"Reverse" proxy available. Any need to put web servers in DMZ ?

From: Marlon (marlon-nospam_at_hotmail.com)
Date: 06/16/05


Date: Thu, 16 Jun 2005 11:43:50 -0700

This is the discussion here:
I have ISA 2004 setup as a workgroup in the DMZ successfully publishing my
OWA 2003.
I have a web server (win2003, IIS6.0) that pulls data from a SQL 2000 db.
Such web server is currently in the "internal" network. Web server requires
no authentication.

In my view it makes more sense keep such web server as is in the internal
network and publish it via "ISA" to take advantages of HTTP filters and
other things ISA offers.

Instead, do you see any advantage security wise of moving such webserver to
the DMZ instead ? That will require a whole in the firewall to allow traffic
to the SQL db which resides in the internal network.

If you can help, advise on pros and cons of placing such web server in the
DMZ instead of keeping ISA->Web server(Internal).



Relevant Pages

  • Re: How vulnerable server will become if placed on DMZ ?
    ... >> I have a type of Web Server. ... > protect your internal network from a compromised web server. ... A DMZ can ... > network as compared to what you probably have now, a single firewall. ...
    (microsoft.public.win2000.security)
  • Re: I got a Web Publishing problem
    ... forward that to your ISA external listener on the 192.168.0.0 lan? ... is external network and 172.16.0.0 is internal network ... Web Server is windows 2003 ent and ISA Server is windows 2003 with ISA ...
    (microsoft.public.isa.publishing)
  • Re: DMZ Arguments....
    ... A DMZ is used with a firewall, ... link to the rest of the network. ... A common approach for an attacker is to break into a host that's vulnerable ... the case of a web server, unauthenticated and untrusted users might be ...
    (Security-Basics)
  • Re: Publish in DMZ : How ?
    ... In the internal LAN, on the ISA DMZ ... routable IP addresses on the DMZ segment? ... How do you want your clients to access the web server? ...
    (microsoft.public.isaserver)
  • Re: Watchguard firebox dmz webserver config
    ... you can use IP forwarding via Nat from external to dmz or use the real ... This poses more risk for your internal network, ... once an internal web server is hacked, your whole network is in danger. ... the webserver is using IIS on a W2000 box as well as MS SQL ...
    (comp.security.firewalls)