Re: Suggestions



Since the MS provided FTP is not Secure FTP and the
authentication takes place in clear text on the network,
the "real" answer is that neither is a good solution nor
"secure".

Given that, if there is then still meaning to "more secure"
based only on the different IIS config for the FTP service,
I would say that it is a total wash. To control access you
would be leveraging NTFS permissions on the storage in
either case. In the single FTP server situation one could
use one single storage area or multiple vdirs of separate
storage areas. There is a slight difference as MS FTP
does not allow parent path traversal to real storage above
the folder used as the vdir root (unlike MS WWW).
But, I do not see any real security difference between the
three scenarios (your two, with the single server configured
with one big or multiple smaller vdirs). In all cases an account
is contained to what NTFS allows to it, and in all cases it is
a single FTP service that is running. The differences are in
details of the service's instancing and in user perception and
convenience or inconvenience.

--
Roger Abell
Microsoft MVP (Windows Server : Security)

"Bad Beagle" <maxwelli@xxxxxxxxxxxxxxxx> wrote in message
news:%23NwJNYpIGHA.2896@xxxxxxxxxxxxxxxxxxxxxxx
>I am doing some consolidation of Windows 2003 IIS servers. What is more
>secure - to have 1 ftp server shared by all IIS servers using virutual
>directories or running 4 individual ftp servers without virutual
>directories and using ntfs to lock it down? Any suggestions would be
>appreciated.
>


.



Relevant Pages

  • Re: Folder sharing and ZA
    ... rather than have a shared folder you could set up either an FTP ... server or Web server on your machine. ... but be aware that regular FTP isn't very secure - passwords can be ...
    (comp.security.firewalls)
  • RE: [OT] M$ collaborates with Suse
    ... Most hosting facilities do allow FrontPage and/or FTP access...FrontPage ... Remote Administration to an actual server can be done with a Terminal ... Secure Administration on the inside can be done with Scripting. ... decent free SSH Servers out there for Windows and I like freeSSHd. ...
    (Debian-User)
  • Help with IPFW + NATD + Passive FTP
    ... passive FTP connections through IPFW with NATD enabled. ... $cmd 005 allow all from any to any via dc0 ... # Interface facing Public internet ... # Allow out access to my ISP's Domain name server. ...
    (freebsd-questions)
  • RE: Client Computers cannot upload or download from Remote FTP ser
    ... SBS External NIC - Cannot FTP From this server ... SBS Internal NIC ... FTP server is Checked in Routing and Remote Access - Internet Connection - ...
    (microsoft.public.windows.server.sbs)
  • Re: [fw-wiz] OT: FTP Servers
    ... > the site are anonymous FTP, potentially some 'real' FTP users, and up to ... the security, the worse the configurability/features. ... Extremely secure. ... It's also the FTP server of choice in Linux Red Hat 9. ...
    (Firewall-Wizards)