Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Moving web servers into a DMZ?

Posted on 2016-10-25
3
Medium Priority
?
128 Views
Last Modified: 2016-11-07
We've a pair of load balanced MS Windows 2008 R2 servers setup as a cluster for redundancy running IIS7.5.  And we host about 40 sites and domains.  We're using MS Load Balancer app.

I need to move these sites into a DMZ.  So my first question is do I have to change the ip address on the web servers and assign one from the DMZ subnet?  Or should I just be able to change the ip address of the sites and assign them an address from the DMZ.

I tried doing that today and it didn't work.  It worked fine on the server itself.  But when I try to access the site by ip it can't be found.

Let me  know if you need more info.

Thanks
0
Comment
Question by:mobot
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 29

Accepted Solution

by:
Dr. Klahn earned 2000 total points
ID: 41859513
Presumably your web servers are now inside your LAN and the firewall has been told to route port 80 traffic to their current IP address.

Then the first step would be to reassign them new static IP addresses inside the DMZ, which you've done.

If the servers host multiple sites, access by IP address might not work correctly.  Virtual hosts are "routed to" internally in the server by the hostname section of the incoming URL.

When you moved the servers into the DMZ, was the firewall told to route port 80 traffic to their new IP address?
0
 

Author Comment

by:mobot
ID: 41864197
I didn't move the actual IIS servers that host the sites into the DMZ.

What I did was add an ip address from the DMZ subnet to the cluster properties.  Then assign that address from the DMZ subnet to a site.  I made the appropriate changes to DNS,  DNS resolves correctly.
I can access the site in IIS Manager on the server.

But from my workstation's browser I can't access the site.

So I'm asking do I need to assign addresses from the DMZ subnet to the IIS servers before I add the sites to the DMZ?

Thanks
0
 

Author Comment

by:mobot
ID: 41872727
Anyone???
0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Have you ever sent email via ColdFusion and thought of tracking this mail to capture the exact date and time when the message was opened ?  If yes, then this article is for you ! First we need a table user_email with columns user_id , email , sub…
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…

661 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question