Jump to content

Change

Welcome to We Got Served Forums

Welcome to We Got Served Forums, like most online communities you must register to view or post in our community, but don't worry this is a simple free process that requires minimal information for you to signup. Be a part of We Got Served Forums by signing in or creating an account.
  • Start new topics and reply to others
  • Download Windows Home Server add-ins
  • Less ads to entertain you
  • Subscribe to topics and forums to get automatic updates
  • Get your own profile and make new friends
  • Customize your experience here

Hosting A Blog On Whs 2011, Is It Really Safe?


5 replies to this topic

#1
swearingencj

    Member

  • Members
  • PipPip
  • 57 posts
  • Gender:Male
Opening a port on my router and exposing the server to the internet seems frought with peril. How do you secure the webserver and segregate it from your internal network.

Are you guys using dual nics and a dmz? dual firewall type dmz? or is there a built in method for keeping the prying internet world from slogging around my internal network?

I am interested in running a Wordpress driven blogsite from the WHS 2011 box and am trying to think out the most secure way of separating the public and private parts of the server.


Upgrade to a WGS Supporter Account to remove this ad.

#2
swearingencj

    Member

  • Members
  • PipPip
  • 57 posts
  • Gender:Male
I know someone has an opinion....

Hopefully you guys have considered the gaping security hole that is created by opeining port 80/443 on your router?

#3
Shidoshi

    Advanced Member

  • Members
  • PipPipPip
  • 200 posts
  • Gender:Male
  • Location:4th Dimension, USA
  • Interests:Network Engineerin' and such... Graphic arts... Jumping back in to programming. That's pretty much it. I'm a fairly boring person.
Opening port 80 or 443, by itself, should not open the rest of your network to the internet in an "Explorer" way, unless you have a port forwarding rule that also forwards ports 445 and 139 (for NetBIOS and SMB/CIFS), or your server is running web serving software that's horribly unpatched or has gaping vulnerabilities.

Any device making a request to your domain name over port 80 is only going to get the webpage, because the server will be listening and respond with the website as a reply. Now, if you somehow had your port forwading/port-range forwarding take an external request on port 80 to ports 139 or 445 internally, then that's a different story.

A DMZ would be a great way to segregate your server from the rest of your network, but then your router would have to have a routing entry to let your internal clients know how to reach your DMZ -- otherwise if you use a "home" DMZ setup like what Netgear or Belkin routers do with only a single IP address from your ISP, your server will be the only device able to connect to the Internet at all...

...which, paradoxically, is a pretty good idea, I guess; removing the rest of your network's access to the Internet is a pretty good way to "secure" it from the Internet.

#4
swearingencj

    Member

  • Members
  • PipPip
  • 57 posts
  • Gender:Male

View PostShidoshi, on 17 February 2012 - 09:29 AM, said:

Opening port 80 or 443, by itself, should not open the rest of your network to the internet in an "Explorer" way, unless you have a port forwarding rule that also forwards ports 445 and 139 (for NetBIOS and SMB/CIFS), or your server is running web serving software that's horribly unpatched or has gaping vulnerabilities.

Any device making a request to your domain name over port 80 is only going to get the webpage, because the server will be listening and respond with the website as a reply. Now, if you somehow had your port forwading/port-range forwarding take an external request on port 80 to ports 139 or 445 internally, then that's a different story.

A DMZ would be a great way to segregate your server from the rest of your network, but then your router would have to have a routing entry to let your internal clients know how to reach your DMZ -- otherwise if you use a "home" DMZ setup like what Netgear or Belkin routers do with only a single IP address from your ISP, your server will be the only device able to connect to the Internet at all...

...which, paradoxically, is a pretty good idea, I guess; removing the rest of your network's access to the Internet is a pretty good way to "secure" it from the Internet.


Agreed, I was wondering if it was possible with WHS2011 to add a second NIC to the server, assign a static IP and then restrict the webserver to that IP only. I know there are NAS devices that will do this. Then you could use a DMZ to contain that connection and increase your security.

#5
Shidoshi

    Advanced Member

  • Members
  • PipPipPip
  • 200 posts
  • Gender:Male
  • Location:4th Dimension, USA
  • Interests:Network Engineerin' and such... Graphic arts... Jumping back in to programming. That's pretty much it. I'm a fairly boring person.

View Postswearingencj, on 17 February 2012 - 01:36 PM, said:


Agreed, I was wondering if it was possible with WHS2011 to add a second NIC to the server, assign a static IP and then restrict the webserver to that IP only. I know there are NAS devices that will do this. Then you could use a DMZ to contain that connection and increase your security.
You can add a second NIC to your server and configure IIS to specify your website only use that second NIC, but here's where things get a bit tricky:

As I was saying before, with only one IP address given by your ISP, if you create a DMZ on most home routers, then the DMZ will be the only subnet receiving an IP address and will be the only device capable of reaching the Internet (and being reached from the internet), and without a routing table entry there'd be a pretty good chance your other internet network devices would not know how to find your server internally, either. If you pay for a second IP address from your ISP, then you could assign the second address to your DMZ, configure your second NIC to your DMZ and configure IIS to bind your websites to the DMZ IP address.

#6
swearingencj

    Member

  • Members
  • PipPip
  • 57 posts
  • Gender:Male
Thanks for that, totally makes sense. I think the only way I'd approach this would be the second IP address. Not sure it's worth the expense.

Thanks again.

By the way, I used a solution you posted about refreshing the dlna table on the server to get new media to show up on other devices. Worked great and now I'm looking to create a script to take care of that little microsoft oversight...





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users


Toggle shoutbox Shoutbox

takiyon : (12 May 2012 - 02:28 PM) Server Scripter Just Got An Update. Check The Add-In Development Thread & Let Me Know What You Think.
takiyon : (12 May 2012 - 02:27 PM) Server Scripter Just Update
Fester : (30 April 2012 - 04:45 AM) Gdatasoft Protects 5 Pc's Yet Homeserver Allow 10 Connections ?
Fester : (30 April 2012 - 04:30 AM) Is This Orbitalbackupconfig Ready For Lion Yet ?
Gordon Currie : (30 April 2012 - 03:34 AM) @myangeldust - Yes Sql Server Express Can Be Installed On Whs1. I Would Recommend 2008 R2 Over 2005.
myangeldust : (21 April 2012 - 05:04 PM) Can Sql Server Express Be Installed On Whs V1?
Shidoshi : (12 April 2012 - 04:07 AM) @omega Ra - Reset Ie 8 And Retry. That Happens Anytime Ie Is Updated To A New Full Version (Like From Ie 6 To Ie 7 And Ie 7 To Ie 8) In Win Xp
Rolatio2 : (28 March 2012 - 01:59 PM) Cleanup
Omega Ra : (16 March 2012 - 02:02 PM) Is It Possible To Connect To A Computer Through The Web Access With A Winxp Sp3 Computer? It Keeps Asking About An Activex Component, But Doesn't Give Me An Option To Download It.
dbailey75 : (13 February 2012 - 03:18 AM) I Just Got My Geek On, It Feels Good
Mightyred : (18 January 2012 - 09:27 PM) @garry - It Seems Very Pricey, Think I'll Wait For Some Reviews.....
Garry : (17 January 2012 - 02:40 PM) @mightyred - I Have Not Heard Of Anyone With A Successful Install
Garry : (17 January 2012 - 02:38 PM) @geoff - Indeed, Have A Great Time! Happy Birthday!
bobbyc : (17 January 2012 - 09:30 AM) Happy Birthday Geoff!
Mightyred : (16 January 2012 - 11:52 PM) Anyone Tried The Gdatasoft Yet? Maybe A Review On Wgs Soon?
Garry : (07 January 2012 - 10:25 PM) News Flash Whs2011 A/v: Http://www.gdatasoft...Homeserver.html
Drashna Jael... : (30 December 2011 - 06:59 PM) The Site Is Still Around, Try Http://www.asoft.be/
msprague : (30 December 2011 - 01:14 AM) What's Happened To Asoft?
Terry (WGS) : (18 December 2011 - 05:58 PM) Indeed - Many Happy Returns Dave!
bobbyc : (18 December 2011 - 09:37 AM) Happy Birthday Dave!
Resize Shouts Area

Upgrade to a WGS Supporter Account to remove this ad.