Groups | Blog | Home
all groups > iis security > october 2005 >

iis security : virtual server authorization


Aric
10/19/2005 9:00:49 PM

I am currently about to launch an ecommerce solution for my company an
was wonder about securing the administration section. Currently th
plans are to have the administration site in a virtual server usin
windows authentication and restricted to local ips only. While lookin
at all the documentation I can find this should work perfectly I'm stil
a little worried about having it on a server connected directly to th
net. Anyone know of security flaws in IIS 6.0 running on w2k3 tha
would allow users to get into the administration site

--
Ari
-----------------------------------------------------------------------
Aric's Profile: http://www.highdots.com/forums/m112
View this thread: http://www.highdots.com/forums/t303862
David Wang [Msft]
10/20/2005 4:44:36 AM
Here are some thoughts on what "security" really means:
http://blogs.msdn.com/david.wang/archive/2005/09/30/Thoughts_on_IIS_Security_vs_Apache.aspx
http://blogs.msdn.com/david.wang/archive/2005/10/01/Thoughts_on_IIS_Security_vs_Apache_Part_2.aspx

If you are uneasy, I would suggest that you put two NIC in the server and
bind the administration website to the internal-facing NIC. Then, you can
trust in your network routing configuration skills to make sure that network
traffic goes to the right place.

Personally, if the administration site requires authentication, that's about
all the protection you need, even Internet facing.

--
//David
IIS
http://blogs.msdn.com/David.Wang
This posting is provided "AS IS" with no warranties, and confers no rights.
//
[quoted text, click to view]

I am currently about to launch an ecommerce solution for my company and
was wonder about securing the administration section. Currently the
plans are to have the administration site in a virtual server using
windows authentication and restricted to local ips only. While looking
at all the documentation I can find this should work perfectly I'm still
a little worried about having it on a server connected directly to the
net. Anyone know of security flaws in IIS 6.0 running on w2k3 that
would allow users to get into the administration site?


--
Aric
------------------------------------------------------------------------
Aric's Profile: http://www.highdots.com/forums/m1128
View this thread: http://www.highdots.com/forums/t3038625

AddThis Social Bookmark Button