advice on configuring a small network



I'm a long-time software developer, so I'm familiar with most of the
concepts, but I've never before functioned as a system admin, so I've got
some learning to do.

I've got two Windows 2003 SP1 servers, each on its own completely distinct
Active Directory forest, and three Windows XP-Professional workstations. All
of the machines are connected to a Netgear firewall/swtich. One of the
servers is a webserver/mailserver. I have ports for HTTP, POP3, and SMTP
opened on the firewall to that machine only. The second server is the PDC
for my internal domain, and also runs the SQL Server database used by some
of the websites running on the webserver machine. All of the workstations
are members of the internal domain.

I'm setting up a 1-way trust relationship so that the webserver will trust
the internal domain, but not vice versa. My goal is to be able to easily
move content to/from the webserver from my administrative workstation, but
to protect the internal domain from the outside world.

First question -- Is this a reasonable setup? Any suggestions would be
appreciated.

Second question: Is there any benefit to running firewall software on the
internal domain server?

Thanks,

Joe



--
Posted via NewsDemon.com - Premium Uncensored Newsgroup Service
------->>>>>>http://www.NewsDemon.com<<<<<<------
Unlimited Access, Anonymous Accounts, Uncensored Broadband Access
.



Relevant Pages

  • Re: Can extra processing threads help in this case?
    ... A Webserver at a hosting site ... technology enclosure, the network cable coming out is a huge security ... if I have physical access, I don't need to worry opening the box to steal anything in it, ... server, everything is vulnerable, and it is up to you to ...
    (microsoft.public.vc.mfc)
  • Re: Can extra processing threads help in this case?
    ... A Webserver at a hosting site ... A Webserver rented to the client at the client's site. ... security system, to see what ... the street and my server. ...
    (microsoft.public.vc.mfc)
  • Re: Basic Question (dumb) regarding security
    ... It is not ok to host a public website on your SBS, but it is ok to host ... setup the network and the webserver properly so that only appropriate ... It would be less secure or meaningful to open more holes in ISA so ... Since ISA is an application server, ...
    (microsoft.public.windows.server.sbs)
  • Re: hide ip address of website (no domain name)
    ... > webserver from any other programs/scanners/etc? ... > will proxy server installed on the box or using host ... > various parts of it that are not on port 80. ... How about installing on of the open source firewalls in front of it and ...
    (Security-Basics)
  • RE: ViewState vs. Database
    ... webserver, but that seems like the best performance to cost ratio I can come ... Microsoft MSDN Online Support Lead ... You can send feedback directly to my manager at: ... to server, webserver, server to database server..). ...
    (microsoft.public.dotnet.general)