Security Basics mailing list archives
Webserver on a DMZ still needed?
From: "Davie Elliott - Eluse" <delliott () eluse co uk>
Date: Sun, 3 Sep 2006 12:42:31 +0100
Hi all, I have been working as a systems admin for a charity for about 3 years, I have no schooling in network I have learnt everything myself. During my research I read that servers with public services should be put on a separate subnet which is used as a DMZ (such as POP3, SMTP, webserver ect). Recently I have left that charity and a network company is taking over the administration, and they want to put the Exchange (email) server on the trusted network subnet (the network has a smoothwall firewall, so there are literally 2 separate networks). My question is this: does the Exchange server definatly, need to be put in the DMZ? Or should Microsoft have patched all the vulnerabilities by now? There isn't any other software on the server, such as forums which I see have vulnerabilities found just about ever day. Secondly, if the Exchange server is on the DMZ subnet, how do you get it to interact securely with the Domain Controller on the secure subnet? When I built the network, I made the Exchange server its own Domain Controller. Thanks for your advice, Davie Elliott --------------------------------------------------------------------------- This list is sponsored by: Norwich University EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life. http://www.msia.norwich.edu/secfocus ---------------------------------------------------------------------------
Current thread:
- Webserver on a DMZ still needed? Davie Elliott - Eluse (Sep 05)
- RE: Webserver on a DMZ still needed? Peter Marshall (Sep 05)
- RE: Webserver on a DMZ still needed? Robert D. Holtz - Lists (Sep 05)
- RE: Webserver on a DMZ still needed? Murda Mcloud (Sep 06)
- RE: Webserver on a DMZ still needed? Steve Armstrong (Sep 06)
- Re: Webserver on a DMZ still needed? Micheal Espinola Jr (Sep 07)
- Re: Webserver on a DMZ still needed? MandommGmail (Sep 05)
- Re: Webserver on a DMZ still needed? irado furioso com tudo (Sep 05)
- Re: Webserver on a DMZ still needed? MaddHatter (Sep 06)
- <Possible follow-ups>
- RE: Webserver on a DMZ still needed? Verma, Neeraj K (Sep 05)
- Re: Webserver on a DMZ still needed? lexnlondon (Sep 05)
(Thread continues...)
- RE: Webserver on a DMZ still needed? Peter Marshall (Sep 05)