Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Web server part of NT domain or standalone on dmz1

Status
Not open for further replies.
Nov 15, 2000
6
0
0
US
We are going to install a PIX 520 with 3 interface card( Internal, outside and dmz1 ) firewall in an NT environment with version 6.0. Email server is internal and Dmz1 will have web server. Is it a good idea to have web server part of NT domain or standalone ? I like to keep it on same domain. Am I lossing any security if I keep web server on same domain? I would just like a few recommendations. Thanks.
 
HI!

It is better to make the Web-Server stand alone and not part of the domain for 2 major reasons:
1) It is more secure.
For about the same reason you're putting it in the DMZ and not on the inside.
2) To allow a host in the DMZ be a member in the domain, you must open some additional ports, which degrades security and posses a lot more configuration problems.

Bye
Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top