Setup IIS on primary Server 2008 R2 with Active directory and direct port forward


hello,

i have posted on iis forums well, i'm interested in input affects server well:

i'm knowledgeable setting windows servers, workstations, etc.  i'm not versed in security side of process.  know basics: updates, up-to-date protection, change passwords, etc.  stay away iis, , i've been asked raising shackles on of neck.  basically, have windows server 2008 r2 iis on running medical practice software.  software company wants me open port 443 directly our primary/only application/file/data server.  company assures me "safe" , no 1 else has had problems.  experience iis when working gov’t agency, iis server used penetrate network , subvert it.  luckily, white-hat group had been hired check security, still, experience iis , gut tells me should recommend against this.  i've got couple of questions:

1) good/bad idea on small office server no ids system, stock verizon fios router/firewall, , no regular monitoring?

2) there way mitigate risks reasonable small office no onsite tech support?

3) verizon tells me putting actiontec device bridge mode "not supported," means cannot implement better firewall such cisco, sonicwall, etc.  fair, i've done @ home cisco small business router , works fine.  comments on this?  reasons put in bridging mode, not put in bridging mode, personal experience it?

4) if bad idea, please give me specifics.  implementer told me safe, they've never had complaints, it’s same way implement on cloud service, etc. explained have basic firewall, no ids, , no regular monitoring, response if don't want use system don't have to. 

sorry if these simple questions, don't setup, configure, or secure iis.  i'm not sure if i'm being overly nervous, if being stupidly optimistic, or somewhere in between. 

thanks,

jeffery smith

hi,

it seems discussing potential security issue in using iis , open port 443.

here article setup ca on protect primate information:

how enable ssl customers interact web site in internet information services
http://support.microsoft.com/kb/298805/en-us

and see, should still iis related topic. have posted thread in iis forum, let's see if more information provided there.

thank post!


technet subscriber support in forum |if have feedback on our support, please contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client