Groups | Blog | Home
all groups > iis security > october 2005 >

iis security : Building a Windows 2003 DMZ Server without ISA


johnpaul.temple NO[at]SPAM gmail.com
10/19/2005 2:02:51 AM
hi

I am planning on building a Windows 2003 Web Server and placing into a
DMZ, with CISCO PIX on each side.

I have found only a few documents that describe how to configure the
Windows Server without using ISA. Has anyone got any tips or
suggestions for this sort of scenario?

We don't have a copy of ISA and I don't think there are any plans to
purchase it in the near future, which is why I am planning on building
this DMZ without it.

thanks in advance

JP
Chris Weber [Security MVP]
10/19/2005 12:45:21 PM
I would refer you to the Windows Server 2003 Security Guide at
http://www.microsoft.com/technet/security/prodtech/windowsserver2003/w2003hg/sgch00.mspx

In general, IIS 6 in Win2k3 is pretty nice out of the box - ASP disabled,
IIS lockdown preconfigured etc. So as long as you lockdown your perimeter
firewall to only allow TCP 80 and/or 443 you should be okay, provided you
dont change too many IIS settings or roll out an insecure web application.

Chris Weber




[quoted text, click to view]

johnpaul.temple NO[at]SPAM gmail.com
10/20/2005 5:05:40 AM
hi there

thanks for your reply, I have downloaded this and started reading
through it.

JP

[quoted text, click to view]
AddThis Social Bookmark Button