I was hoping to get some input on the following situation. I want to be informed so I can counter with a thoughtful and realistic answer.
Here at work we want to make the intranet site available over the Internet. We consulted with the security people and they are telling us that in order for the intranet site to be available both via the internet and via the internal network they need to move the web server onto the DMZ. Is this the way things are normally done? I ask because from my understanding, the DMZ is not supposed to talk to the internal network, but we need to access a databse server and a forums server. I don't think moving the databse and forums server to the DMZ is a good idea. What do you guys think?
neopipil
Here at work we want to make the intranet site available over the Internet. We consulted with the security people and they are telling us that in order for the intranet site to be available both via the internet and via the internal network they need to move the web server onto the DMZ. Is this the way things are normally done? I ask because from my understanding, the DMZ is not supposed to talk to the internal network, but we need to access a databse server and a forums server. I don't think moving the databse and forums server to the DMZ is a good idea. What do you guys think?
neopipil
