Solved

SBS 2003 best practices.

Posted on 2004-10-06
4
263 Views
Last Modified: 2013-11-16
I’d love to see something like a definitive answer to this question:  

Which of these 3 configurations of SBS 2003 is the “best practice”?

Assume that external access to the server is required for things like OWA and Remote Workplace

Option 1: SBS is the firewall and LAN internet gateway, directly connected to the internet via 2nd NIC
Option 2: SBS is the gateway (again via 2nd NIC) with a router or firewall appliance between it an the Internet
Option 3: SBS and client systems all use the router as the gateway/firewall; SBS has a single NIC

Option 3 is what we’ve been doing, but my feeling is the option 2 is probably the best.  On the other hand, I remain concerned about the load on the server due to all LAN internet traffic passing through it.  I have no idea whether that is a real issue or not.

This is a rather broad question I know, I'm looking for some definitive pro's and con's.
0
Comment
Question by:logic1cs
4 Comments
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 12240228
Do some server monitoring - see what kind of performance you are getting out of things with System Monitor.  It can monitor your NIC throughput - for one or both NICs.  With option 1 you are putting a highly insecure system right on the internet for people to attack.  Bad idea (I don't care how much you patch it, people keep finding holes in Windows security and exploiting them).  Option 2 to me has some logic - until you realize that all you're doing is adding another layer of failure.  To keep your client workstations on the internet BOTH the router/firewall appliance AND the server must remain on.  Now this can actually work to your advantage if you want to use Windows to track throughput and use programs like Network Monitor to spy in the traffic actually going out to the internet.  But other than that, I'd consider it a waste.  Option 3 is the most logical and the one I'd recommend.
0
 

Author Comment

by:logic1cs
ID: 12240817
Thanks for the quick response.

I'm not referring to a specific network with this query. Server monitoring is always being done on our networks on a regular basis. We look after large and small networks for our clients, I'm trying to establish a "best practice".

I totally agree that option 1 is out of the question I just put it there for reference more than anything.
0
 
LVL 5

Accepted Solution

by:
t_swartz earned 125 total points
ID: 12243340
My two cents;
I have installed multiple SBS 2000 and 2003 servers. We typically go w/ your option 3. Keeping up w/ ISA is painful, especially if you need external access. Those third party firewall just work so much stable, plus they are easier to configure for remote access and whatnot. We feel so strongly about it, we even went back (at our expense) and removed ISA from the SBS server, diabled the external NIC and moved them over to Cisco PIX or Fortigate firewalls, depnding on the functionality required.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now