Termial Services Gateway - DMZ or Internal

I'd like to setup a Terminal Services Gateway server to support about 5-10 users.  The software running on this server may be slightly complicated to setup firewall ports to allow traffic from the DMZ to the internal network, but not impossible.  When using TS Gateway is it best to place this server in the DMZ or since this is using secure connections is it safe to go ahead and leave this on the internal network?  I'd like to maintain adequate security since we are a hospital but not quite sure how far to take it?

Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Ayman BakrSenior ConsultantCommented:
TS Gateway needs to be joined to the Internal network domain because it carries out user authentication and authorization. On the other hand, since it has to deal with external users and to minimize security risks it would be inevitable to be placed in the DMZ. But in this case you will have to open ports for Communication to the AD, or otherwise have a domain controller in the DMZ (perhaps RODC to minimize risks).

But the best design would be to place your TS Gateway in the internal network behind ISA in DMZ.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Jian An LimSolutions ArchitectCommented:
if you are not just looking at microsoft related solution, you might want to look at a juniper solution SA2000
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.