Exposing an intranet to the web
Exposing an intranet to the web
Author
Discussion

BliarOut

Original Poster:

72,863 posts

269 months

Thursday 12th May 2005
quotequote all
What way would you guys go about it? A customer of mine wants to do this and I'm thinking of a reverse proxy rather than just forwarding port 80 through the firewall. I really am not keen to expose their AD to any possible hacks/vulnerabilities so a seperate expendable server with different passwords etc seems the sensible route to me.

It's a SQL driven app and I'm a bit nervous as they don't have any in house security experts.

Any thoughts on best practises and products welcome.

randlemarcus

13,646 posts

261 months

Thursday 12th May 2005
quotequote all
ISA server. Designed for it, kicks ass. Currently in the final stages of EAL4+ certification as well.

Oh, and its a nice web cache the other way too

guydw

1,651 posts

313 months

Thursday 12th May 2005
quotequote all
Firewall ?

BliarOut

Original Poster:

72,863 posts

269 months

Thursday 12th May 2005
quotequote all
It's all firewalled, so port 80 would be the only port allowed inbound, but the server is part of AD and as a second level of defence I was thinking about having the server outside and only allowing it's IP through.

I'll have a nose at ISA and see what that can do. Are there any appliances out there that anyone's used?

zumbruk

7,848 posts

290 months

Thursday 12th May 2005
quotequote all
It's customary to put the web server in a DMZ (either between 2 firewalls, or on another interface from a single firewall) and allow the DMZ IP of the web server to talk through the inside firewall to an application/database server inside. Don't put the database server in the DMZ. And certainly don't put the web server "outside" - you're asking for trouble. And don't make the web server part of an internal domain - you expose too much internal information and have to open unecessary ports on the firewall if you do.

BliarOut

Original Poster:

72,863 posts

269 months

Thursday 12th May 2005
quotequote all
Sorry, by outside I meant DMZ I'm thinking of a second web server as the current one is part of AD, and that makes me very very uncomfortable

zumbruk

7,848 posts

290 months

Friday 13th May 2005
quotequote all
BliarOut said:
Sorry, by outside I meant DMZ I'm thinking of a second web server as the current one is part of AD, and that makes me very very uncomfortable


Me too. We do not permit DMZ machines to be part of an internal domain.

m12_nathan

5,138 posts

289 months

Friday 13th May 2005
quotequote all
stick it in it's own domain with a one way trust so it trusts your internal network (allowing your normal admins to administer the box and your normal web developers to publish content to it as they would any other intranet server). Stick it in a DMZ. Don't allow netbios between the DMZ and internal, best thing is to allow nothing with short logging turned on and unlock ports until it works how you want, be careful not to expose your internal DNS too. Have an IDS system running in the DMZ to check your webserver isn't trying to do anything strange to your internal network.

billb

3,198 posts

295 months

Friday 13th May 2005
quotequote all
if u wanna get really tight something like this depending on who u want to access the intranet:

www.appgate.com