Safest way to publish web services?
Posted on 2011-09-28
Please can you give your opinion on the safest way to host internal web services?
We have 2 options…
1st option is that we simply place the web server in to a DMZ off the corporate firewall – Cisco ASA 5500. We would just allow connections to come in to the web server in the DMZ on ports 80 and 443, there is a static NAT rule on ASA to facilitate this. The web server would not be a member of the corporate domain, and would have no connectivity through the firewall to the inside network.
2nd option is that we locate the web server on the inside network. In addition, we host a unihomed Microsoft ISA 2006 server in the DMZ. We instead allow the port 80 and 443 connections to come in to the ISA server in the DMZ, then we allow the ISA server to access the web server on the inside network through the ASA firewall on ports 80 and 443. The ISA server will be acting as a reverse web proxy server and would not be a domain member.
Please can you somebody advise which option is more secure. and maybe provide pros and cons for each. would either setup work well, or is 1 option more secure than the other.
appreciate your feedback, and will respond quickly to any questions.