Psst! Did you know DevelopmentNow is a mobile web site design agency?

Contact us for help mobilizing your site, or to sign up for our beta Mobile Web SDK!
all groups > iis security > september 2005 >

iis security : IP address restrictions, limits of?


pirho
9/14/2005 7:26:01 AM
Hi folks,

I'm trying to find out if there are any limits on the number of IPs you
can Grant access to, if a web is set as Deny All under the IP security
settings.
I'm looking for hard limits and performance limits both, on IIS 5 vs IIS 6.

If anyone can provide me any information, that would be greatly appreciated.

Also, can anyone confirm that these IPs are stored in the metabase?

Thanks,
Bob Housedorf
pirho
9/14/2005 9:52:01 AM
OK, does anyone know of any performance impact at a large number of IPs? Or
the performance impact at different numbers of IPs?

[quoted text, click to view]
John Cesta
9/14/2005 10:58:36 AM
On Wed, 14 Sep 2005 07:26:01 -0700, "pirho"
[quoted text, click to view]


I don't think there are any hard limits. You can use the metabase
editor to see if they are actually in there. From what I remember they
are stored there.

John Cesta

The CPU Checker - Monitors your CPU % while you sleep
LogFileManager - IIS LogFile Management Tool
WebPageChecker - Helps Maintain Server UpTime
DomainReportIt PRO - Helps Rebuild IIS
http://www.serverautomationtools.com

[quoted text, click to view]
Bernard Cheah [MVP]
9/19/2005 12:00:00 AM


--
Regards,
Bernard Cheah
http://www.iis-resources.com/
http://www.iiswebcastseries.com/
http://www.msmvps.com/bernard/


[quoted text, click to view]

Bernard Cheah [MVP]
9/19/2005 12:00:00 AM
It would be minor. compare to domain name restriction.
i have try 50 before, the dual cpus machine just take it as nothing, can't
feel any performance impact.

--
Regards,
Bernard Cheah
http://www.iis-resources.com/
http://www.iiswebcastseries.com/
http://www.msmvps.com/bernard/


[quoted text, click to view]

pirho
9/19/2005 7:35:03 AM
Bernard,

I'm more concerned about the impact of 1000 single IP entries
and 50 IP range entries.

The restrictions were used as part of the security of the system, when user
count was near 50. Now the system has expanded, and so has the user base.
The web server, IIS 5.0, is failing more often now, and the admin folks are
suggesting that the cause is the number of entries in the IP restriction
section.

I am looking for any performance impact that anyone knows of when using IP
restrictions numbering in the 1 - 2 thousand individual entry range.

My personal guess is that IIS is caching these in memory and maybe using 1
or 2 Mb to store it. And that it should NOT be a performance issue, at least
not yet. However, the folks who admin our web server are suggesting that we
implement our OWN IP restriction code, which for obvious reasons I am
resisting with every last breath I can muster....

Anyone out there have a boat load of IPs added in to restrict or allow
access? Please tell me IIS version and server specs!!

[quoted text, click to view]
HB
10/11/2005 8:32:02 PM
Any more, i want add 1 thousand ip in the list too. Thanks.

[quoted text, click to view]
HB
10/11/2005 9:56:01 PM
Pirho, how to add 1~2 thousand entry into the list.

[quoted text, click to view]
AddThis Social Bookmark Button