Articlesclick.com Menu
Newest Articles
Most Viewed Articles
Articlesclick.com RSS
Submit Article
Login
Signup
Search the articles

Articles Main Categories
Advice
Animals
Automobiles
Business
Career
Communications
Computer Programming
Computers
Entertainment
Environment
Family
Fashion
Finance
Food
Health & Medical
Home & Garden
Humor
Internet Business
Internet Marketing
Legal
Leisure & Recreation
Marketing
Other
Politics
Reference & Education
Religion
Self Improvement
Sports
Technology & Science
Travel
Writing
Subscribe
Receive alert message from us when new articles submitted to our site for free.

Enter your name

Enter your email

Syndicate

















Related Products
Home::Networking

Web Servers and Firewall Zones

Author : Chris Weight
Web and FTP Servers



Every network that has an internet connection is at risk of being compromised. Whilst there are several steps that you can take to secure your LAN, the only real solution is to close your LAN to incoming traffic, and restrict outgoing traffic.



However some services such as web or FTP servers require incoming connections. If you require these services you will need to consider whether it is essential that these servers are part of the LAN, or whether they can be placed in a physically separate network known as a DMZ (or demilitarised zone if you prefer its proper name). Ideally all servers in the DMZ will be stand alone servers, with unique logons and passwords for each server. If you require a backup server for machines within the DMZ then you should acquire a dedicated machine and keep the backup solution separate from the LAN backup solution.



The DMZ will come directly off the firewall, which means that there are two routes in and out of the DMZ, traffic to and from the internet, and traffic to and from the LAN. Traffic between the DMZ and your LAN would be treated totally separately to traffic between your DMZ and the Internet. Incoming traffic from the internet would be routed directly to your DMZ.

Therefore if any hacker where to compromise a machine within the DMZ, then the only network they would have access to would be the DMZ. The hacker would have little or no access to the LAN. It would also be the case that any virus infection or other security compromise within the LAN would not be able to migrate to the DMZ.



In order for the DMZ to be effective, you will have to keep the traffic between the LAN and the DMZ to a minimum. In the majority of cases, the only traffic required between the LAN and the DMZ is FTP. If you do not have physical access to the servers, you will also need some sort of remote management protocol such as terminal services or VNC.



Database servers



If your web servers require access to a database server, then you will need to consider where to place your database. The most secure place to locate a database server is to create yet another physically separate network called the secure zone, and to place the database server there.

The Secure zone is also a physically separate network connected directly to the firewall. The Secure zone is by definition the most secure place on the network. The only access to or from the secure zone would be the database connection from the DMZ (and LAN if required).



Exceptions to the rule



The dilemma faced by network engineers is where to put the email server. It requires SMTP connection to the internet, yet it also requires domain access from the LAN. If you where to place this server in the DMZ, the domain traffic would compromise the integrity of the DMZ, making it simply an extension of the LAN. Therefore in our opinion, the only place you can put an email server is on the LAN and allow SMTP traffic into this server. However we would recommend against allowing any form of HTTP access into this server. If your users require access to their mail from outside the network, it would be far more secure to look at some form of VPN solution. (with the firewall handling the VPN connections. LAN based VPN servers allow the VPN traffic onto the network before it is authenticated, which is never a good thing.)


Article Source: http://www.articledashboard.com





Chris Weight is a writer for www.stekno.com , information for IT professionals





Related articles


  1. Become an Expert: How to Make Prospects Come Begging for You
  2. How to choose a managed wide area network provider?
  3. Everything I Need to Know About SuccessI Learned Through Networking
  4. Personal Charisma - Developing Four Components for Business
  5. Networking Strategy: Just Say No to Business Cards
  6. Communication is the Key
  7. Connections at Conventions
  8. Is Networking REALLY Worthwhile?
  9. How To Become A Natural Networker
  10. What's Your "Follow-Up" Rating? Take My 10-point Test
  11. The Banking of Effective Networking (The Networking Factor)
  12. How to Use The Ryze Network! Detailed Instructions
  13. Network Marketing Tip: A 30-Second Tool
  14. Build an Internet and Network Marketing Business by Cracking The Millionaire Code - Part 4
  15. Meeting in Person Makes a Powerful Impact
  16. Your Social Network is a Powerful Marketing Tool
  17. Why Should I Go to a Networking Event or Join a Networking Group?
  18. Social Skills 101
  19. How NOT To Network
  20. A Networking Legacy
  21. Networking for Business
  22. Making Networking Work
  23. Productive Networking
  24. Pass That Lead Along Instead Of Saying No!
  25. The Six Degrees Of Networking

 

More Articles Advertising Copywriting E-Mail Marketing Internet Marketing Link Popularity Marketing Marketing Strategy Newsletters Online Business PPC Advertising Public Relations Sales Scams S E Optimization S E Positioning S E Tactics Search Engines Self Improvement Site Security Spam Web Development Web Hosting Webmasters Writing

Featured Articles :
Auto and Trucks | Business and Finance | Computers and Internet | Education | Food & Drink | Home Improvement | Kids and Teens | Legal | Marketing | Online Business | Pets & Animals | Parenting | Recreation and Sports | Self Improvement and Motivation | Site Promotion | Travel and Leisure | Web Design and Development | Women

ArticlesClick.com || More Articles || More Authors || Tips || E-Books || Resources

© 2007 Articles Click  / Articles.articlesclick.com Email : info(AT)articlesclick.com  Powered by Destiny Infotek Limited

Partner Links: Linux Web Hosting | Web Hosting | SMS Plug-in | Readymade Logo Design | Web Templates Affiliate | SEO Top Ranking | Ebooks  Webmaster | Register Domain Name | Hindustanlink | MT & BPO Forum | Medical Transcription | BPO Services India | Mobile Phone Forum | Send Gifts to India | RSS Feed Guide | Search E-books | Downloadable ebooks | BPO | SEO Services | Mehendi World | Destiny | Web-link | Beauty Care Forums | Web Hosting India | Logo Design | Home Based Business | Google SiteMap Maker | India Tourist Places | Medical Transcription | Mehendi Blog | Teachers Forum | BSE Sensex | Digital Signature Certificate | Discuss | Manoj Jain's Blog | Jigg | Chartered Accountant | Hosting Directory | Free Blog | Honeymoon Tips | Wallpapers | BPO Portal

ArticlesClick.com makes no representations regarding either the products or external links.
The products and external links referenced in this site are provided by parties other than ArticlesClick.com