nt credentials.
    >
    > We need to provide the site externally, translate the internal links
    > to external links, and still pass their NT credentials to the website.
    >
    > MGMT wants to do this without vpn, or any other 3rd party software on
    > the clients computer.
    >
    > The goal here is a single user sign on, so that the end user is
    > presented with the same experience at home as they are at work.
    >
    > We WILL use SSL to protect the transportation of the userid and password.
    >
    > The web server is IIS on windows2003.
    >
    > The web server will be in the DMZ, and only port 443 will be allowed
    > from the outside world.
    >
    > The problem is that webserver in the dmz will need to have the ability
    > to talk to the domain controller, as well as a sql server.
    >
    > I prefer my resources be separated, and never have internal servers
    > traverse the dmz, but in this case that is not possible due to a
    > dependency on the website having tight integration with Active
    > directory resources.
    >
    > We could put a sql box in the dmz, but a domain controller....... I
    > don't feel comfortable doing that. One box in the dmz is compromised,
    > then the DC is open to direct attack.
    >
    > If the box talks from the dmz to the internal Domain controller, we
    > can acl the traffic so that it only talks over limited port numbers;
    > however there is still some risk involved. (which we may have to
    > accept)
    >
    > What experience have members of this list had with publishing their
    > intranets to the internet in a secure manner.
    >
    > What has worked reliably, and still provided solid security.
    >
    > I've considered a SSL VPN type portal, ISA Server, and the like as
    > well as several forwarding proxies, but am not 100% comfortable with
    > any of the solutions I have seen thus far.
    >
    > Any reccomendations List members can make will be helpful to us.
    >


  • Next message: Mike Sweeney: "RE: Transparent Anti spam and virus web/mail/ftp Proxying on a Bridge"

    Relevant Pages

    • Re: Can I run an Internet web server from a Win2K computer?
      ... You can deffinately run an internet website from IIS on Windows 2000 Pro., ... I'm trying to use the web server that comes with Windows 2000 ...
      (microsoft.public.win2000.general)
    • Re: External website unavailable from inside
      ... Our internet is working fine, but i just can't reach our website which is ... Is your web server on your network or your ISP's? ...
      (microsoft.public.windows.server.dns)
    • Exchange 2007 since Service Pack 1 installed OWA not working
      ... The timeout may have occurred due to Internet congestion. ... Contact website: You may want to contact the website administrator to ... The connection to the Web server was lost. ... Nubie to Exchange so any help gratefully received. ...
      (microsoft.public.exchange.admin)
    • You are not authorized to view this page - HTTP Error 403.6
      ... When attempting to access a SBS website from the internet I receive the following error: ... The Web server you are attempting to reach has a list of IP addresses that are not allowed to access the Web site, and the IP address of your browsing computer is on this list. ... RDC & Sharepoint sites work externally but this business website doesnt. ...
      (microsoft.public.windows.server.sbs)
    • SSL web page not working from LAN
      ... I have currently setup a web server in the DMZ which has ... web page from the internet and it works fine. ... Cannot find server or DNS Error ...
      (microsoft.public.inetserver.iis.security)