Solved

Giving DUN users access IIS WEB server but not downstream SQL server.

Posted on 2006-07-06
3
196 Views
Last Modified: 2013-12-04
HI Brainies
I need to provide security protection to our system. ( All Microsoft software )
 I wish ....  DUN users to  connect to  a RAS server with IIS. This server gets its data for ASP pages from a SQL server. How do I allow these DUN users to only see web pages with no security issue with  them stuffing up the downstream SQL server.
 I assume also I cannot do all this on the one box from a security point.

Thanks in advance
Rodney
0
Comment
Question by:comerro1
  • 2
3 Comments
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
Comment Utility
on your RAS server, assign a dedicated subnet for those DUN users with no default gateway assigned, so all the DUN users will only access this separated subnet (e.g. 192.168.1.x). the IIS web server of course needs to assigned a fixed IP on this subnet too. the IIS server may be a multihome host, which connects another subnet (e.g. 192.168.2.x) on where the SQL server stays.

the topology diagram may be as follows:

DUN users -> (PBX) -> RAS server <-> DUN subnet <-> IIS <-> SQL subnet <-> SQL server
                                                         192.168.1.x                    192.168.2.x

hope it helps,
bbao
0
 

Author Comment

by:comerro1
Comment Utility
Hi Bbao
Do I load 2 ips on the 1 NIC or use 2 NICs in the RAS box?

Rodney
0
 
LVL 37

Accepted Solution

by:
Bing CISM / CISSP earned 500 total points
Comment Utility
2 IPs on the same NIC shoud be OK but not recommended because 1) security considerations 2) compatibility.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
Recently, I read that Microsoft has analysed statistics for their security intelligence report. It revealed: still, the clear majority of windows users do their daily work as administrator. An administrative account is a burden, security-wise. My ar…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now