Use or Not to use ISA

From: Ron (Ron_at_discussions.microsoft.com)
Date: 05/21/05


Date: Fri, 20 May 2005 16:14:04 -0700

I am looking for advice on the best way to protect my web server.

I currently sit behind a Symantec Gateway 360 security appliance firewall
I have the following systems
2 Win2k3 DC's running active directory forwarding DNS requests to my ISP
with no recursion selected.
1 Win2k3 with IIS installed.
1 Win2k3 as a DHCP and Print server.
2 XP clients

I currently do consulting on a small scale and plan on hosting sites for a
small number of clients as well as my own.
I use my ISP's DNS services on the out side to route the sites to my public
IP address.
I have configured the firewall to allow for Ports 80 and 443 to be open and
point to my IIS server.
And have partitioned the drives of the IIS box which will hold the clients
sites and
have enabled web sharing for each client folder.
Have created separate web sites for each client using host header names.
Currently using 1 IP Address for all sites, will establish a separate IP
address each SSL site when necessary.

Would i be logical to run ISA on the IIS box for more security?
And what benefits would it give me?
Since i don't have the funds to place another firewall between the IIS box
and the rest of my internal network to create a DMZ.

A reply would be greatly appreciated.

Thanks
Ron



Relevant Pages

  • Re: IPTables Blocking Outbound by destination port.
    ... # firewall Firewall startup/shutdown script ... echo "firewall: ... # for each additional server running from 6000 to 6063. ... Clients may access remote POP-3 servers" ...
    (comp.security.firewalls)
  • Re: Being hacked...
    ... Are you offering a webserver and ftp server to users on the internet as per having ... FTP and HTTP open? ... For internet attacks what I would look for is patterns in the firewall ... I am not an expert on IIS by any means but I do know if you are using FTP and IIS you ...
    (microsoft.public.win2000.security)
  • Re: IIS 6.0 FTP
    ... if your ftp is working first. ... So, go to the remote machine (which allow to connect to your iis server), go ... The ftp server connection msgs you posted, doesn't look like IIS FTP to me. ... clients are using an order entry program created in Microsoft access. ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: IIS 6.0 FTP
    ... if your ftp is working first. ... So, go to the remote machine (which allow to connect to your iis server), go ... The ftp server connection msgs you posted, doesn't look like IIS FTP to me. ... clients are using an order entry program created in Microsoft access. ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: IIS 6.0 FTP
    ... does not look like the behavior of an IIS FTP server. ... By default, IIS FTP ... using the clients username and password, ...
    (microsoft.public.inetserver.iis.ftp)