Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

What is the best way to set up security?

Status
Not open for further replies.

bigfoot

Programmer
May 4, 1999
1,779
US
We have an intranet for our internal people, which some of our "on the road" people have to get to.

I don't want outside people who are not from out company to be able to get in. Maybe a password system, but I don't want another database to keep track of. Can I use NT security.

BTW: I have a few MAC users internally too.

I would like to know what security method is most widely used, so I thought I'd post the question here.

We are also using a firewall.

-Gary
They never have to knock if your door is always open.
 
Hi Gary

Using NT security is a good way to go. You must make sure that all users have a user account on the server. Make sure to renamen the administrator account as it will be vunerable for attacks.

Leo
 
Hi! Gray

you can use the windows NT Security but for this secrity you must have the windows NT O/S on the machine where you wants to aply the security another thing is the harddrives are on NTFS not on FAT to tighten the Security. You can creat a guest account with minimum rights. You can apply policy for that acoount to ristrict that user to access the network to access the local harddrive.Also advise your co workers to lock their systems before they leave their seats.
 
If you are using a firewall, you might consider using a VPN based connection... it's the safest way of doing this...
Otherwise, only communicate over SSL (but you'll need a certificate for this as well... I'd go for VPN) Peter Van Eeckhoutte
peter.ve@pandora.be

 
Are you using a portal with made with IIS? (I supose this is the thing because in other way the question would be OT)
If yes I suppose you are using password authentication with basic autentication. The security problems are knowing to be with the password passed in clear, however the possibility of sniffing is zero in attacks made from dial-up connections and the server hjacking is a very remotly possibility. You are realy vulnerable only from a brute-force attack (but who isn't??! :-( work with strong password!!:))
You don't need of another database because you are using NT authentication so all you must do is to set well the permission on the filesystem for the users that are inside the NT doman and that logs on the web portal.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top