MSFN Forum: DMZ and Internet question - MSFN Forum

Jump to content


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

DMZ and Internet question Rate Topic: -----

#1 User is offline   Anthony2oo5 

  • Group: Members
  • Posts: 1
  • Joined: 11-August 11
  • OS:2003 x86

Posted 11 August 2011 - 03:41 AM

Good Morning, im wondering if someone could give me a bit of advice please?

Our company has a standalone sbs server 2003 that runs exchange, SQL, Active Directory ect ect. It has 2 network cards, one with 192.168.1.1 (which is in a DMZ set on the router) and 192.168.0.1 (Which is the internal network). It is not running ISA.

Is there any point the server being in the DMZ seen as it is a standalone server ?

Also we are having a problem with the internet being really slow. Its almost impossible to login to the router so im guessing its getting hammered. The problem is, when we look at the logs on the router everything comes from 192.168.1.1:852145 (or some other random port). So we are finding it hard to track who is causing the traffic on the internal network. How can we track who is causing the problems and what internal IP its coming from.

Thanks in advance for your help.

Regards


#2 User is offline   Tripredacus 

  • K-Mart-ian Legend
  • Group: Super Moderator
  • Posts: 8,670
  • Joined: 28-April 06
  • OS:Server 2012
  • Country: Country Flag

Posted 11 August 2011 - 07:48 AM

The only time I've seen a server in the DMZ was if it is running a web server app. What is the particular reason you have it in the DMZ?
Also I'm not too keen on the idea of having a DC in the DMZ... sounds like a possible security concern.

#3 User is offline   allen2 

  • Not really Newbie
  • PipPipPipPipPipPipPip
  • Group: Members
  • Posts: 1,736
  • Joined: 13-January 06

Posted 11 August 2011 - 01:32 PM

The only reason, i see for it to be in dmz, is so it can handle the smtp function without another device or redirection (which is a very stupid idea).
As Tripedacus said, it is very dangerous having a DC in DMZ.
You might think about buying more hardware like two more servers and use them to create VMs for handling each function (one for each). You'll need also to setup a smtp relay with filtering capability in both ways.
The problem you encounter might be a "simple" reverse spam attack (with non delivery reports).

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2013 msfn.org
Privacy Policy