Avatar of rvthost
rvthost
 asked on

Hardening IIS 6

Windows Server 2003 - R2
Dedicated IIS server

It's been requested that I make a site public.  This site accesses a SQL database which is hosted on a second server.  The data stored is considered sensitive.  I'm going to put the IIS server in the DMZ and keep the SQL DB on the inside.  Only SSL connections allowed to IIS from the outside.  From the IIS server to the inside of the network, only those ports required will be opened. (SQL, etc.)

What other "key" steps should I be taking to make this as secure as possible?  I can, and have, googled around and found plenty of sites talking about hardening IIS (rename admin acct, good passwords, etc.).  I will follow those but I'm just making sure I'm not missing something else that I should be doing.  If anyone has done this and wishes to share, I appreciate the feedback.  Thanks!
Microsoft IIS Web Server

Avatar of undefined
Last Comment
rvthost

8/22/2022 - Mon
Dave_Dietz

IIS 6.0 is secure by default.

Only enable the functions you require and leave the rest disabled.

Along with the network security you have already mentioned you should be good to go.

Dave Dietz
rvthost

ASKER
Thanks for your comments.

One of our web developers suggested keeping both our SQL and our IIS server inside the network, and then put a http proxy server in the DMZ instead.  I understand the idea of a proxy server, but have not worked with them.  What are the security implications of that setup, pros/cons?  If I should start a new question, I will do so.   Thanks.
SOLUTION
Dave_Dietz

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
ASKER CERTIFIED SOLUTION
Log in to continue reading
Log In
Sign up - Free for 7 days
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
rvthost

ASKER
Thanks to both for your comments.  We're proceeding forward...no proxy :)
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy