Re: AD for webhosting?

From: karl [x y] (jamescagney90210@excite.com)
Date: 08/15/02


From: "karl [x y]" <jamescagney90210@excite.com>
Date: Thu, 15 Aug 2002 06:17:31 -0400


"P" <sdfsd@sdfsd.com> wrote in message
news:_mI69.13039$Cq.523323@ozemail.com.au...
> We host a few win2k webservers. Until now we have made them standalone
> servers in their own little workgroup. However we want to implement
standard
> IPSEC policies for some traffic and be able to apply security
configuration
> templates centrally.
>
> But we are concerned about AD on public hosted servers. We use AD for our
> internal network, but I don't feel comfortable with it in the hosted
> environment.

If you only have a few win2000 servers, I don't really see the benefit of
implementing AD, especially since ideally you'd want these to be on at least
two additional non-web servers, which adds expense. You could use simple
batch files and/or scheduled tasks to copy Group policy templates containing
IPsec policies and apply them using the SECEDIT command.

I don't think this is the ideal way to modify existing filters, but I
believe another way to distribute IPsec filters is by using IPSECPOL from
the windows 2000 resource kit and
possibly available for free download from www.microsoft.com/download
Utility described at:
http://www.google.com/search?hl=en&ie=ISO-8859-1&q=windows-2000+ipsec+comman
d-line+filters+apply



Relevant Pages

  • Re: Web App Security Model.
    ... SQL permissions are correctly restrictive (so worse case the allowed ... If these machines are standalone the threats posed by them are ... applications / implementation and whether their design has ... My company wants to have a few Windows Servers running web app's (ASPX ...
    (microsoft.public.security)
  • Re: Web App Security Model.
    ... If these machines are standalone the threats posed by them are ... My company wants to have a few Windows Servers running web app's (ASPX ... For the time being there wont be a Firewall between the servers and the ... so we aren't in a DMZ type environment. ...
    (microsoft.public.security)
  • AD for webhosting?
    ... Until now we have made them standalone ... IPSEC policies for some traffic and be able to apply security configuration ... But we are concerned about AD on public hosted servers. ...
    (microsoft.public.win2000.security)
  • COM+ App Proxying With Windows 2003
    ... We have two Win2000 servers that use DCOM COM+ Application Proxying to ... standalone, and not in a common workgroup or domain. ... we cannot get the app proxy to work. ...
    (microsoft.public.security)
  • looking for sample iptables and ipchains setups
    ... schemas - for all kinds of situtations - be they "standalone" workstations, ... servers, firewalls, routers - whatever. ...
    (comp.os.linux.security)