Firewall Wizards mailing list archives

Re: Web server inside the firewall


From: "Bob Acosta" <acostar () allied-chas com>
Date: Tue, 1 Dec 1998 19:05:43 -0500

All CONS.  Do NOT DO THIS!!!!
    -----Original Message-----
    From: Kevin Tyrrell <tyrrell () i2k com>
    To: Firewall Wizards <firewall-wizards () nfr net>
    Date: Tuesday, December 01, 1998 5:45 PM
    Subject: Web server inside the firewall
    
    
    We are running a Gauntlet 4.1 firewall. We allow FTP and HTTP originating from the inside. We have also created a 
POP3 plug from inside to a local ISP. We don't allow any traffic originating from the outside.

    I have been getting pressure lately to have a web server moved from the DMZ to behind the firewall. The reasoning 
is this will make it easier to access databases on our internal network. 

    The web server is IIS 4 on NT 4.0+SP3 with FrontPage extensions. The firewall is in its own subnet. What ports need 
to be opened to make this work? 

    What do people feel about this type of configuration. Pros and Cons?

    Thanks,

    Kevin Tyrrell


Current thread: