Web server placement in DMZ

From: gmoney1616 (toms1616_at_optonline.net)
Date: 05/29/04


Date: 29 May 2004 07:34:52 -0700

Hi-

I'm going to be rolling out a website and would like to protect the
internal network.. I see that placing a webserver in a dmz is safest..
Right now this web server is part of a domain, should I remove the
webserver from the domain and create a workgroup or leave it joined in
a domain.. I assume leaving it in a domain is not safe,,, Or should I
rebuild this server as a new dc and wen server and then place it in
the DMZ?..

I want to protect our internal network so I'm trying to figure out the
safest way..

BTW it goint to be IIS6 W2k3 server..

Thanks,
TOM



Relevant Pages

  • RE: Firewalling with a webserver and DB
    ... But the DB on the internal network. ... only allow port 80 into your DMZ IF all you have are ... As clients computers will use these ports dynamically to talk to ... Firewalling with a webserver and DB ...
    (Security-Basics)
  • Impossible?
    ... My internal network is devided into a "normal" lan part and one dmz part. ... I've got trustix 1.5 with 2.4.17 kernel and iptables 1.2.5 to act as ... really need to be able to surf to the other sites on my webserver too. ...
    (comp.os.linux.security)
  • Impossible?
    ... My internal network is devided into a "normal" lan part and one dmz part. ... I've got trustix 1.5 with 2.4.17 kernel and iptables 1.2.5 to act as ... really need to be able to surf to the other sites on my webserver too. ...
    (comp.security.firewalls)
  • Re: Impossible?
    ... > My internal network is devided into a "normal" lan part and one dmz part. ... > really need to be able to surf to the other sites on my webserver too. ... I guess you are using iptables to forward port 80 from the firewall ...
    (comp.security.firewalls)
  • Re: Impossible?
    ... > My internal network is devided into a "normal" lan part and one dmz part. ... > really need to be able to surf to the other sites on my webserver too. ... I guess you are using iptables to forward port 80 from the firewall ...
    (comp.os.linux.security)