You are here:About>Business & Finance>Business Security> Internet Security> IIS 6.0 Specific Configurations
About.comBusiness Security
Newsletters & RSSEmail to a friendSubmit to Digg

Securing Internet Information Server (IIS) 6 for DMZ Placement

From Ryan Groom,
Your Guide to Business Security.
FREE Newsletter. Sign Up Now!

IIS 6.0 Specific Configurations

The default web site is well known and could have some inherent vulnerabilities; it is best to ensure that this web site is deleted and create a new one for your purposes.

From the master properties for the web server, remove all unnecessary mime types by deleting any type of file extension that will not be served by this web server. These mime types can be added later if necessary.

Set the IIS logging parameters at the "Web Sites" level so that all new sites will inherit these settings.

Set the logging location to the secure location or the drive allocated for these logs (F:\securelogs). Set the NTFS permissions on this folder to System and Administrators to ‘Full Control’ on this partition and remove the ‘Everyone’ group from this folder.

  1. Introduction
  2. Planning
  3. Installing IIS 6.0 Securely
  4. IIS 6.0 Specific Configurations
  5. Using the Win2k3 High-Security Templates - Part I
  6. Using the Win2k3 High-Security Templates - Part II
  7. Using the Win2k3 High-Security Templates - Part III
  8. Disable Microsoft Networks
  9. Enabling the Windows Firewall
  10. Allow Proper Internet Traffic

<< Previous | Next >>

 All Topics | Email Article | | |
Advertising Info | News & Events | Work at About | SiteMap | Reprints | HelpOur Story | Be a Guide
User Agreement | Ethics Policy | Patent Info. | Privacy Policy©2008 About, Inc., A part of The New York Times Company. All rights reserved.