Re: AD , Schema and Exposure to Internet

From: Steven L Umbach (sumbach_at_nospam-ameritech.net)
Date: 02/20/04


Date: Fri, 20 Feb 2004 14:48:46 GMT

I am not an IIS guy and there is also a separate IIS security newsgroup
which you will find helpful. However I would certainly never make a domain
controller a public IIS server and not a domain member unless absolutely
necessary. Of course a firewall is needed to protect any IIS server to just
allow necessary traffic with default block all inbound and outbound rules
with exceptions then created for needed traffic. A non domain controller
domain member does not have any AD info stored on it, though it potentially
could be an entrance point to the domain resources that might not exist
otherwise. I would also be sure to harden our IIS server by at least running
IIS lockdown tool on it only after backing up current confiuration with the
IIS management console. --- Steve

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/locktool.asp

"Jozz" <anonymous@discussions.microsoft.com> wrote in message
news:37CFF4FB-40CD-4AE3-840F-ABCA531F1F78@microsoft.com...
> Hi
>
> What are the considerations that need to be taken into account when
planning to deploy an AD, with web-server environment?
>
> What do I need to consider in terms of public access to the AD and AD
schema and other secuirty issues?
>
>



Relevant Pages

  • Re: NT AuthorizationAnonyomous logon error
    ... SQL BI Product Unit ... What I am doing now is creating a CAB file coping to the IIS ... >>> I have a SQL box and a IIS server. ... >>> Server and have place several cube that I wish client to access via a ...
    (microsoft.public.sqlserver.olap)
  • Re: another IIS Authentication
    ... > I have a IIS server that is NOT on our corporate domain. ... > I have half the users on workstations logging in to the ... If the server is not on your corporate domain then you can't authenticate ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS - SMTP - CDONTS
    ... > Hi Alan, ... Are all the messages queued in the IIS? ... I then checked the recipient's e-mail account and it did receive the ... > |> after you reinstall the IIS server. ...
    (microsoft.public.inetserver.iis)
  • Re: Firewall & DMZ
    ... The IIS server not knowing that the internal network exists is not entirely ... the IIS in the DMZ should be connected to the internal network ...
    (microsoft.public.inetserver.iis.security)
  • Re: Windows authentication query
    ... Yes, ideally setting the SPN should be fine, but it did not work. ... > install IIS, only the NetBIOS name of the IIS server is registered with ... > FQDN) with the KDC. ... IIS server in the list of sites that would be available in the intranet. ...
    (microsoft.public.inetserver.iis.security)