Results 1 to 5 of 5

Thread: Getting my head around implementing a webserver

  1. #1

    Getting my head around implementing a webserver

    Hi Everyone,

    I`m working in a school and at present our network is sat behind a VERY restrictive firewall and proxy, the school have decided they want to host thier own website in-house, to do this I need to contact the EMBC (our ISP) and put a written request in for an external IP, it also suggests reading thier firewall policy which iv done, basicaly in a nutshell it says they will remove thier firewall protection for that perticular IP.

    Am I right in thinking that because our webserver would be on our LAN if an attacker compromised it, they could potentially compromise our whole network. and because the IP I specify to them is an internal LAN one I cant put it on a network of its own. It does state that we have to have a firewall in operation protecting it, could anyone make any suggestions as to how this could be set up?

    Thanx

    Craig Dunn

  2. #2
    rebmeM roineS enilnOitnA steve.milner's Avatar
    Join Date
    Jul 2003
    Posts
    1,021
    Without knowing the network topography in this school it would be difficult to comment properly.

    I would look at using either the DMZ or Virtual Server functions of your edge router to help handling the traffic.

    You might want to use another firewall between the web server and the rest of the network to protect the rest of the network if the web server becomes compromised.

    Steve
    IT, e-commerce, Retail, Programme & Project Management, EPoS, Supply Chain and Logistic Services. Yorkshire. http://www.bigi.uk.com

  3. #3
    Senior Member
    Join Date
    Dec 2001
    Posts
    319
    Normally, web servers are placed in the DMZ. Get with your network admin and see if they'll free up a port for you.

  4. #4
    Senior Member WolfeTone's Avatar
    Join Date
    Jun 2007
    Location
    Ireland
    Posts
    197
    What I would suggest is setting up two separate VLANs on your router/firewall, one for your "normal" network and one for your webserver network. Just make sure they are completely separate and you should be fine.

  5. #5
    Senior Member
    Join Date
    Oct 2003
    Location
    MA
    Posts
    1,052
    Honestly you have a lot of concerns that are related to security, I would just pay a few bucks and have another company manage it for you. Hosting is pretty cheap these days... Thats just my 2 cents

Similar Threads

  1. IIS Log - Is somebody trying to Hack my website
    By vishwas_joshi in forum Microsoft Security Discussions
    Replies: 7
    Last Post: December 6th, 2005, 06:04 AM
  2. [Delphi] Building my own webserver.
    By Katja in forum Web Development
    Replies: 11
    Last Post: September 1st, 2005, 08:54 AM
  3. Webserver on my iPaq...
    By Katja in forum Web Development
    Replies: 6
    Last Post: August 8th, 2005, 02:05 AM
  4. Apache Webserver Help
    By cleanbash in forum Newbie Security Questions
    Replies: 13
    Last Post: June 12th, 2003, 10:40 AM
  5. Installation of a secure webserver.
    By instronics in forum The Security Tutorials Forum
    Replies: 0
    Last Post: January 19th, 2003, 01:53 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •