Re: virtual server authorization

From: David Wang [Msft] (someone_at_online.microsoft.com)
Date: 10/20/05


Date: Thu, 20 Oct 2005 04:44:36 -0700

Here are some thoughts on what "security" really means:
http://blogs.msdn.com/david.wang/archive/2005/09/30/Thoughts_on_IIS_Security_vs_Apache.aspx
http://blogs.msdn.com/david.wang/archive/2005/10/01/Thoughts_on_IIS_Security_vs_Apache_Part_2.aspx

If you are uneasy, I would suggest that you put two NIC in the server and
bind the administration website to the internal-facing NIC. Then, you can
trust in your network routing configuration skills to make sure that network
traffic goes to the right place.

Personally, if the administration site requires authentication, that's about
all the protection you need, even Internet facing.

-- 
//David
IIS
http://blogs.msdn.com/David.Wang
This posting is provided "AS IS" with no warranties, and confers no rights.
//
"Aric" <Aric.1x60ly@no-mx.forums.yourdomain.com.au> wrote in message
news:Aric.1x60ly@no-mx.forums.yourdomain.com.au...
I am currently about to launch an ecommerce solution for my company and
was wonder about securing the administration section.  Currently the
plans are to have the administration site in a virtual server using
windows authentication and restricted to local ips only.  While looking
at all the documentation I can find this should work perfectly I'm still
a little worried about having it on a server connected directly to the
net.  Anyone know of security flaws in IIS 6.0 running on w2k3 that
would allow users to get into the administration site?
-- 
Aric
------------------------------------------------------------------------
Aric's Profile: http://www.highdots.com/forums/m1128
View this thread: http://www.highdots.com/forums/t3038625


Relevant Pages

  • RE: Login Failure to Frontpage Admin
    ... compromise security to my websites and my server as the follwing procedure ... did popup a security message. ... My websites by default were ALL set to "Integrated Windows Authentication" ...
    (microsoft.public.frontpage.extensions.windowsnt)
  • security-basics Digest of: get.123_145
    ... VPN to ASP a security risk? ... Re: Multiple IPSec tunnels? ... Subject: Security NT Server ... VPN to ASP a security risk? ...
    (Security-Basics)
  • Re: << SBS News of the week - Sept 26 >>
    ... > And he points to the info you need to put the file on the server in the ... > at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... An attacker can exploit these flaws in tandem via specially ...
    (microsoft.public.backoffice.smallbiz2000)
  • << SBS News of the week - Sept 26 >>
    ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
    (microsoft.public.windows.server.sbs)
  • Re: << SBS News of the week - Sept 26 >>
    ... > And he points to the info you need to put the file on the server in the ... > at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... An attacker can exploit these flaws in tandem via specially ...
    (microsoft.public.windows.server.sbs)