Re: Newbie's question on dmz

From: Adie (a_usenetizen@hotmail.com)
Date: 02/24/03


From: Adie <a_usenetizen@hotmail.com>
Date: Mon, 24 Feb 2003 01:13:35 +0000

MC wrote:

>Add a third network card for http, ftp servers etc, so this becomes the dmz,
>right? If that's the case, what IP address should I give it?
>Would I physically need another PC to run IIS or could I use the current Win
>2000 server?
>If the third nic needs to be publicly available then what happens to nic2
>(gateway card) as the internal PC requires internet access?

I'm no expert but you could buy a NATs router with some sort of DMZ
facility. Then stick the PC with IIS on another subnet so your LAN traffic
isnt broadcast to the IIS server. Or (cheap option) you could just use a
software firewall configured to allow connections to port 80 on the
webserver machine. Personally i'd go with a router/nats/swich combo and
use something like zone alarm or tiny on each machine (theyre free.)



Relevant Pages

  • Re: Steps to setup app allowing offsite network access using IIS Authe
    ... The first paras imply you want them to be able to _run_ a web app on an IIS server? ... Regardless of all that, one problem to look out for is that they won't have Active Directory if it's in a DMZ, so Integrated Authentication won't work, nor will Impersonation, You'd need to use plain text with SSL, nasty, and you'd need to pass the passwords as plain text if you want them to be able to start a process, unless you can get Kerberos working in the DMZ and able to pass the tickets over two hops. ... DMZ, there will be several steps involved - from compiling the application with a strong name, to setting up IIS and finally access to the application which will need to run on a server from the DMZ for our partners. ... Can anyone outline each step required to set this up on an IIS server in the network or DMZ along with the assembly requirements of the application to run on this network? ...
    (microsoft.public.vsnet.general)
  • Re: Security for Win2003 Servers
    ... It seems you have found the W2k3 hardening guide, ... I do not understand you choices for the IIS box. ... In is in the DMZ, ... Microsoft MVP (Windows Server System: ...
    (microsoft.public.win2000.security)
  • Re: Where to put the server
    ... I did end up placing the 2003 IIS box in the DMZ. ... > Put the 2003 IIS Server in the DMZ. ... > SBS box or another LAN server. ...
    (microsoft.public.backoffice.smallbiz2000)
  • RE: Setting up Exchange Server
    ... Exchange server in Lan, with IIS. ... Users have to use a 128 Bit SSL Link from client to Proxy in DMZ. ...
    (Security-Basics)
  • Re: Where to put the server
    ... then leave it on the server in the DMZ. ... I did end up placing the 2003 IIS box in the DMZ. ... >> SBS box or another LAN server. ...
    (microsoft.public.backoffice.smallbiz2000)

Quantcast