IT:Network:Apps.  Microsoft Web Server ◦ Used by ~ 50% of Fortune 500 companies  Comes with Server OS  Expandable  Easy to use.

Slides:



Advertisements
Similar presentations
Windows 2003 Server. Windows 2003 Server Contents Fitur Windows 2003 Server Installation And Configuration Windows Management Resource  User Management.
Advertisements

1 Configuring Internet- related services (April 22, 2015) © Abdou Illia, Spring 2015.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 13: Administering Web Resources.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 13: Administering Web Resources.
1 Configuring Web services (Week 15, Monday 4/17/2006) © Abdou Illia, Spring 2006.
Hands-On Microsoft Windows Server 2003 Administration Chapter 7 Administering Web Resources in Windows Server 2003.
Chapter 13 Chapter 13: Managing Internet and Network Interoperability.
IIS Configuration © N. Ganesan, Ph.D.. Renaming the Default Web.
Configuring a Web Server. Overview  Understand how a Web server works  Install IIS (Internet Information Services) and Apache Web servers  Examine.
ASP.NET 2.0 Chapter 6 Securing the ASP.NET Application.
CP476 Internet Computing Browser and Web Server 1 Web Browsers A client software program that allows you to access and view Web pages on the Internet –Examples.
Access Control in IIS 6.0 Windows 2003 Server Prepared by- Shamima Rahman School of Science and Computer Engineering University of Houston - Clear Lake.
Ch 13 - Adminstering Web Resources1 Ch. 13 – Administering Web Resources MIS 431 – Created Spring 2006.
1 Enabling Secure Internet Access with ISA Server.
Windows Server 2008 Chapter 8 Last Update
Hands-On Microsoft Windows Server 2008 Chapter 8 Managing Windows Server 2008 Network Services.
Sharepoint Portal Server Basics. Introduction Sharepoint server belongs to Microsoft family of servers Integrated suite of server capabilities Hosted.
1 Advanced Application and Web Filtering. 2 Common security attacks Finding a way into the network Exploiting software bugs, buffer overflows Denial of.
2440: 141 Web Site Administration Web Server Configuration Instructor: Enoch E. Damson.
CRMUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Implementing CRM 2011 Claims-Based Authentication, ADFS and IFD Best Practices and Tips.
August 25, SSO with Microsoft Active Directory Presented by: Craig Larrabee.
Ins and Outs of Authenticating Users Requests to IIS 6.0 and ASP.NET Chris Adams Program Manager IIS Product Unit Microsoft Corporation.
1 ISA Server 2004 Installation & Configuration Overview By Nicholas Quinn.
Web Server Configuration Alokes Chattopadhyay Computer & Informatics Centre IIT Kharagpur.
Web Servers Web server software is a product that works with the operating system The server computer can run more than one software product such as .
1 Infrastructure Hardening. 2 Objectives Why hardening infrastructure is important? Hardening Operating Systems, Network and Applications.
Configuring a Web Server. Overview Overview of IIS Preparing for an IIS Installation Installing IIS Configuring a Web Site Administering IIS Troubleshooting.
Session 11: Security with ASP.NET
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Six Configuring Windows Server 2008 Web Services,
Session 10 Windows Platform Eng. Dina Alkhoudari.
1 HTML (Set Up Public Folder) Some material on these slides is taken directly from
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 13: Administering Web Resources.
15.47 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 15: Configuring a Windows.
Remote Administration Remote Desktop Remote Assistance Remote Server Administration Tools.
5 Chapter Five Web Servers. 5 Chapter Objectives Learn about the Microsoft Personal Web Server Software Learn how to improve Web site performance Learn.
Copyright 2000 eMation SECURITY - Controlling Data Access with
Microsoft Internet Information Services 5.0 (IIS) By: Edik Magardomyan Fozi Abdurhman Bassem Albaiady Vince Serobyan.
Course ILT Internet/intranet support Unit objectives Use the Internet Information Services snap-in to manage IIS, Web sites, virtual directories, and WebDAV.
© FPT SOFTWARE – TRAINING MATERIAL – Internal use 04e-BM/NS/HDCV/FSOFT v2/3 Securing a Microsoft ASP.NET Web Application.
Internet Information Server © N. Ganesan, Ph.D. All Rights Reserved.
IIS Security Sridurga Mavram. Contents -Introduction -Security Consideration -Creating a web page -Drawbacks -Security Tools -Conclusion -References.
Database-Driven Web Sites, Second Edition1 Chapter 5 WEB SERVERS.
1 Windows 2008 Configuring Server Roles and Services.
Internet Information Server Name : Yao Gu Date : 10-June-2000 COSC : 573.
Hands-On Microsoft Windows Server Implementing Microsoft Internet Information Services Microsoft Internet Information Services (IIS) –Software included.
Module 11: Securing a Microsoft ASP.NET Web Application.
Module 2: Overview of IIS 7.0 Application Server.
Turning Windows 7 into a Web Server Ch 28. Understanding Internet Information Services.
Ins and Outs of Authenticating Users Requests to IIS 6.0 and ASP.NET Chris Adams Program Manager IIS Product Unit Microsoft Corporation.
Web Access. Overview  Purpose  Prerequisites  Install Components  Enable Virtual Directories  IIS Configuration & Security  Troubleshooting.
1 Chapter Overview Creating Web Sites and FTP Sites Creating Virtual Directories Managing Site Security Troubleshooting IIS.
Security E-Learning Chapter 08. Security Control access to your web site –3 Techinques for Identifying users Giving users access to your site Securing.
Web Server Administration Chapter 6 Configuring a Web Server.
Installing IIS 7(.5). Web Platform Installer What’s New in IIS 7 Fast CGI (PHP!) Shared Configuration Automated App Pool Isolation Extensions PowerShell.
Free Powerpoint Templates Page 1 Free Powerpoint Templates Chapter 4- Server Configuration.
IS 4506 Windows NTFS and IIS Security Features.  Overview Windows NTFS Server security Internet Information Server security features Securing communication.
Customizing WebLink Lab 208 Alex Huang. Table of Contents Introduction – What is WebLink Disclaimer Customization Basics and Exercises Resources Questions.
VIRTUAL SERVERS Chapter 7. 2 OVERVIEW Exchange Server 2003 virtual servers Virtual servers in a clustering environment Creating additional virtual servers.
Web Server Administration Chapter 6 Configuring a Web Server.
1 E-Site - FTP Services Setup / install guide. 2 About FTP services can run on any desired port(s) Runs as a windows service Works for all sites installed.
Web and Proxy Server.
Web Technology Seminar
Jim Fawcett CSE686 – Internet Programming Summer 2005
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 13: Administering Web Resources.
Introduction to Networking
IIS.
الخطوات المطلوب القيام بها قبل انشاء الموقع
Configuring Internet-related services
APACHE WEB SERVER.
Designing IIS Security (IIS – Internet Information Service)
Presentation transcript:

IT:Network:Apps

 Microsoft Web Server ◦ Used by ~ 50% of Fortune 500 companies  Comes with Server OS  Expandable  Easy to use

 Windows Components > Application Server ◦ ASP.NET (optional but lots of 3 rd party solns use it) ◦ IIS >  Common Files  IIS Manager  World Wide Web Service  Other stuff can be installed (SMTP server, FTP server)

  DNS name  Update the abccompany.local zone ◦ www Address ◦ www Alias mssrv01.abccompany.local

 IIS Manager > server > Web Sites > Default Web Site  Pretty much basic, functional web site ◦ Listens on Port 80 ◦ C:\InetPub\wwwroot\ ◦ Need to create the index.htm (and related) file(s)

 Properties of Site ◦ WebSite  IP address (All or specific)  Port(s) (NOTE: SSL is more than just listing port)  Logging/timeout ◦ HomeDirectory  Where find files  Could be redirection  Permissions (like share perms) ◦ Documents  What files to look for  index.html ???

 IP address/Domain Restrictions ◦ Who will we talk to? Who will we ignore ◦ Allow all – Exceptions.OR. Deny all – Exceptions  Authentication ◦ What users can see this site ◦ How authenticate them ◦ More in a bit  Secure Communications ◦ SSL ◦ More later

  acct.abccompany.local  mktg.abccompany.local  How many servers do we need?

 New hardware for each “site”  New IP address for each “site”

 One box ◦ Big Disk/RAM ◦ Multiple IP addresses???  Web sites “Virtualized” inside physical server  Server must pick correct Virtual Server to access.

 Multiple IP addresses on Physical Server ◦ DNS for each Virtual Server points to different IP addr  acct.fencon.local   mktg.fencon.local  ◦ Configure Web site to pay attention to unique IP   acct site   mktg site  Need IP address for each virtual host!

 Single IP address on Physical Server ◦ All Virtual hosts use the same IP address ◦ Host header assigned to Virtual Server  When request comes in to physical server, it looks at the URL that was used (acct.abccompany.local vs mktg. abccompany.local)  Picks the correct virtual server based on the host headers  Only need one IP address!  Arguably the most common method

 For internal webs, we may only want access from INTERNAL addresses ◦ “You can see this, but only when you are at work”  site Properties > Directory Security > IP Address and Domain Restrictions  Set default behavior (Grant/Deny)  Set exceptions ◦ DENY All except /16

 By default anonymous access is allowed  Users group has ◦ Read/Execute ◦ List Folder Contents ◦ Read Permissions etc  Take away permissions and take away anonymous access  user must authenticate

 Site Props > Directory Security > Authentication & access control  Disable Anonymous  Pick Methods ◦ Integrated Windows auth  IE only (now firefox as well) ◦ Basic auth  password sent clear text!! ◦ Digest (only for domain users) ◦.NET

 Created multiple web sites inside a single web server  Restricted access by IP (where are you?)  Restricted access by user (who are you?)  Still need… ◦ Encryption (SSL) ◦ Nicer Content – Portals, etc