Frame Corner

Frame Top

GSW Study Notes Home

GSW MCSE Notes Home Networking Essentials Notes NT Server 4.0 Notes NT Administration Notes

Module 13: Internetworking and Intranetworking

Security Considerations

It is possible to integrate a corporate intranet with the Internet. Both can be supported by the same network system. Following security implications should be considered before attempting to integrate an intranet with the Internet.

IIS and PWS Overview

IIS and PWS are network file and application servers that use:

  1. HTTP; is used to create and navigate Web hypertext documents and applications
  2. Gopher service is a hierarchical system used to create links to other computers or services, to put these links into custom menus, and to annotate files and directories.
  3. FTP is used to transfer files between two computers on a TCP/IP network.

IIS

PWS

Any computer running Windows NT Server Any computer running Windows NT Workstation
Supports the heavy usage Used for small scale Web server or an individual
 Both can use Performance Monitor and Event Viewer

Key features that IIS and PWS provide for a computer running Windows NT  

Feature

Use this feature to

File publication Publish existing files from Windows NT
Network management Monitor and record network activity and provide clients with access to valuable network resources such as HTML pages, shared files and printers
Security Provide clients with secure access to Internet and intranet resources
Support for common Internet standards Enable development of Web applications using languages such as CGI (Common Gateway Interface) and PERL (Practical Extraction and Report Language)
Microsoft Internet
Explorer
Enables Windows 3.11, Windows for Workgroups, Windows NT, Windows 95 and Macintosh easy access to the Web
Scalability Enable Internet access to multiple platforms running on standard hardware packages, including single and multiprocessor servers
Support for Microsoft BackOffice applications Provides businesses with ability to deliver commercial solutions on the Web (SQL Server and SNA Server)

 

IIS Installing Requirements:

Changes can be made to a current installation of IIS through the Internet Information Server Setup icon located in Microsoft Internet Server (Common) folder.

Can be installed when Windows NT Server is installed, or later using Network program or the Install Internet Information Server icon located on desktop.

PWS Installing Requirements:


Changes can be made to a current installation of PWS through the Peer Web Services Setup icon located in Microsoft Peer Web Services Internet Server (Common) folder.

Configuring IIS and PWS

Use Microsoft Internet Service Manager (ISM) to:

Properties

User connections and user logon and authentication requirements

the home directory for each service

server activity tracking through the Logging tab
 

 

secured access by IP address and bandwidth for each service

Configuring Services

ISM can be used to configure following services:

Allow Anonymous Access with the Internet Guest Account.

 

Note: Internet Guest account is added to the Guest group. Changes to the Guest group user rights and resource permissions also apply to the Internet Guest account

 

Require a User Name and Password on WWW and FTP resources

There are two types of authentication available when requiring a user name and password:

  1. Basic Authentication does not encrypt transmissions between client and server. Intruders could discover valid user name and passwords.

  2. Windows NT Challenge/Response authentication, supported by Microsoft Internet Explorer version 2.0 or later, protects the password; thereby, providing for secure logon over the network. User account obtained from client is the one with which the user logged on at the client.
Note: FTP server supports only basic authentication, so an FTP site is more secure if only anonymous connections are allowed.

Guidelines for Securing an Internet or Intranet Site:

 

Top of Page Top of page

E-mail Me! Comments and suggestions? E-mail me at grantwilson21@yahoo.com
I'm sorry, but I can't answer specific network-related, or exam-related questions.
Last Updated: August 6, 2001 Grant Wilson, Edmonton, AB Canada