Solved

Moving web servers into a DMZ?

Posted on 2016-10-25
3
109 Views
Last Modified: 2016-11-07
We've a pair of load balanced MS Windows 2008 R2 servers setup as a cluster for redundancy running IIS7.5.  And we host about 40 sites and domains.  We're using MS Load Balancer app.

I need to move these sites into a DMZ.  So my first question is do I have to change the ip address on the web servers and assign one from the DMZ subnet?  Or should I just be able to change the ip address of the sites and assign them an address from the DMZ.

I tried doing that today and it didn't work.  It worked fine on the server itself.  But when I try to access the site by ip it can't be found.

Let me  know if you need more info.

Thanks
0
Comment
Question by:mobot
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 28

Accepted Solution

by:
Dr. Klahn earned 500 total points
ID: 41859513
Presumably your web servers are now inside your LAN and the firewall has been told to route port 80 traffic to their current IP address.

Then the first step would be to reassign them new static IP addresses inside the DMZ, which you've done.

If the servers host multiple sites, access by IP address might not work correctly.  Virtual hosts are "routed to" internally in the server by the hostname section of the incoming URL.

When you moved the servers into the DMZ, was the firewall told to route port 80 traffic to their new IP address?
0
 

Author Comment

by:mobot
ID: 41864197
I didn't move the actual IIS servers that host the sites into the DMZ.

What I did was add an ip address from the DMZ subnet to the cluster properties.  Then assign that address from the DMZ subnet to a site.  I made the appropriate changes to DNS,  DNS resolves correctly.
I can access the site in IIS Manager on the server.

But from my workstation's browser I can't access the site.

So I'm asking do I need to assign addresses from the DMZ subnet to the IIS servers before I add the sites to the DMZ?

Thanks
0
 

Author Comment

by:mobot
ID: 41872727
Anyone???
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A web service (http://en.wikipedia.org/wiki/Web_service) is a software related technology that facilitates machine-to-machine interaction over a network. This article helps beginners in creating and consuming a web service using the ColdFusion Ma…
When it comes to security, close monitoring is a must. According to WhiteHat Security annual report, a substantial number of all web applications are vulnerable always. Monitis offers a new product - fully-featured Website security monitoring and pr…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
Suggested Courses

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question