Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: Web access to web server in private LAN

Subject: Re: Web access to web server in private LAN
Date: Wed, 22 Feb 2006 14:41:17 -0500
It would be a security best practice to simply use a reverse proxy or
filtered port forwarding inward to the IIS box.

Putting this box on your DMZ would require many holes in your
firewall/filter/etc to facilitate Windows/NetBIOS/etc access.

On 2/21/06, Ivan . <ivanhec@gmail.com> wrote:
Hi DM

Moving to the DMZ would be the best solution. Is there a reason that
they can't/wont move it? This could form part of your TRA, ie the
expensive to move out weighs the risks, etc..

Using a reverse proxy like Squid is OK, but not prefered.
http://squid.visolve.com/squid/reverseproxy.htm


cheers
Ivan

On 2/21/06, David Moneo <dummycerberus@gmail.com> wrote:
Hello everybody,

my organization has an Apache web server for world wide access in the
DMZ. Right now, another department want to made their own IIS server
(installed on their private LAN) available from the Internet. How can
I manage that kind of access without moving the IIS to the DMZ? Could
I use a reverse proxy or something like that?

Thanks in advance and best regards

DM

---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------




--
ME2

---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Tailor your education to your own professional goals with degree 
customizations including Emergency Management, Business Continuity Planning, 
Computer Emergency Response Teams, and Digital Investigations. 

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>