Re: Secure Web Browsing via Terminal Server/Citrix

From: Duane Arnold (notme_at_notme.com)
Date: 10/17/05


Date: Mon, 17 Oct 2005 00:00:19 GMT


"rot-eron" <rotero2@yahoo.com> wrote in news:1129497662.548012.222370
@g44g2000cwa.googlegroups.com:

> Hi,
>
>
> I recently came across a unique security architecture in an Insurance
> Firm I am dealing with. They put a Citrix/TS farm in their DMZ, hosting
> only IE and closed outbound port 80/443.
>
> This way, internal users can *not* access the web, unless they use the
> TS, which is easier to manager, easier to secure, and sits in the DMZ -
> without access to the internal network. The additional benefit is that
> the internal network is, in a way, separate/disconnected from the
> Internet - with all the security benefits associated with that.
>
> Has anyone seen this elsewhere?
> What do you think of this approach to solving the browsing
> security-related problems?
>

No and I have worked in a Citrix Terminal Server Farm situation. It
sounds kind of rediculous.
 
Duane :)



Relevant Pages

  • Re: Exchange server in DMZ, not FE server. Is this ever ok?
    ... It will turn out that it doesn't add value in terms of security ... If I hear you as saying having a firewall present is without value, ... NICs - one for the internal network, and the other for the DMZ. ...
    (microsoft.public.security)
  • Secure Web Browsing via Terminal Server/Citrix
    ... I recently came across a unique security architecture in an Insurance ... TS, which is easier to manager, easier to secure, and sits in the DMZ - ... the internal network is, in a way, separate/disconnected from the ... Internet - with all the security benefits associated with that. ...
    (comp.security.firewalls)
  • One-way trust between Internal network and DMZ
    ... WE are going to build a separate W2K domain in DMZ and have a one way trust ... between internal network and DMZ. ... Are there and security concerns? ...
    (microsoft.public.win2000.active_directory)
  • Re: DMZ NT4 TO Internal 2000 AD One-Way Trust via Firewall
    ... leverage an effectivity security policy to ensure that password complexities ... > currently a mess of local and domain users, no security policy, etc. ... DMZ, not publicly accessible) that aren't going away within the stated ... to non-DC web servers in the DMZ on 80 and 443 - none of which are directed ...
    (microsoft.public.windows.server.active_directory)
  • Re: slightly off topic - flaws in using win2k for wireless security and openbsd replacing
    ... > Hi UNIX security professionals and hobbyists, ... > Basically, we have our wired internal network, then we have a dual-NIC ... > win2k server that acts as a Microsoft PPTP VPN server, ... > The problem I see is, anybody can connect to the wireless access point ...
    (comp.security.unix)