Building DMZs for Enterprise Networks

In March 2003, Internet trend analysis company Netcraft put the count of Microsoft-based Web servers at over 1 million IP addresses and ranked Internet Information Services (IIS) as the second most popular Web server running on the Internet today (after Apache). Yet Microsoft platforms take a bad rap when it comes to security in a DMZ context. After all, the most noticeable and talked-about Internet worms Nimda, Code Red, and SQL Sapphire all live and breed on Windows. However, this does not speak to Windows 2000's built-in security mechanisms so much as it highlights the poor planning that all to often accompanies a new Windows 2000 DMZ server build. This chapter will help you, the systems engineer, avoid the most common pitfalls in deploying Windows 2000 to a hostile Internet-facing environment using mostly on-board, built-in tools.
| Note | A natural companion to this chapter is Syngress Publishing's Hack-Proofing Windows 2000, which goes into more detail on a number of topics not covered in depth here due to space considerations. One chapter alone cannot possibly explore all topics that the 716-page Hack-Proofing covers in detail, such as Microsoft's implementation of the IPSec protocol suite, certificate and Kerberos authentication infrastructures, and NT 4.0 to Windows 2000 upgrading mechanisms and strategies. Furthermore, Microsoft is well aware of its less-than-stellar reputation in the security space after all, its products are primarily designed for ease of use, with an eye toward serving all possible roles in the enterprise. To address this issue, Redmond launched the Trusted... |