16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

674 Part VIII: Securing SharePoint <strong>Products</strong> <strong>and</strong> <strong>Technologies</strong><br />

External<br />

User<br />

NLB<br />

SharePoint Portal<br />

Server Farm<br />

Front-end<br />

web server<br />

Front-end<br />

web server<br />

F25XR01<br />

Figure 25-1 SharePoint Portal Server deployment behind a firewall<br />

On a simple level, firewalls perform packet filtering: when traffic comes to the<br />

firewall, it compares the data in the Internet Protocol (IP) header with the preconfigured<br />

rules to determine whether to allow or deny access. However, to protect<br />

SharePoint Portal Server deployments from external attacks, it is also necessary to<br />

check <strong>and</strong> verify the payload inside the HTTP header. A <strong>Microsoft</strong> Internet Security<br />

<strong>and</strong> Acceleration (ISA) Server 2000 firewall is an application-layer firewall that, in<br />

addition to packet filtering, provides the ability to examine the content contained in<br />

the application-level protocols such as HTTP. Using ISA Server provides the ability<br />

to publish portal sites to the Internet without compromising the security of your<br />

internal network. In this chapter, we will look into issues you need to consider when<br />

you configure ISA Server 2000 to protect the SharePoint Portal Server deployments<br />

from unauthorized access.<br />

ISA Server 2000 Web Publishing<br />

Back-end<br />

servers<br />

When you set up the external ISA Server 2000 firewall, you first need to consider<br />

how to use ISA Server 2000 Web publishing rules for making the internal SharePoint<br />

site available for external users.<br />

When a client on the Internet requests an object from a front-end Web server,<br />

the request is actually sent to an IP address on the ISA Server computer. Web publishing<br />

rules that are configured on the ISA Server computer forward the request, as<br />

applicable, to the server running SharePoint Portal Server located behind the firewall.<br />

The servers running SharePoint Portal Server require no special IP configuration.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!