Re: virtual server authorization
From: David Wang [Msft] (someone_at_online.microsoft.com)
Date: 10/20/05
- Next message: johnpaul.temple_at_gmail.com: "Re: Building a Windows 2003 DMZ Server without ISA"
- Previous message: Tymbow: "Re: IIS 6.0, Host Headers and SSL"
- In reply to: Aric: "virtual server authorization"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 20 Oct 2005 04:44:36 -0700
Here are some thoughts on what "security" really means:
http://blogs.msdn.com/david.wang/archive/2005/09/30/Thoughts_on_IIS_Security_vs_Apache.aspx
http://blogs.msdn.com/david.wang/archive/2005/10/01/Thoughts_on_IIS_Security_vs_Apache_Part_2.aspx
If you are uneasy, I would suggest that you put two NIC in the server and
bind the administration website to the internal-facing NIC. Then, you can
trust in your network routing configuration skills to make sure that network
traffic goes to the right place.
Personally, if the administration site requires authentication, that's about
all the protection you need, even Internet facing.
-- //David IIS http://blogs.msdn.com/David.Wang This posting is provided "AS IS" with no warranties, and confers no rights. // "Aric" <Aric.1x60ly@no-mx.forums.yourdomain.com.au> wrote in message news:Aric.1x60ly@no-mx.forums.yourdomain.com.au... I am currently about to launch an ecommerce solution for my company and was wonder about securing the administration section. Currently the plans are to have the administration site in a virtual server using windows authentication and restricted to local ips only. While looking at all the documentation I can find this should work perfectly I'm still a little worried about having it on a server connected directly to the net. Anyone know of security flaws in IIS 6.0 running on w2k3 that would allow users to get into the administration site? -- Aric ------------------------------------------------------------------------ Aric's Profile: http://www.highdots.com/forums/m1128 View this thread: http://www.highdots.com/forums/t3038625
- Next message: johnpaul.temple_at_gmail.com: "Re: Building a Windows 2003 DMZ Server without ISA"
- Previous message: Tymbow: "Re: IIS 6.0, Host Headers and SSL"
- In reply to: Aric: "virtual server authorization"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|