Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Server on DMZ, or behind firewall?

Status
Not open for further replies.

heli423

Technical User
Dec 11, 2002
2
US
The situation:

Need to set up a method of accessing a web server, which may be running Lotus Notes server as well.

How could I set this up so that users can access their email or web pages from any internet-enabled access point, and have a reasonable level of security in doing so? (it's not government secrets - just business business correspondences)

I've thought about setting it up on the DMZ, but that seems too exposed. There are only about 15 users at this company, but the need to have a solution in this regard is paramount.

They are currently set up on DSL using a Cisco router (800 series)using static IP's in 10.x

I'd appreciate anyone's take on this -
 
Thank you Yizhar -

I appreciate the information -
 
What are they trying to acess on the webserver? It seems odd to have a webserver sitting in your dmz that is also running your company's Notes server, not real secure. What about setting up a VPN tunnel so that they can access everything from an internal standpoint?

If the webserver is just that then I would suggest having a standalone webserver in the dmz with port 80 open and then having a seperate box internal running your Notes server. From a security standpoint if your web/notes server is in the DMZ and it's compromised then everything is at risk, business information, contact information, way too much information for the general public. Anyways, my thoughts if it matters. :>)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top