1. sensibilium
  2. » sensiblog
  3. » Securing the Server

Securing the Server

Monday, the 19th of September, 2005 at 11:03pm GMT
So they guy came round and had a look over my settings, everything appeared to be hunky-dory, and he just re-ran the Internet Connection Wizard (somewhat different from the non-server wizard) and then all my clients had access to all protocols and content type required.

After reading the ISA book I recently bought, I decided to get another network card for the server, at six pounds for a huge increase in security has to be worth it. I mean, six quid?! Bargain!

Anyway, I shat down the server and installed the second NIC. Rebooted and waited an age for the Preparing Network Connections... bit finished, got slightly concerned that wouldn't ever finish what it was doing, but just as I gave up it finished and brough up the login prompt.

So, I then changed the IP address on the external connection to a IP range outside of the local area network (otherwise conflicts can take place in ISA's LAT table), and plugged in my router. Suddenly realised that I couldn't access my routers web admin as I hadn't changed the IP address, so I had to unplug the router from the external network card and plug it back into the the hub, whereupon I logged into the webpanel and changed the IP address. Plugged it back into the servers external NIC and hey presto! A live internet connection.

Then spent a little time configuring the VPN passthrough using Routing and Remote Access, phoned up my remote user, asked him to try it out, and other than one problem (I had forgotten to give the VPN user account Dial-In permission), he connected within seconds. Marvellous.

As confusing as all this sounds, it really is a shit lot easier than you'd think.

So, here's an example of our old network setup:

User posted image

As you can see that problem lies in the fact that any hax0r that breaks into the router is then onto the internal network.

The second network card allowed me to do this:

User posted image

Now if anyone breaks through the router, they then have to break through ISA Server too. Much more secure I'm sure you'll agree.

Comments

horab fibslager on Tue 20 Sep 2005 at 12:03pm GMT #
very nice. it's the way i probaly would've set it up myself, but that's nto ebcause i'm qualified or have any know how. :p
 
Opinion, Tattle & Shite
NAVIGATE
Visitors

If you wish to add comments to our blog posts, please Register here.
If you prove to be a worthwhile contributor, your account will be upgraded to allow you post your own articles!
Existing users, login below.

Switch Stylesheet

Latest Comments

spamgun: KA-POW!...
ahdkaw: owning the shit...
lyric: bout fucking time...
ahdkaw: Comments are working again for members...
ahdkaw: Of course I am, but you already know this. I only post this so that the various random visitors are...
lyric: Are you still alive? Chris was back at the Gap and had you on the missing persons list. Not to be...
ahdkaw: Thud will likely [b]not[/b] return, although such things are not beyond the realms of...
lyric: Is Thud coming back? I need to read this more carefully. Once all the holiday foo fa is done...
ahdkaw: I must admit though, it does look pretty funky (reCaptcha)...
ahdkaw: You should know by Angus, this site is designed to not use any distributed software (let's ignore...
AngusThermopile: What sort of question is that you bloody turnip? Did you get that from an old blackadder...
ahdkaw: Example question to help you all out (answers should be short, single word answers (if a word is...
ahdkaw: Well it appears that it may not be working as expected after all. It seems that new tags can't be...
lyric: Yes I always knew you could be deadly if allowed free rein. I will keep your new Killer status in...
lyric: I have no idea what you are talking about, but I am glad to see you are still alive and working...
ahdkaw: And as of this morning, I have my Quest Cape at last!...
ahdkaw: That's bollocks mate, I can clearly see the icon when not logged in. Vista problem?...
4000MilesAway: indeed it does, however you have to be logged in for it to appear. Is that by design?...
ahdkaw: The ORANGE RSS icon appears on the right hand side of the address bar in FF on Windoze but not in...
ahdkaw: I think the TAG bug should now be fixed...
ahdkaw: Thanks for the heads up on the Tags bug, will look into it eventually. As for the RSS feed, it...
4000MilesAway: Came up eventually mind...
4000MilesAway: Do you have a roach infestation or what? Ok So on with the bugs. I initially came to this place...
4000MilesAway: PS: Bug Since you only allow 5 tags & I spent all of 10 long seconds crafting my own tags...
ahdkaw: Fuck fuck fuck! Lost the damn lot. :( I shall post a shortened version of my lost comment...
lyric: Nice post title, this should keep the Dog in the Adult section for a month :-} I love adblock...
lyric: Sorry your bday wasn't a blast. I am glad to see you still live. I thought you had fallen into your...
ahdkaw: Cheers folks! Didn't have as much a nice birthday as I originally intended but I have been drunk...
AngusThermopile: Happy slappity Birthday Ahd! Oh and post some content. We all know giving us the ability to do...
AngusThermopile: So have you built it now?...

NICENESS

Sidewalkcurl Jasidog SSSBella Delicious 23ae DRT whyareweiniraq HHC OpenSUSE Adam Buxton A Boy And His Computer BeatBasement FSM - Believe! Sensibilium

10.4
BETA