Re: How vulnerable server will become if placed on DMZ ?

From: karl [x y] (jamescagney90210@excite.com)
Date: 08/21/02


From: "karl [x y]" <jamescagney90210@excite.com>
Date: Wed, 21 Aug 2002 07:56:25 -0400


"Marlon Brown" <marlon_brownj@hotmail.com> wrote in message
news:eIHhDoNSCHA.2272@tkmsftngp11...
> I have a type of Web Server (proprietary web server).
> This server needs to be accessed from the Internet.
> I have a firewall and TCP 80 inbound and outbound should be configured to
> allow people to access the described server from the Internet.
>
> Third party software vendor recommended that the server is placed on the
> "DMZ".
> When it comes to security, how badly am I going to increase potential
> threats if I put the server on the "DMZ" instead of keeping it "inside" my
> network ?

The idea of a DMZ is not to subject your web server to greater risk, but to
protect your internal network from a compromised web server. A DMZ can also
give you greater control over what traffic is permitted and denied to and
from which network. [e.g. right now I bet you have little or no control or
logging concerning what traffic flows between your internal network and the
web server]. A DMZ is generally considered better security for your entire
network as compared to what you probably have now, a single firewall.

In setting up a DMZ, you face some choices... a single firewall with a third
network interface for an isolated DMZ network, a second firewall with the
DMZ network in between the two firewalls, a second firewall with a third
network interface, a proxy server, etc. The book Building Internet
Firewalls is considered a little dated but describes firewall architectures
and filters.

Setting up a web server without compromising your network security takes
some knowledge. If you aren't already an expert at DMZs and other facets of
internet security, I would highly recommend finding a security consultant to
help. Hopefully you've already configured your web server and Windows with
the latest patches, settings and permissions using all available security
hardening checklists. An awful lot of serious network compromises can slip
through a firewall on a single port such as TCP 80.



Relevant Pages

  • RE: can ping but not browse
    ... I have stopped the firewall. ... # are safed from all (security) hazards. ... firewall/bastion host to the internet ... # internet and to an internal network, ...
    (Fedora)
  • Re: Using a Linksys router, should I also use Zonealarm?
    ... public internet to access corporate network. ... In the "old days" when people used to use Dial-In instead of VPN you ware ... protected by corporate Firewall -- since there was no public Internet ...
    (microsoft.public.security)
  • RE: Hidden Ports
    ... this is done by the firewalls to prevent authenticated files from being replaced by trojans and connecting to the internet. ... kerio firewall ... or a program that already had network access attempted to ... > Depending on the Access setting for a component, ZoneAlarm Pro ...
    (Security-Basics)
  • Re: Entire Network
    ... Internet access is different and just because a firewall isn't ... Second, if it isn't the firewall, then often it is a case of the system ... any way a network guru. ... > The network connection works just fine from both computers for internet ...
    (microsoft.public.windowsxp.basics)
  • Re: Using a Linksys router, should I also use Zonealarm? Internet Acceptable Use Policy
    ... my browser's access to the Internet is restricted. ... I thought it was the company's firewall extending a slap on my ... > public internet to access corporate network. ... > NAT is Network Address Translation. ...
    (microsoft.public.security)