putting a http website behind the firewall.

What potential issue do I have if I have a web site behind the firewall to be accessed via http only but no https?

Please advise.

Thanks.
nav2567Asked:
Who is Participating?
 
Chris MillardConnect With a Mentor Commented:
There are lots of factors to consider - is your website to be available to the world? What type of Firewall are you going to be behind? What will your website do and what platform will it run on (ASP, PHP, SQL, MySQL etc)...

Basically as soon as you start opening ports to your network, you are giving potential intruders a way in. If they find holes in your web applications, they could quite easily inject malicious code into your network.

You need to ensure that your server is fully patched, and make sure you thoroughly test any web site / application before opening it up to the outside world.

Ideally if you had the funds, you'd pay a consultant to perform a penetration test so that they could report back with any loopholes they find.

Of course you could make things a bit safer by having your web server on a DMZ behind your Firewall so that it is separate from your main network too.
0
 
gheistCommented:
With http poor overworked telecoms admins will be able to see all what your users do.
i tink you can get ssl certificate for single site for free (comodo?)
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.