Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IIS and Behind Firewall Access

Status
Not open for further replies.

cyberkatis

IS-IT--Management
May 30, 2002
29
US
I know that you'd never want to do this but is it possible and how.

1. Have a web server in a DMZ Zone
2. Have a 2000 File Server in the Trusted Zone
3. There are files (.pdf) that I want to serve up on the file server through the web server by going through the firewall.

This not only seems impossible but if it were to be accomplished it would breach the firewall in ways that I wish not too.....

Does this make sense?

Thanks.

Chris.
 
This can be done, but as you say, you have to be carefull with the firewall
 
Challenging.

If I were to do this it would involve the use of a second network card on the ‘external’ web server.

This card would be connected to the internal network and separated from the ‘external’ network by disabling TCP/IP in the second network card on the ‘external’ machine, and disabling IPX/SPX on the first network card (the card in the machine now).

Then by ‘sharing’ the directory on the server (setting the rights to read only) the internal network remains isolated from the external network.

Make sense? Have I ever done this? No. Security for this can still be a tricky business, because of the way that authentication takes place and the use of network shares (not recommended).

However, I believe that this is the safest way to approach it.

[morning] Amiel
amielzz@netscape.net

 
Hold on! You have a web server running on Port 80, that is the only port you need to open to access your pdf files.

Certainly this works in any browser:



will return the pdf as long as the firewall has port 80 forwarding to the private ip, and it doesn't require a pdf.
 
Correction

will return the pdf as long as the firewall has port 80 forwarding to the private ip, and it doesn't require a pdf.

not a pdf a dmz I am losing it big time.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top