M
markm75
I'm trying to restructure our domain.. and I believe I have had the
ftp service in a "bad" location prior..
Prior to now.. it was installed on a domain (member) server.. I used a
dummy account to provide access to the directory though..
Now i've virtualized alot of the infrastructure and created an "edge"
server, which is not joined to the domain.
It is my belief that the FTP service should reside here. On this edge
server (virtual).. i have two nics, but one isnt in use and the other
has a local ip address to our network. So for now i'm not using a
public ip address, but i'm guessing i probably should assign a public
ip to the one nic?
My other question relates to the placement of our RRAS service which
supplies access to PPTP vpn, as of now it resides on a member server..
using the single NIC on that system etc..
Is this location ok? What about moving it to the edge server? I'm
not sure how this would work over there, as once they connect, they
need access to the domain.. I'm guessing i could set up a one way
vpn.. but wouldnt this technically compromise the ftp security?
Also.. any thoughts on how to "secure" the PPTP connection, so the
passwords arent sent in clear text.. ie: with a certificate (not sure
how this would work)..
Thanks in advance
ftp service in a "bad" location prior..
Prior to now.. it was installed on a domain (member) server.. I used a
dummy account to provide access to the directory though..
Now i've virtualized alot of the infrastructure and created an "edge"
server, which is not joined to the domain.
It is my belief that the FTP service should reside here. On this edge
server (virtual).. i have two nics, but one isnt in use and the other
has a local ip address to our network. So for now i'm not using a
public ip address, but i'm guessing i probably should assign a public
ip to the one nic?
My other question relates to the placement of our RRAS service which
supplies access to PPTP vpn, as of now it resides on a member server..
using the single NIC on that system etc..
Is this location ok? What about moving it to the edge server? I'm
not sure how this would work over there, as once they connect, they
need access to the domain.. I'm guessing i could set up a one way
vpn.. but wouldnt this technically compromise the ftp security?
Also.. any thoughts on how to "secure" the PPTP connection, so the
passwords arent sent in clear text.. ie: with a certificate (not sure
how this would work)..
Thanks in advance