Exposing an intranet to the web
Discussion
What way would you guys go about it? A customer of mine wants to do this and I'm thinking of a reverse proxy rather than just forwarding port 80 through the firewall. I really am not keen to expose their AD to any possible hacks/vulnerabilities so a seperate expendable server with different passwords etc seems the sensible route to me.
It's a SQL driven app and I'm a bit nervous as they don't have any in house security experts.
Any thoughts on best practises and products welcome.
It's a SQL driven app and I'm a bit nervous as they don't have any in house security experts.
Any thoughts on best practises and products welcome.
It's all firewalled, so port 80 would be the only port allowed inbound, but the server is part of AD and as a second level of defence I was thinking about having the server outside and only allowing it's IP through.
I'll have a nose at ISA and see what that can do. Are there any appliances out there that anyone's used?
I'll have a nose at ISA and see what that can do. Are there any appliances out there that anyone's used?
It's customary to put the web server in a DMZ (either between 2 firewalls, or on another interface from a single firewall) and allow the DMZ IP of the web server to talk through the inside firewall to an application/database server inside. Don't put the database server in the DMZ. And certainly don't put the web server "outside" - you're asking for trouble. And don't make the web server part of an internal domain - you expose too much internal information and have to open unecessary ports on the firewall if you do.
stick it in it's own domain with a one way trust so it trusts your internal network (allowing your normal admins to administer the box and your normal web developers to publish content to it as they would any other intranet server). Stick it in a DMZ. Don't allow netbios between the DMZ and internal, best thing is to allow nothing with short logging turned on and unlock ports until it works how you want, be careful not to expose your internal DNS too. Have an IDS system running in the DMZ to check your webserver isn't trying to do anything strange to your internal network.
if u wanna get really tight something like this depending on who u want to access the intranet:
www.appgate.com
www.appgate.com
Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff



I'm thinking of a second web server as the current one is part of AD, and that makes me very very uncomfortable 