Groups | Blog | Home
all groups > iis ftp > may 2006 >

iis ftp : Best Practice and advise


Adam Raff
5/25/2006 9:11:32 AM
Good Day,

I am building a FTP server for our company, as of this time I am not sure
what product I will be using weather it will be IIS or some third party ftp
product. My first concern is best practice and security. What needs to be
done and what are some of the better security issues I should enforce before
installing anything.

The system will be a Windows 2003 SP1 server (full patched). The system is
behind a firewall using NAT. Our old FTP system is a Windows XP box but I
wanted to get a little more out of it and decided to go with 2K3. Since I
am new to this, these questions may be a little basic but I wanted to make
sure that I got my infrastructure right and setup before moving on.

If anybody can point me to some white papers that are basic security and
tips that I can look through it would be a great help. If anybody would
like to post ideas they are also welcome.

For instance our old system is on our domain, or should it be part of a
workgroup and not part of our domain?
Should it be on a DMZ zone instead or is using NAT ok?

The question that I asked may be simple but to me it's not. Over the last
week or so I have seen in my logs that people have been knocking at my door
per say. Which is the reason why I want to upgrade our FTP site and get a
better handle on it and lock it down better.

Thanks
Adam Raff

Bernard Cheah [MVP]
5/26/2006 12:00:00 AM
The IIS FTP offers in W2k3 is not a fancy one, just basic feature sets and
capability. One good thing about it is that it is bundle with the OS,
integrated to OS user account db without additional cost, well it's already
included anyway :)

As for the security, it offers no means of security at all. it is a plain
text protocol, so you need to secure the connection, etc. Few KBs for you to
read

HOW TO: Set Up an FTP Server in Windows Server 2003
http://support.microsoft.com/?id=323384
HOW TO: Limit Access to a FTP Site in Windows Server 2003
http://support.microsoft.com/?id=816525
Information About the IIS File Transmission Protocol (FTP) Service
http://support.microsoft.com/?id=283679

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

AddThis Social Bookmark Button