all groups > iis security > december 2005 >
You're in the

iis security

group:

security basics


security basics Dave
12/8/2005 10:33:34 PM
iis security:
i will be setting up a new w2003 server shortly. it will be an external web
server and also an internal lan file and print server for a simple
workgroup. the router only does nat, no firewall. i plan on using the
windows firewall and ipsec policies to restrict outside access to only port
80. the web site does no ssl and does not require any type of
authentication. it will have 2 sites set up with host headers off the same
ip address. what is the easiest way to lock it down? i am using urlscan on
my old w2k-ws 'server' now, is there an equivalent with 2003? or some other
way to do it better?

Re: security basics Tom Kaminski [MVP]
12/9/2005 9:52:46 AM
[quoted text, click to view]

Start here for security guidance on IIS:
http://www.microsoft.com/technet/security/prodtech/IIS.mspx

--
Tom Kaminski IIS MVP
http://www.microsoft.com/windowsserver2003/community/centers/iis/
http://mvp.support.microsoft.com/
http://www.iistoolshed.com/ - tools, scripts, and utilities for running IIS

AddThis Social Bookmark Button